Google WorkspaceCAUTION
MCP server for Google Drive, Docs, Sheets, Slides, Calendar, Gmail, and Contacts
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
MCP server providing Claude access to Google Drive, Docs, Sheets, Slides, Calendar, Gmail, and Contacts.
Quick Start
1. Set Up Google Cloud
- Go to the Google Cloud Console and create or select a project
- Enable all required APIs (one-click link)
- Go to APIs & Services > Credentials and create an OAuth 2.0 Client ID (Desktop app type)
- Copy the Client ID and Client Secret
2. Configure Claude Desktop
macOS: ~/Library/Application Support/Claude/claude_desktop_config.json Windows: %APPDATA%\Claude\claude_desktop_config.json
{
"mcpServers": {
"google-workspace": {
"command": "npx",
"args": ["@dguido/google-workspace-mcp"],
"env": {
"GOOGLE_CLIENT_ID": "YOUR_CLIENT_ID.apps.googleusercontent.com",
"GOOGLE_CLIENT_SECRET": "YOUR_CLIENT_SECRET",
"GOOGLE_WORKSPACE_SERVICES": "drive,gmail,calendar"
}
}
}
}That's it. On first tool call, a browser window opens for Google OAuth consent. Tokens are saved automatically.
Alternative: file-based credentials
Download the credentials JSON from Google Cloud Console and save to ~/.config/google-workspace-mcp/credentials.json, then authenticate manually:
npx @dguido/google-workspace-mcp auth
See Advanced Configuration for file-based setup, named profiles, and multi-account setup.
What You Can Do
Create a Google Doc called "Project Plan" in /Work/Projects with an outline for Q1.
Search for files containing "budget" and organize them into the Finance folder.
Create a presentation called "Prod
8cbe02646512OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add google-workspace-mcp --env GOOGLE_CLIENT_SECRET=${GOOGLE_CLIENT_SECRET} --env GOOGLE_WORKSPACE_MCP_TOKEN_PATH=${GOOGLE_WORKSPACE_MCP_TOKEN_PATH} -- npx -y @dguido/[email protected]{
"mcpServers": {
"google-workspace-mcp": {
"command": "npx",
"args": [
"-y",
"@dguido/[email protected]"
],
"env": {
"GOOGLE_CLIENT_SECRET": "${GOOGLE_CLIENT_SECRET}",
"GOOGLE_WORKSPACE_MCP_TOKEN_PATH": "${GOOGLE_WORKSPACE_MCP_TOKEN_PATH}"
}
}
}
}Exposed tools (71)
25 read · 32 write · 14 destructive. Blast radius: 14 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
action | read | Action to take: |
add_google_sheet_conditional_format | write | Add conditional formatting to a Sheet |
append_to_doc | read | Append text to the end of a Google Doc |
backup-folder | read | Export all files in a folder to a local directory. Google Docs are exported as their native formats. |
batch_delete | destructive | Batch move files to trash (max 100 per batch) |
batch_move | write | Batch move files to folder (max 100 per batch) |
batch_restore | read | Batch restore files from trash (max 100 per batch) |
batch_share | read | Batch share files with a user (max 100 per batch) |
cleanup-old-files | destructive | Find and optionally delete files older than a specified number of days. |
copy_file | read | Copy a file with optional new name |
create_contact | write | Create a new contact |
create_event | write | Create a new calendar event |
create_file | write | Create file (auto-detects type from name) |
create_filter | write | Create an email filter |
create_folder | write | Create a new folder in Google Drive |
create_google_doc | write | Create a new Google Doc |
create_google_sheet | write | Create a new Google Sheet |
create_google_slides | write | Create a new Google Slides presentation |
create_google_slides_shape | write | Create a shape in Google Slides |
create_google_slides_text_box | write | Create a text box in Google Slides |
create_text_file | write | Create a text or markdown file |
daysOld | read | Minimum age in days for files to be considered old |
delete_contact | destructive | Delete a contact |
delete_draft | destructive | Permanently delete one or more drafts by ID (max 100). |
delete_email | destructive | Delete emails permanently (max 1000 IDs per request) |
delete_event | destructive | Delete a calendar event |
delete_filter | destructive | Delete an email filter |
delete_item | destructive | Move items to trash |
delete_label | destructive | Delete a user-created label |
delete_text_in_doc | destructive | Delete text range from a Google Doc |
draft_email | write | Create or update a draft email. Omit draftId to create new; |
emails | read | Comma-separated list of email addresses |
empty_trash | destructive | Permanently delete all files in trash |
fileIds | read | Comma-separated list of file IDs to share |
fileTypes | read | Comma-separated file types to convert: doc, xls, ppt (or |
folderId | read | The ID of the folder to organize (use |
format_google_doc_range | read | Format text and paragraphs in a Doc |
format_google_sheet_cells | read | Format cells in a Google Sheet |
format_slide_background | write | Set slide background color in Google Slides |
format_slides_shape | read | Format shape fill and outline in Google Slides |
format_slides_text | read | Format text styling in Google Slides |
get_or_create_label | write | Get or create a Gmail label |
insert_text_in_doc | write | Insert text at a position in a Doc |
localPath | write | Local directory path to save the backup |
merge_google_sheet_cells | write | Merge cells in a Google Sheet |
migrate-format | read | Convert Office files to Google Workspace formats for editing, or convert legacy binary formats (.doc, .xls, .ppt) for reading. |
modify_email | destructive | Add/remove labels on threads (max 1000 IDs per request) |
move_item | write | Move items to a new folder |
organize-folder | read | Organize files in a folder by type or date. Creates subfolders and moves files accordingly. |
organizeBy | read | How to organize: |
remove_permission | destructive | Remove sharing permission from a file |
rename_item | write | Rename a file or folder |
replace_text_in_doc | read | Find and replace text in a Doc |
restore_from_trash | read | Restore a file from trash |
restore_revision | read | Restore file to previous revision |
role | read | Permission role: reader, commenter, or writer |
send_email | write | Send an email |
share-with-team | read | Share multiple files with a list of email addresses with specified permissions. |
share_file | read | Share a file with a user, group, domain, or make public |
sheet_tabs | destructive | Manage tabs in a spreadsheet: list, create, delete, or rename |
slides_speaker_notes | write | Get or update speaker notes for a slide |
star_file | read | Star or unstar a file in Google Drive |
update_contact | write | Update an existing contact |
update_event | write | Update an existing calendar event |
update_file | write | Update file (auto-detects type) |
update_google_doc | write | Replace content in a Google Doc |
update_google_sheet | write | Update a Google Sheet range |
update_google_slides | write | Update a Google Slides presentation |
update_label | write | Update an existing Gmail label |
update_text_file | write | Update content of a text or markdown file in Google Drive |
upload_file | write | Upload file from disk or base64 |
Trust audit
CAUTIONgrade B · trust 81/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (1 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (11)
redirectUri: credentials.redirect_uris?.[0] || "http://127.0.0.1/oauth2callback",
log("service account", { private_key: "-----BEGIN RSA PRIVATE KEY-----\nMIIE..." });log("debug", { key: "-----BEGIN PRIVATE KEY-----\nMIIE..." });batch_delete, cleanup-old-files, delete_contact, delete_draft, delete_email, delete_event, delete_filter, delete_item, delete_label, delete_text_in_doc, empty_trash, modify_email, remove_permission, s
.oxlintrc.json
.pre-commit-config.yaml
3. Authenticate with Google — the browser redirects to `http://127.0.0.1:<port>/...`
"http://127.0.0.1:54321/oauth2callback" + "?code=4/0AQSTthis_is_the_code&state=abc123";
const input = "http://127.0.0.1:54321/oauth2callback" + "?code=4/0AQSTthis_is_the_code";
const input = "http://127.0.0.1:54321/oauth2callback?error=access_denied";
@toon-format/toon, zod, oxfmt
Gates applied: no_behavioural_pass.
8cbe02646512full audit observations/trust-audit/mcp-server/dguido__google-workspace-13.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 8cbe02646512 | CAUTION | B | 81 | first audit |
Questions
What is the Google Workspace MCP server?
MCP server for Google Drive, Docs, Sheets, Slides, Calendar, Gmail, and Contacts
What tools does Google Workspace expose?
71 in total: 25 read-only, 32 that write, and 14 that can delete or overwrite (batch_delete, cleanup-old-files, delete_contact, delete_draft, delete_email). Every one is listed on this page with its risk.
Is Google Workspace safe to connect to an agent?
With care. The audit graded it B (81/100) and found 11 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 14 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Google Workspace need?
It reads GOOGLE_CLIENT_SECRET and GOOGLE_WORKSPACE_MCP_TOKEN_PATH from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Google Workspace run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as @dguido/google-workspace-mcp at 3.4.4.
How current is this page?
The grade is for one exact copy of the source (8cbe02646512), read on 2026-10-08. The repository is watched and re-audited when it changes.