VPS Snaps

How to back up a server to Google Drive with rclone

The dependable way to back up a Linux server to Google Drive is rclone. Create your own Google OAuth client ID, set up a Drive remote with the drive.file scope so rclone sees only the files it creates, authorize it from a desktop browser with rclone authorize, and upload archives with rclone copy through a crypt remote so Google stores only ciphertext. Verify with rclone cryptcheck, and plan around Drive's limits: 750 GB of uploads per user per 24 hours, duplicate file names, and a trash that still uses your storage.

8 min readUpdated Checked against official documentation

What you need

  • rclone on the server, and on a desktop computer with a browser for the one-time sign-in. rclone recommends the same version on both.
  • Room in Drive. A personal Google Account includes 15 GB shared across Gmail, Drive and Google Photos.
  • Your own OAuth client ID. rclone's docs say its shared client ID will stop working during 2026, and all rclone users share its rate limit.

rclone's install script for Linux:

Terminal
sudo -v ; curl https://rclone.org/install.sh | sudo bash

sudo -v asks for your password first, so the piped script can install as root. For more on rclone itself, see rclone backups.

Choose a scope: drive.file

The scope decides what the token saved on your server can reach. If the server is compromised, so is the token.

ScopeWhat rclone can accessFor server backups
drive.fileOnly files and folders rclone created. They show in the Drive web interface.Use this. Google classes it as non-sensitive.
driveEvery file in the Drive, except the app data folderOnly if rclone must read files it didn't create. Google classes it as restricted.
drive.readonlyRead every file; no uploadsRestores only
drive.appfolderA private folder hidden from the Drive web interfaceAvoid: you can't download backups from the website in an emergency

With drive.file, a stolen token can't read your documents, photos or anything else in the account. The trade-offs: rclone can't see files uploaded another way, and can't empty the trash, which the Drive API allows only with the full drive scope.

Keep the client ID and secret with your recovery notes. With drive.file, rclone reaches only the files created through your app, so a rebuilt server should use the same client.

Create your own client ID

  1. Sign in to the Google Cloud console with any Google account, and select or create a project.
  2. Under Enable APIs and services, search for Drive and enable the Google Drive API.
  3. Click Credentials in the left panel, then Configure consent screen and Get started. Enter an app name (rclone is fine) and a support email. Under Audience, choose External for a personal account or Internal for a Google Workspace account. Add your contact email and click Create.
  4. Click Data Access, then Add or remove scopes, add https://www.googleapis.com/auth/drive.file, and save.
  5. Click Audience and add yourself as a test user.
  6. Click Overview, then Create OAuth client. Choose Desktop app, click Create, and copy the client ID and client secret.
  7. For an External app, open Audience and click Publish app.

Don't leave an External app in Testing. Google gives External apps in Testing refresh tokens that expire after 7 days, so the backup job stops a week after setup. A published personal app with fewer than 100 users doesn't need Google's verification; at most you click past an unverified-app warning at sign-in. If Publish app is greyed out, rclone's guide says Google first wants a home page and a privacy policy URL under Branding.

Set up the remote on a headless server

Terminal
rclone config
  • n for a new remote; name it gdrive.
  • Storage: drive.
  • client_id and client_secret: the values from the console.
  • scope: drive.file.
  • service_account_file: leave blank. If asked to edit advanced config, answer n.
  • Use web browser to automatically authenticate: n, because the server has no browser.

rclone then prints an rclone authorize command. Run it on the desktop exactly as printed, including any text after "drive", which carries your client settings:

Terminal
rclone authorize "drive"

Sign in and allow access. The desktop prints a token; paste it at the server's config_token> prompt. Answer n to Configure this as a Shared Drive unless you use a Workspace shared drive, and keep the remote.

To skip rclone on the desktop, forward the sign-in port over SSH instead, answer y to the browser question on the server, and open the printed http://127.0.0.1:53682/auth link in your local browser:

Terminal
ssh -L localhost:53682:localhost:53682 user@your-server

Test the remote. about shows the quota, usage and trash size:

Terminal
rclone about gdrive:

The token in rclone.conf opens your backups to anyone who reads the file. Find it with rclone config file, chmod 600 it, and consider rclone config encryption set. An encrypted config needs its password in scripts, through RCLONE_CONFIG_PASS or --password-command.

Encrypt with a crypt remote

A crypt remote wraps another remote and encrypts file contents and names on the server before upload, with NaCl SecretBox (XSalsa20 and Poly1305). Google then stores only ciphertext. Run rclone config again:

  • n, name it gdrive-crypt, Storage: crypt.
  • remote: gdrive:server-backups-encrypted, a folder you use only through the crypt remote.
  • filename_encryption: standard. directory_name_encryption: true.
  • password: type a long passphrase, or let rclone generate one.
  • password2, the salt: g to generate one. It acts as a second password.

Store both passwords in a password manager, off the server. Without them nobody can decrypt the backups, you included. rclone.conf keeps them only lightly obscured, and existing encrypted files can't be re-keyed: a new password means uploading everything again.

Crypt doesn't hide file sizes or modification times, and standard name encryption limits names to about 143 characters.

Upload a backup

Make the archive first, with tar or a database dump, and put the date in its name. Then:

Terminal
rclone copy /var/backups/web-01 gdrive-crypt:web-01 --drive-stop-on-upload-limit --log-file /var/log/rclone-gdrive.log -v
  • copy uploads new and changed files and never deletes at the destination. sync would delete remote files that are gone locally, the wrong default for backups.
  • gdrive-crypt:web-01 is the folder web-01 inside the encrypted remote.
  • --drive-stop-on-upload-limit makes Drive's daily upload limit a fatal error, so the job fails visibly instead of retrying.
  • --log-file writes the log to a file, and -v logs each transfer.

Send archives, not trees of small files: rclone's docs say Drive's rate limits hold it to about 2 files per second. Dated names matter too. Drive lets several files in one folder share a name, which confuses later copies; rclone dedupe repairs that. Schedule the job with cron.

Retention: delete old archives, skip the trash

Terminal
rclone delete gdrive-crypt:web-01 --min-age 30d --drive-use-trash=false --dry-run
  • --min-age 30d limits the command to files older than 30 days.
  • --drive-use-trash=false deletes permanently. By default rclone moves files to the trash, which counts against your storage until Drive deletes them after 30 days.
  • --dry-run lists what would go. Remove it once the list is right.

rclone cleanup gdrive: empties the whole trash, but only with the full drive scope. With drive.file, delete permanently as above, or empty the trash on the Drive website.

Verify the upload

Terminal
rclone cryptcheck /var/backups/web-01 gdrive-crypt:web-01 --one-way

cryptcheck reads the nonce from each uploaded file, encrypts the local copy with it, and compares the result's checksum with the one Drive stores. --one-way checks that every local file is on Drive and matches, and ignores older archives that exist only on Drive.

For an unencrypted remote, rclone check compares sizes and MD5 hashes:

Terminal
rclone check /var/backups/web-01 gdrive:server-backups/web-01 --one-way

A match proves the upload; a restore proves the backup. Pull one back to scratch space and open it, as in how to test a backup restore:

Terminal
rclone copyto gdrive-crypt:web-01/web-01-2026-10-03.tar.gz /tmp/restore/web-01-2026-10-03.tar.gz

Drive limits that matter

  • 750 GB a day. Google's Workspace help says each user can upload and copy 750 GB within 24 hours, and rclone reports the same limit. The file that crosses it finishes; later uploads fail until the limit refreshes, within 24 hours.
  • 5 TB per file.
  • Storage. 15 GB shared with Gmail and Photos on a free personal account. Over quota, uploads stop.
  • Trash. Trashed files use storage until they are permanently deleted, which Drive does after 30 days.
  • Same names. Several files in one folder can share a name.
  • Rate limits. About 2 files per second through rclone.
  • Tokens. A refresh token stops working if you revoke access, after six months unused, or after 7 days for an External app in Testing. rclone config reconnect gdrive: signs in again.

Personal account or Google Workspace

Personal Google AccountGoogle Workspace
Storage15 GB free, shared with Gmail and PhotosSet by your Workspace plan
OAuth audienceExternal; publish the app to avoid 7-day tokensInternal; limited to your organization's users, no publishing needed
Admin controlsNoneAn admin can block third-party apps or restrict Drive; ask them to trust your client ID

Workspace also has shared drives, which rclone offers during setup, and service accounts with domain-wide delegation for access without a personal sign-in. Both need an administrator.

For how many archives to keep in Drive, and for how long, see how long to keep backups.

Frequently asked questions

Can I back up a Linux server to Google Drive?
Yes, with rclone. Use your own OAuth client ID, the drive.file scope and a crypt remote, and schedule rclone copy with cron.
Why did my rclone Google Drive token stop working after a week?
Your OAuth app is External and still in Testing, so Google issued a refresh token that expires after 7 days. Publish the app under Audience, then sign in again with rclone config reconnect gdrive:.
What is Google Drive's daily upload limit?
750 GB per user in 24 hours, with single files up to 5 TB. Add --drive-stop-on-upload-limit so rclone fails instead of retrying when you hit it.
Do deleted files in Google Drive still use storage?
Yes, while they are in the trash. Drive deletes them permanently after 30 days. Use --drive-use-trash=false when rclone removes old backups.
Should rclone use the drive or drive.file scope for backups?
drive.file. rclone can then reach only the files it created, so a leaked token exposes your backups, not the rest of your Drive.

How this was checked

Commands, limits and prices were checked against these official pages, on October 3, 2026: