> Documentation index: https://rift.sh/llms.txt

# Rift vs Google Drive

Google's Drive MCP server gives an agent read access to a person's whole Drive. Rift gives an agent its own key and only the folders it was granted.

### What Google Drive is

Google Drive is the file store of Google Workspace, where people edit documents together in the browser. In 2026 Google added a Drive MCP server, in developer preview, so that agents can search, read and create files in a person's Drive.

### How they differ

Google's MCP server for Drive asks for permission to view all of a person's Drive files, and Google checks every request. Where a customer holds the encryption keys, Google says Gemini cannot act on those files. With Rift, the agent holds its own key, and each machine that receives a file checks the grant.

- Identity
  - Google Drive: A service account, or the signed-in person.
  - Rift: A key that each machine and agent makes for itself. No account.

- Smallest share
  - Google Drive: To another Google account, one file or folder as viewer, commenter or editor. To an app, the files a person picks or the app created. The Drive MCP server also needs read access to the whole Drive.
  - Rift: A folder, a subfolder or one file, as read or write.

- Who checks access
  - Google Drive: Google.
  - Rift: Each machine that receives a file checks the grant itself.

- Who can read your files
  - Google Drive: Google. With client-side encryption, offered on some editions, Google cannot read the files and Gemini cannot act on them.
  - Rift: Only the machines you shared with. Rift Cloud holds ciphertext.

- When your machines are off
  - Google Drive: Files stay available from Google.
  - Rift: Files stored in Rift Cloud stay available.

### Which to choose

Choose Google Drive when

- Your company runs on Google Workspace.
- People edit documents together in the browser.
- You want Gemini to work on the files.

Choose Rift when

- An agent should hold a key it made itself, with no Google account behind it.
- Two companies' agents should share a folder with no Google account on either side.
- Whoever stores the files must be unable to read them, with no key service on your side.

Based on Google's documentation, read in October 2026. Sources: [Drive MCP server](https://developers.google.com/workspace/drive/api/guides/configure-mcp-server) , [sharing roles](https://support.google.com/drive/answer/7166529) , [API scopes](https://developers.google.com/workspace/drive/api/guides/api-specific-auth) , [encrypted files in the API](https://developers.google.com/workspace/cse/guides/handle-cse-files) , [client-side encryption](https://knowledge.workspace.google.com/admin/security/about-client-side-encryption) , [Gemini FAQ](https://knowledge.workspace.google.com/admin/gemini/gemini-for-google-workspace-faq).
