Atlas / MCP servers / a-bonus / Google Docs

Google DocsCAUTION

mcp/a-bonus/google-docs

The Ultimate Google Docs, Sheets, Drive, Gmail, & Google Calendar MCP Server. This MCP (primarily for use in Claude Desktop) gains full access to your google suite and lets claude do its thing.

Verdict
CAUTION
Grade
B
Trust score
89 /100
Exposed tools
121 112r · 7w · 2d
Transport
streamable-http
License
MIT
Stars
664
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://mcptoplist.com/server/glama%2Fa-bonus%2Fgoogle-docs-mcp)

Connect Claude Desktop, Cursor, or any MCP client to your Google Docs, Google Sheets, Google Drive, Gmail, and Google Calendar.

Quick Start

1. Create a Google Cloud OAuth Client

  1. Go to the Google Cloud Console
  2. Create or select a project
  3. Enable the Google Docs API, Google Sheets API, Google Drive API, Gmail API, and Google Calendar API
  4. Configure the OAuth consent screen (External, add your email as a test user, and add the gmail.modify and calendar.events scopes alongside the Docs/Sheets/Drive scopes)
  5. Create an OAuth client ID (Desktop app type)
  6. Copy the Client ID and Client Secret from the confirmation screen
Need more detail? See step-by-step instructions at the bottom of this page.

2. Authorize

GOOGLE_CLIENT_ID="your-client-id" \
GOOGLE_CLIENT_SECRET="your-client-secret" \
npx -y @a-bonus/google-docs-mcp auth

This opens your browser for Google authorization. After you approve, the refresh token is saved to ~/.config/google-docs-mcp/token.json.

3. Add to Your MCP Client

Claude Desktop / Cursor / Windsurf:

{
"mcpServers": {
"google-docs": {
"command": "npx",
"args": ["-y", "@a-bonus/google-docs-mcp"],
"env": {
"GOOGLE_CLIENT_ID": "your-client-id",
"GOOGLE_CLIENT_SECRET": "your-client-secret"
}
}
}
}

The server starts automatically when your MCP client needs it.

Remote Deployment (Cloud Run)

Deploy once for your team -- no local installs required. The server uses MCP OAuth 2.1 so your MCP client handles authentication automatically.

gcloud run deploy google-docs-
Read from source at commit bab48508c25bOBSERVED · 2026-09-28
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add google-docs-mcp --env GOOGLE_CLIENT_SECRET=${GOOGLE_CLIENT_SECRET} --env JWT_SIGNING_KEY=${JWT_SIGNING_KEY} --env TOKEN_ENCRYPTION_KEY=${TOKEN_ENCRYPTION_KEY} --env TOKEN_STORE=${TOKEN_STORE} -- npx -y @a-bonus/[email protected]
claude-desktop
{
  "mcpServers": {
    "google-docs-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "@a-bonus/[email protected]"
      ],
      "env": {
        "GOOGLE_CLIENT_SECRET": "${GOOGLE_CLIENT_SECRET}",
        "JWT_SIGNING_KEY": "${JWT_SIGNING_KEY}",
        "TOKEN_ENCRYPTION_KEY": "${TOKEN_ENCRYPTION_KEY}",
        "TOKEN_STORE": "${TOKEN_STORE}"
      }
    }
  }
}
03

Exposed tools (121)

112 read · 7 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
addCommentreadAdds a comment to the document at the specified text range. Use listComments to retrieve the comment ID after creation. Note: programmatically created comments appear in the comments panel but may not show as anchored highlights in the document UI.
addConditionalFormattingreadAdds a conditional formatting rule to one or more ranges in a spreadsheet. Applies a format (background color, bold, text color, etc.) when cells meet a specified condition. Use CUSTOM_FORMULA for complex conditions like
addSheetreadAdds a new sheet (tab) to an existing spreadsheet. Returns the new sheet
addTabwriteAdds a new tab to a Google Docs document. Optionally set the tab title, position, parent tab (for nesting), and icon emoji. Returns the new tab
appendMarkdownreadAppends formatted content to the end of a document using markdown syntax. Supports headings, bold, italic, strikethrough, links, and bullet/numbered lists. Use this instead of appendText when you need formatting.
appendRowsreadAppends rows to the end of a sheet. Data is added after the last row with content in the specified range.
appendTableRowsreadAppends one or more plain-text rows to the end of an existing Google Docs table while preserving the table structure.
appendTextreadAppends plain text to the end of a document. For formatted content, use appendMarkdown instead.
applyParagraphStylereadApplies paragraph-level formatting (alignment, spacing, heading styles) to paragraphs identified by a character range or by searching for text. Use namedStyleType to set heading levels (HEADING_1 through HEADING_6).
applyTextStylereadApplies character-level formatting (bold, italic, color, font, etc.) to text identified by a character range or by searching for a text string. This is the primary tool for styling text in a document.
autoResizeColumnsreadAuto-resizes columns in a spreadsheet to fit their content. Optionally restrict to a column range (e.g.,
autoResizeRowsreadAuto-resizes rows in a spreadsheet to fit their content. Optionally restrict to a row range (e.g., startRow=2, endRow=50); defaults to all rows.
batchApplyTextStylereadApplies character-level formatting (bold, italic, color, font, etc.) to MANY ranges in a single tool
batchWritereadWrites data to multiple ranges in a single API call. More efficient than multiple separate writeSpreadsheet calls when updating several ranges at once.
clearRangereadClears all cell values in a range without deleting the cells themselves. Formatting is preserved.
cloneTablereadClones a source Google Docs table into a target document, preserving text, column widths, row styles, cell styles, and pinned header rows where supported.
copyFilereadCreates a copy of a file or document in Google Drive. Returns the new copy
copyFormattingreadCopies formatting (not values) from a source range to a destination range within the same spreadsheet. Copies bold, colors, borders, number formats, etc.
copySheetToreadCopies a sheet (tab) from one spreadsheet to another spreadsheet. Use getSpreadsheetInfo to find the numeric sheet ID. The copied sheet will be appended to the destination spreadsheet.
createAppsScriptProjectreadCreates an Apps Script project, optionally bound to a Doc, Sheet, Slides or Form so its triggers and custom menus run inside that file. Optionally writes the initial files in the same call. Requires the Apps Script API to be enabled at https://script.google.com/home/usersettings.
createDocumentreadCreates a new empty Google Document. Optionally places it in a specific folder and adds initial text content.
createDocumentFromTemplatereadCreates a new document by copying an existing template and optionally replacing placeholder text. Provide key-value pairs in the replacements parameter to substitute template variables.
createDraftwriteCreates a Gmail draft (does NOT send). Use this for AI-composed emails that the user should review before sending. The draft appears in the Gmail Drafts folder and can be sent later with sendDraft, edited with updateDraft, or deleted with deleteDraft. Supports threading via replyToMessageId.
createEventwriteCreates a new event on a Google Calendar. Supports timed events (start/end with dateTime) and all-day events (start/end with date). Set sendUpdates to email invitations to attendees.
createFolderreadCreates a new folder in Google Drive. Optionally places it inside an existing parent folder.
createSheetsCellNotereadCreates or replaces a native Google Sheets cell note on a cell or range. Use this when the review text must be attached to a specific cell in the Sheets UI. This is a cell note, not a threaded Drive comment.
createSpreadsheetreadCreates a new spreadsheet. Optionally places it in a specific folder and populates it with initial data.
createTablereadCreates a new named table with specific column types. Tables provide structured data with typed columns, automatic formatting, and special features like dropdown validation.
deleteChartreadDeletes a chart from a Google Spreadsheet by chart ID.
deleteCommentreadPermanently deletes a comment and all its replies from the document.
deleteConditionalFormattingreadDeletes one or more conditional formatting rules from a sheet by their index. Use getConditionalFormatting to list existing rules and their indices.
deleteDraftreadPermanently deletes a Gmail draft. This is irreversible — the draft is removed entirely, not moved to Trash. Use when an AI-composed draft was rejected or replaced.
deleteEventdestructiveDeletes an event from a Google Calendar. This is permanent — the event is removed, not trashed. Use sendUpdates to email cancellations to attendees.
deleteFilewriteMoves a file or folder to the trash, or permanently deletes it. Set permanent=true for irreversible deletion.
deleteRangereadDeletes content within a character range [startIndex, endIndex) from a document. Use readDocument with format=
deleteSheetreadDeletes a sheet (tab) from a spreadsheet. Use getSpreadsheetInfo to find the numeric sheet ID.
deleteSheetsCommentreadPermanently deletes a comment and all its replies from a Google Spreadsheet.
deleteTablereadDeletes a table from a spreadsheet. By default, only removes the table object and formatting while keeping the cell data. Optionally clears the data as well.
deleteTableRowsreadDeletes one or more rows from an existing Google Docs table without replacing the whole document.
downloadFilereadDownloads any file from Google Drive to a local path.
duplicateSheetreadDuplicates a sheet (tab) within a spreadsheet, copying all values, formulas, formatting, validations, and conditional formatting. Use getSpreadsheetInfo to find the numeric sheet ID.
findAndReplacereadReplaces all occurrences of a text string throughout the document (or a specific tab).
findElementreadLocates elements in a Google Document. With textQuery, returns the document index range (startIndex/endIndex) of every non-overlapping occurrence of the text — use each as a range for deleteRange or the text-styling tools, or its startIndex as an insertText location. With elementType
findSectionsByHeadingreadFinds heading-based sections in a Google Document and reports heading ranges plus the first table that follows each heading.
formatCellsreadApplies formatting to a range of cells in a spreadsheet. Supports bold, italic, font size, text color, background color, alignment, and number format. Use range
freezeRowsAndColumnsreadPins rows and/or columns so they stay visible when scrolling. Use frozenRows=1 to freeze a header row. Set a value to 0 to unfreeze.
getAppsScriptContentreadReads the files of an Apps Script project. Use it before updateAppsScriptContent to see what is already there, or to review code that is currently deployed.
getCommentreadGets a specific comment and its full reply thread. Use listComments first to find the comment ID.
getConditionalFormattingreadLists all conditional formatting rules for a sheet as JSON. Each rule includes its index (needed for deleteConditionalFormatting), kind (BOOLEAN or GRADIENT), ranges, condition type/values, and applied formats (colors, bold, italic).
getDocumentInforeadGets metadata about a document including its name, owner, sharing status, and modification history.
getDraftreadFetches a single Gmail draft by ID with full headers and body. Use listDrafts to discover draft IDs.
getFolderInforeadGets metadata about a Drive folder including its name, owner, sharing status, and parent folder.
getMessagereadFetches a single Gmail message by ID with headers, decoded plain-text body, HTML body, and a list of attachments (metadata only). Use listMessages to discover message IDs.
getSheetsCommentreadGets a specific comment and its full reply thread from a Google Spreadsheet. Use listSheetsComments first to find the comment ID.
getSpreadsheetInforeadGets metadata about a spreadsheet including its title, URL, and a list of all sheets with their dimensions.
getTablereadGets detailed information about a specific table including its columns, range, and properties. Use the table name or ID returned by listTables.
getTableStructurereadReturns detailed structure for a table in a Google Document, including row/column counts and extracted cell text.
groupRowsreadCreates collapsible row groups in a Google Sheet using the Sheets API addDimensionGroup request. Each group specifies a range of rows (1-based, inclusive) to collapse.
insertChartreadInserts a chart into a Google Sheet. Supports bar, column, line, area, scatter, pie, donut, and treemap (hierarchical) chart types.
insertDateChipreadInserts a Google Docs date smart chip at a specific paragraph location. This creates a real date element, not plain text.
insertImagereadInserts an inline image into a Google Document. Provide either a publicly accessible URL or a local file path. Local files are automatically uploaded to Google Drive before insertion.
insertPageBreakreadInserts a page break at a character index in the document.
insertPersonreadInserts a Google Docs person smart chip at a specific paragraph location using an email address.
insertRichLinkreadInserts a Google Docs rich link smart chip at a specific paragraph location. Use for Google resource links such as Drive files or Calendar events.
insertSectionBreakreadInserts a section break at a character index in the document. A section break starts a new section whose style (page orientation, margins, columns, page numbering) can then be customized with updateSectionStyle. Use sectionType=
insertTablereadInserts an empty table with the specified number of rows and columns at a character index in the document.
insertTableWithDatareadInserts a table pre-populated with data at a specific index in the document.
insertTextreadInserts text at a specific character index within a document. Use readDocument with format=
listCommentsreadLists all comments in a document with their IDs, authors, status, and quoted text. Returns data needed to call getComment, replyToComment, resolveComment, or deleteComment.
listDocumentTablesreadLists tables in a Google Document with stable MCP table IDs, ranges, and dimensions. Use this before table-specific editing tools.
listDocumentsreadLists Google Documents in your Drive, optionally filtered by name or content. Use modifiedAfter to find recently changed documents.
listDraftsreadLists Gmail drafts for the authenticated user. Returns draft IDs along with the recipient, subject, snippet, and date for each. Use sendDraft, updateDraft, or deleteDraft to act on a returned draft.
listDriveFilesreadLists files across Google Drive with optional filtering by type, folder, and ownership.
listEventsreadLists or searches Google Calendar events. Defaults to the user
listFolderContentsreadLists files and subfolders within a Drive folder. Use folderId=
listLabelsreadLists all Gmail labels for the authenticated user, including system labels (INBOX, SENT, STARRED, UNREAD, etc.) and custom user-created labels. Use the returned IDs with modifyMessageLabels or listMessages labelIds filter.
listMessagesreadLists Gmail messages for the authenticated user. Supports the full Gmail search syntax via the q parameter (e.g.
listSheetsCommentsreadLists all comments in a Google Spreadsheet. Filter by sheet name, specific row(s), specific cell, or a cell range. Returns comment IDs needed for getSheetsComment, replyToSheetsComment, resolveSheetsComment, or deleteSheetsComment.
listSmartChipsreadLists smart chips in a Google Document, including date elements, person mentions, and rich links.
listSpreadsheetsreadLists spreadsheets in your Drive, optionally filtered by name or content.
listTablesreadLists all tables in a spreadsheet or specific sheet. Use this to discover table names and IDs before performing table operations.
listTabsreadLists all tabs in a document with their IDs and hierarchy. Use the returned tab IDs with other tools
modifyMessageLabelswriteAdds and/or removes labels on a Gmail message. Use this to star (add STARRED), archive (remove INBOX), mark read (remove UNREAD), or apply custom labels. Discover label IDs with listLabels. At least one of addLabelIds or removeLabelIds must be provided.
modifyTextreadCombines text replacement/insertion and formatting in one atomic operation.
moveFilereadMoves a file or folder to a different Drive folder. By default adds the new parent while keeping existing parents; set removeFromAllParents=true for a true move.
protectRangereadLocks (protects) a range or an entire sheet to prevent accidental edits. Optionally specify a description. The protection applies to the authenticated user
quickAddEventreadCreates a calendar event from a natural-language string using Google Calendar\
readCellFormatreadReads the formatting/style of cells in a given range. Returns formatting details like bold, italic, fontSize, fontFamily, colors, alignment, borders, and number format per cell.
readDocumentreadReads the content of a Google Document. Returns plain text by default. Use format=
readSpreadsheetreadReads data from a range in a spreadsheet. Returns rows as arrays. Use A1 notation for the range (e.g.,
renameFilereadRenames a file or folder in Google Drive. Returns the updated file info.
renameSheetreadRenames a sheet (tab) in a spreadsheet. Use getSpreadsheetInfo to find the numeric sheet ID.
renameTabreadRenames a tab in a Google Docs document. Use listDocumentTabs to get tab IDs first.
replaceDocumentWithMarkdownreadReplaces the entire document body with content parsed from markdown. Supports headings, bold, italic, strikethrough, links, and bullet/numbered lists. Use readDocument with format=
replaceRangeWithMarkdownreadReplaces a specific character range in a document with formatted markdown content. Use readDocument with format=
replaceTableRowDatareadReplaces the plain-text contents of a single row in an existing Google Docs table while preserving the table structure and formatting.
replyToCommentreadAdds a reply to an existing comment thread. Use listComments or getComment to find the comment ID.
replyToSheetsCommentreadAdds a reply to an existing comment thread in a Google Spreadsheet. Use listSheetsComments or getSheetsComment to find the comment ID.
resolveCommentreadMarks a comment as resolved. Note: resolved status may not persist in the Google Docs UI due to a Drive API limitation.
resolveSheetsCommentreadMarks a comment as resolved in a Google Spreadsheet. Note: resolved status may not persist in the Sheets UI due to a Drive API limitation.
searchDocumentsreadSearches for documents by name, content, or both. Use listDocuments for browsing and this tool for targeted queries.
searchDriveFilesreadSearches across all file types in Google Drive by name or content.
sendDraftreadSends an existing Gmail draft. After sending, the draft is removed and the message appears in Sent. This is the second half of the compose-review-send flow that pairs with createDraft.
sendEmailreadSends a plain-text email from the authenticated Gmail account. Supports cc/bcc and optional threading by passing replyToMessageId (which copies threadId and sets In-Reply-To/References so the reply lands in the same thread).
setCellBordersreadSets borders on a range of cells. Each side (top, bottom, left, right, innerHorizontal, innerVertical) can be configured independently with a style and color. Use style
setColumnWidthsreadSets the width (in pixels) of one or more columns in a spreadsheet. Accepts multiple column specs in a single call, each targeting a single column or a contiguous range (e.g.,
setDropdownValidationwriteAdds or removes a dropdown list on a range of cells. Provide values to create a dropdown restricting input to those options. Omit values to remove dropdown validation from the range.
setFilePermissionreadSets a sharing permission on a Drive file or folder. Common case: type=
setRowHeightsreadSets a fixed pixel height for a range of rows in a spreadsheet. Useful for ensuring rows are tall enough to display wrapped text.
trashMessagedestructiveMoves a Gmail message to Trash. This is the same as clicking Delete in the Gmail UI — reversible from the Trash folder for 30 days. Not a permanent delete.
triageInboxreadComposite tool: fetches the user
ungroupAllRowsreadRemoves all row groupings from a sheet by deleting the entire row dimension group. Use before re-running groupRows to prevent duplicate collapse widgets from accumulating across report refreshes.
updateAppsScriptContentreadWrites files into an existing Apps Script project. Default mode
updateDraftreadReplaces the contents of an existing Gmail draft. The new contents fully overwrite the old draft (this is a full replace, not a patch). Use this when iterating on an AI-composed draft before sending.
updateEventwriteUpdates an existing Google Calendar event with PATCH semantics — only the fields you provide are changed; everything else stays the same. Common uses: reschedule (set start+end), retitle (set summary), add/remove attendees (set attendees array which fully replaces).
updateTableBordersreadApplies table border styles to a Google Docs table range. Supports top/bottom/left/right borders across a cell range.
updateTableCellStylereadApplies cell-level formatting to a Google Docs table range, including background color, alignment, padding, and borders.
updateTableColumnWidthreadSets fixed widths for one or more columns in an existing Google Docs table.
updateTableRangereadModifies a table
updateTableRowStylereadApplies row-level styling to a Google Docs table, including minimum row height and optional pinned header rows.
writeSpreadsheetreadWrites data to a range in a spreadsheet, overwriting existing values. Use appendRows to add data without overwriting.
04

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (6 observation(s))
Network
declared (2 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (12)

MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
src/index.ts:229
logger.info(`MCP Server running at ${process.env.BASE_URL || `http://0.0.0.0:${port}`}/mcp`);
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
deleteEvent, trashMessage
Why it matters. 2 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.prettierignore
.prettierignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/tools/calendar/createEvent.ts:5
import { getCalendarClient } from '../../clients.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/tools/calendar/deleteEvent.ts:4
import { getCalendarClient } from '../../clients.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/tools/calendar/listEvents.ts:4
import { getCalendarClient } from '../../clients.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/tools/calendar/quickAddEvent.ts:4
import { getCalendarClient } from '../../clients.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/tools/calendar/updateEvent.ts:5
import { getCalendarClient } from '../../clients.js';
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
src/oauthRefresh.repro.test.ts:95
base = `http://127.0.0.1:${(server.address() as AddressInfo).port}`;
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@google-cloud/firestore, fastmcp, google-auth-library, googleapis, markdown-it, xsschema, zod, @types/markdown-it
Why it matters. 13 dependency range(s) float
Fix. pin exact versions or ship a lockfile
INFOInventory / provenance · inv.oversize · CWE-1104
assets/google.docs.mcp.1.gif
assets/google.docs.mcp.1.gif
Why it matters. 13109304 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
google docs mcp.mp4
google docs mcp.mp4
Why it matters. 20297599 bytes not read

Gates applied: no_behavioural_pass.

Audited 2026-09-28 · audit v0.4.1 · source sha bab48508c25bfull audit observations/trust-audit/mcp-server/a-bonus__google-docs.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-28bab48508c25bCAUTIONB89first audit
06

Questions

What is the Google Docs MCP server?

The Ultimate Google Docs, Sheets, Drive, Gmail, & Google Calendar MCP Server. This MCP (primarily for use in Claude Desktop) gains full access to your google suite and lets claude do its thing.

What tools does Google Docs expose?

121 in total: 112 read-only, 7 that write, and 2 that can delete or overwrite (deleteEvent, trashMessage). Every one is listed on this page with its risk.

Is Google Docs safe to connect to an agent?

With care. The audit graded it B (89/100) and found 12 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Google Docs need?

It reads GOOGLE_CLIENT_SECRET, JWT_SIGNING_KEY, TOKEN_ENCRYPTION_KEY and TOKEN_STORE from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Google Docs run?

It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as @a-bonus/google-docs-mcp at 1.11.3.

How current is this page?

The grade is for one exact copy of the source (bab48508c25b), read on 2026-09-28. The repository is watched and re-audited when it changes.

Advertisement