summary
When you stop using a Figma plugin that connects to Google Drive, that plugin still has access to your account until you explicitly remove it. Revoking access takes under a minute and is the correct hygiene step — here is exactly how to do it.
why does a figma plugin retain google drive access after you stop using it?
When you authorise a Figma plugin to connect to Google Drive, you grant it an OAuth token. That token lives in your Google account — not inside Figma. Uninstalling the plugin from Figma, or simply never opening it again, does not invalidate the token. The plugin's OAuth credentials remain active until Google's token expiry cycle or until you manually revoke them.
This is standard OAuth behaviour, not a flaw. The same applies to any third-party app you've ever connected to Google — Slack, Notion, Zapier. Stopping use is not the same as revoking access.
how to revoke google drive access from a figma plugin
Revocation is handled entirely in your Google account. Figma has no interface for it.
- Go to myaccount.google.com/permissions while signed in to the Google account you used during plugin authorisation.
- Find the plugin in the list of connected apps. It will appear under the name registered by the plugin developer — for ExportHub, this is ExportHub.
- Click the app name to expand its access details.
- Click Remove access, then confirm.
The token is revoked immediately. The plugin can no longer read or write to your Google Drive using those credentials. If you ever reinstall and reopen the plugin, it will prompt you to authorise again from scratch.
what access does a google drive figma plugin actually have?
The answer depends on the OAuth scope the plugin requested when you authorised it. There are two common scopes for Drive-connected plugins:
- drive.file — access only to files the plugin itself created or files you explicitly opened through it. This is the narrower, safer scope.
- drive — read and write access to all files in your Drive.
ExportHub requests drive.file scope only. It cannot read files it did not create, and it cannot access the rest of your Drive. You can verify the scope for any connected app on the same permissions page at myaccount.google.com/permissions — it is listed under the app's access details before you revoke.
If a plugin you no longer use holds broad Drive scope, revoking access is especially worth doing. See the full breakdown in Is it safe to authorize a Figma plugin for Google Drive?
what happens to files already exported after you revoke access?
Nothing. Revoking an OAuth token removes the plugin's ability to make future API calls on your behalf. Files already in your Drive are unaffected — they remain exactly where they are. The plugin simply loses the ability to upload, create folders, or read files going forward.
what if you don't see the plugin on the google permissions page?
Two reasons this happens:
- Wrong account. You may have authorised the plugin with a different Google account than the one you're currently viewing. Check all accounts you use in Figma.
- Token already expired. Google OAuth tokens expire if unused for an extended period — typically six months for inactive grants with sensitive scopes. If the plugin's token has already expired, Google removes it from the permissions list automatically. No action is needed.
If you use multiple Google accounts across client projects, the process for managing each one is covered in Switch Google accounts in a Figma plugin for separate client Drive spaces.
should you revoke access even if the plugin is still installed?
Yes, if you are not actively using it. An installed plugin that you haven't opened in months still holds valid credentials. Revoking access while keeping the plugin installed is a legitimate state — the plugin will simply ask to reconnect the next time you open it. Think of it as logging out rather than uninstalling.
This is particularly relevant for agency designers who connect plugins to client Google accounts. When a project ends, revoking Drive access for that client's account is the correct offboarding step — not just closing the Figma file.
how to reconnect a figma plugin to google drive after revoking access
Open the plugin inside Figma. Because the OAuth token has been revoked, the plugin will detect that its credentials are no longer valid and prompt a new sign-in. Click the authorisation prompt, choose the Google account you want to connect, and grant the requested permissions. The plugin is reconnected and ready to use.
The full OAuth flow — what it requests and why — is explained in Connect a Figma plugin to Google Drive: OAuth and folders.
a note on regular access audits
Most designers authorise a handful of tools and forget them. A quarterly audit of myaccount.google.com/permissions takes about two minutes and removes credentials from apps you've stopped using. It is the single highest-leverage account hygiene action for anyone who connects third-party tools to Google Workspace.
If you are evaluating which Figma-to-Drive plugin to connect in the first place, Figma to Google Drive plugins compared covers the current options with honest tradeoffs.
ExportHub is a Figma plugin built to export assets directly from Figma to Google Drive — no downloads, no upload loop. Get the free plugin.
FAQ
does uninstalling a figma plugin remove its google drive access?
No. Uninstalling a plugin from Figma does not revoke its OAuth token. You need to remove access manually via myaccount.google.com/permissions while signed in to the connected Google account.
how do i find which figma plugins have access to my google drive?
Go to myaccount.google.com/permissions. Every third-party app and plugin that has been authorised to access your Google account is listed there, including any Figma plugins connected to Drive.
will revoking google drive access delete my exported files?
No. Revoking access only prevents the plugin from making future API calls. Files already exported to your Drive remain untouched and fully accessible.
can a figma plugin access all my google drive files?
It depends on the OAuth scope it requested. Plugins using the drive.file scope can only access files they created — not your entire Drive. You can check the scope for any connected app on the Google permissions page before or after revoking access.
like reading? here's some more
free, forever, for everyone
give it a try today - you can remove exporthub at any moment



