> ## Documentation Index
> Fetch the complete documentation index at: https://docs.pdfnoodle.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Configuring Google Cloud Storage

This guide walks you through creating your bucket, enabling HMAC authentication, assigning the correct IAM permissions, and adding your credentials to pdf noodle.

***

### 1. Create or Select Your GCS Bucket

If you don’t already have a bucket:

1. Go to Google Cloud Console → Cloud Storage → Buckets
2. Click Create
3. Choose:

* **Bucket Name**: Your choice (I'm using `pdfnoodle-gcp-test`)
* **Location**: Region closest to your users
* **Storage class**: Standard (recommended)
* **Public access**: Prevent public access (ON)
* **Access control**: Uniform (required)

4. Finish creation

Here's how my final configuration looks like:

<img src="https://mintcdn.com/pdforge/rwoRLXXUvihWxlAY/images/configuring-s3/1-create-or-select-your-gcs-bucket-1.png?fit=max&auto=format&n=rwoRLXXUvihWxlAY&q=85&s=9c256bbad676be652184130568f10b71" alt="" width="1355" height="698" data-path="images/configuring-s3/1-create-or-select-your-gcs-bucket-1.png" />

<Warning>
  **Important:** Uniform bucket-level access + public access prevention is the
  recommended setup for private PDF storage with pdf noodle.
</Warning>

***

### 2. Create a service account

Now let’s set up the service account that pdf noodle will use when interacting with your Google Cloud Storage bucket. This account defines exactly what pdf noodle is allowed to do inside your bucket: uploading files, reading them back, or both.

If you already have a dedicated service account for storage operations, **feel free to move on to the next step.**

**Here's how to do it:**

1. Go to Google Cloud Console → IAM & Admin → Service Accounts
2. Click Create Service Account
3. Enter a name (e.g., pdf-noodle-storage) and click Create and Continue
4. Assign the required permissions:

#### Upload-only (maximum privacy)

Choose this if you want pdf noodle to upload files but never read them.

Add the role:

```
Storage Object Creator
```

#### Upload + Read (full integration)

Choose this if you want pdf noodle to upload, read, or validate files.

Add both roles:

```
Storage Object Creator
Storage Object Viewer
```

<Danger>
  **Important:** This guide uses `Storage Object Creator` under the assumption
  that you *won’t* be overwriting files with the same key (filename). If your
  workflow requires pdf noodle to replace existing files, switch to `Storage
      Object Admin` to avoid permission errors during upload.
</Danger>

Here's an example on how your Service Account Permissions should look like:

<img src="https://mintcdn.com/pdforge/rwoRLXXUvihWxlAY/images/configuring-s3/image-1-2.png?fit=max&auto=format&n=rwoRLXXUvihWxlAY&q=85&s=89d981f6f640c72a79a7dab798e3cb63" alt="" width="890" height="785" data-path="images/configuring-s3/image-1-2.png" />

***

### 3. Create Credentials and Grant Access to Your Bucket

Now that your service account is ready, you’ll generate the **HMAC access key and secret** that pdf noodle will use to communicate with Google Cloud Storage through the S3-compatible API.

<img src="https://mintcdn.com/pdforge/rwoRLXXUvihWxlAY/images/configuring-s3/3-create-credentials-and-grant-access-to-your-buck-1.png?fit=max&auto=format&n=rwoRLXXUvihWxlAY&q=85&s=f429a22a066d2dd401064952ccb5b1ba" alt="" width="966" height="894" data-path="images/configuring-s3/3-create-credentials-and-grant-access-to-your-buck-1.png" />

1. Go to Google Cloud Console → Cloud Storage → Settings → Interoperability
2. Scroll to the HMAC keys section
3. Click Create a key for a service account
4. Select the service account you just created
5. Click Create Key to generate your:
   * **Access Key ID**
   * **Secret Access Key**

<Info>
  These credentials allow pdf noodle to authenticate with your bucket using
  S3-style requests. Make sure to store the secret key securely. It is only
  shown once.
</Info>

***

## 4. Add GCS Credentials to pdf noodle

<img src="https://mintcdn.com/pdforge/rwoRLXXUvihWxlAY/images/configuring-s3/step-4-connect-your-bucket-to-pdf-noodle-1.png?fit=max&auto=format&n=rwoRLXXUvihWxlAY&q=85&s=10f462cf8f7164cc8765020bdc742a7f" alt="" width="1920" height="1003" data-path="images/configuring-s3/step-4-connect-your-bucket-to-pdf-noodle-1.png" />

1\. In pdf noodle, go to Settings > S3 Configuration.

2\. Click Add S3 Connection, then enter:

* Provider: Google Cloud Storage
* Access Key and Secret Key
* Bucket Name
* *(Optional)*: Enable **Upload access only** if you don’t want pdf noodle to read from the bucket.

<Warning>
  **Note:** With **Upload access only** enabled, we won’t return the file in the
  API response—only its key.
</Warning>

<img src="https://mintcdn.com/pdforge/rwoRLXXUvihWxlAY/images/configuring-s3/image-1-3.png?fit=max&auto=format&n=rwoRLXXUvihWxlAY&q=85&s=ae2edb8c9385d7a3f88a47382f2457d6" alt="" width="1808" height="1017" data-path="images/configuring-s3/image-1-3.png" />

3\. Click Continue. If everything’s configured properly, you’ll see a success message.

pdf noodle will attempt to upload a test file to:

`pdfnoodle_test/delete_me_{date}.txt`

Since we don’t have delete permissions, you’ll need to remove that file manually later.

<Info>
  Hint: If you see an error, double-check your credentials and bucket
  permissions.
</Info>

***

### Step 6: Set as Default Storage

<img src="https://mintcdn.com/pdforge/rwoRLXXUvihWxlAY/images/configuring-s3/step-6-set-as-default-storage-2.png?fit=max&auto=format&n=rwoRLXXUvihWxlAY&q=85&s=68277900f65ade96f2afdf282479e67f" alt="" width="1440" height="810" data-path="images/configuring-s3/step-6-set-as-default-storage-2.png" />

Go back to your S3 settings in pdf noodle and select your new connection as the default bucket. **All future PDFs will now be saved there. 🎉**

<Success>
  **Hint:** You can also set on which `s3_bucket` and `s3_key` you want to save
  PDFs individually, by passing an extra parameter. [You can see more about it
  here](https://app.gitbook.com/o/6WKbIlYX72bYYe0wYnOa/s/5XMpOekw27OhJlJjfwYv/)!
</Success>
