Allow QR to Sheets in your Google Workspace
QR to Sheets is a browser scanner that writes each scanned code as a row in a Google Sheet the teacher or staff member owns. If your Google Workspace restricts third-party apps, a staff member who tries to connect QR to Sheets is stopped by Google with an error such as admin_policy_enforced or access_not_configured, and a Google Workspace admin has to allow the app once in the Admin console.
Written by the QR to Sheets team. Last updated .
Who needs access, and who does not
Only the staff member who sets up QR to Sheets signs in with Google. Students never sign in, never open the scanner link and need no account: staff scan the code on a student's card. So no student organizational unit needs this app, and the separate setting Google applies to users designated as under 18 does not come into play.
The phone that scans opens a web link and needs no Google account either. Each phone that scans counts as one device. Free covers one phone; Premium is $7 per phone per month. People being scanned never open the link and need nothing.
Source: Google, Manage access to unconfigured third-party apps for users designated as under 18, read on .
What QR to Sheets asks Google for
QR to Sheets asks for two separate approvals, each under its own client ID:
- Sign-in: the staff member's name, email address and profile photo.
- Google Sheets connection: access to only the spreadsheets the staff member picks in Google's own file picker or creates with QR to Sheets. It cannot open or list any other file in that Drive.
The Drive access QR to Sheets uses is not on Google's list of high-risk Drive scopes. Google gives "scopes that allow apps to access user-selected files in Drive" as its example of a scope that is not classified as high-risk. The exact permission list is in our privacy policy.
Source: Google, Control which apps access Google Workspace data, read on .
Steps in the Google Admin console
Do this once. It takes a few minutes, and nothing needs installing on staff phones or student devices.
Open API controls
Sign in to the Google Admin console with an account that has the Service Settings administrator privilege, then go to Menu > Security > Access and data control > API controls.
Start configuring a new app
Click Manage App Access (some consoles label it Manage Third-Party App Access). Under Configured apps, click Configure new app (or Add app, then OAuth App Name or Client ID).
Find QR to Sheets by its client ID
Paste the Sign-in client ID from the list below, click Search, and select the app in the results.
Choose who it applies to
For Scope, select only your staff organizational units: students never sign in, so they do not need it. Choosing the top organizational unit allows it for everyone. Click Continue.
Choose the access level
For Access to Google data, choose Trusted, then click Continue and Finish.
Repeat for the second client ID
Repeat steps 2 to 5 with the Google Sheets connection client ID. Google says changes can take up to 24 hours but typically happen more quickly.
Prefer not to choose Trusted?
Limited also works when your Drive service is unrestricted: Google describes a Limited app as one users can sign in to that can request only unrestricted Google data. If your Drive service is Restricted, choose Trusted, or turn on the Drive service setting Google names "For apps that are not trusted, allow users to give access to OAuth scopes that aren't classified as high-risk".
Source: Google, Control which apps access Google Workspace data, read on .
Source: Google, Control which third-party & internal apps access Google Workspace data, read on .
QR to Sheets client IDs
Configure both. If your settings block all unconfigured third-party apps, Google blocks the sign-in as well as the Sheets connection. These are public identifiers that appear in the web address of every Google approval screen QR to Sheets opens; they are not secrets.
Sign-in
Sign in with Google for the staff member who sets up QR to Sheets: name, email address and profile photo.
308354423415-1khvffepkmundrgsu0f0oi6qpkagld73.apps.googleusercontent.comGoogle Sheets connection
The second approval, which lets QR to Sheets open and add rows to only the spreadsheets the staff member picks or creates with it.
308354423415-mumh0omgin16cn3mbaofnlent4ust4b0.apps.googleusercontent.comIf a teacher sees access_not_configured or admin_policy_enforced
Both are Google errors, and both mean your Workspace settings stopped the approval, not that QR to Sheets is down. Google's help says a "400 access_not_configured" error means "the app has not been properly configured by a Workspace for Education Administrator", and that "400 admin_policy_enforced" can happen "when you use an account from work or another organization". The steps above clear both. After they take effect, the teacher clicks Connect Google again in QR to Sheets.
Source: Google, Understand and fix error codes, read on .
Source: Google, Using OAuth 2.0 for Web Server Applications, Errors, read on .
What QR to Sheets stores and who can see it
- From Google sign-in: the staff member's name, email address and profile photo.
- For each scan: the scanned value, the scan time, the scanner link's name, the device type and a random device identifier made by the phone's browser. Each scan is written to the school's own Google Sheet, and QR to Sheets keeps a copy on servers in the United States.
- Nothing about the person scanning, who has no account. No photos: the camera picture is read on the phone and only the decoded text is sent. No location.
- Google access tokens are stored encrypted.
- Scan data is private to the workspace: it is never sold, never shared with other customers or advertisers, never used for advertising, and used only to run and support the service.
- Deleting the workspace in Settings deletes its scans, links, devices and Google connection at once, and the owner's account if it was their only workspace; Google access can be revoked at any time at myaccount.google.com/permissions. Rows already in the school's Sheet stay there.
We suggest codes carry a student ID number rather than a name. The details are in our privacy policy and in Is QR to Sheets safe for student data?.
Questions
Email hello@qrtosheets.com. If you are the teacher, forward this page to your IT team: the address is qrtosheets.com/google-workspace-admin.
Related guides
- Is QR to Sheets safe for student data? What it stores, who sees it, how to delete itWhat QR to Sheets stores when staff scan a student code, who can see it, where it is kept, how to delete it, and how a school Google admin allows it.Read the guide
- How to take QR code attendance in Google Sheets for freeFree QR code attendance tracking with a Google Form and a Sheet, step by step. Where it breaks for schools and clubs, and the no-app staff-scan fix.Read the guide
- Daily classroom attendance for teachers, with QR codes and Google SheetsHow a teacher takes daily class attendance with QR codes: print one card per student, scan the room from your phone, read absences in Google Sheets.Read the guide
- How to scan student or staff ID cards for attendance into Google SheetsScan the ID cards students or staff already carry into Google Sheets: which barcodes a phone reads, plus the free USB scanner and Google Form routes.Read the guide