GSheetsBLOCK
MCP server for Google Sheets - Read, write and manipulate spreadsheets through Claude Desktop
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://www.npmjs.com/package/mcp-gsheets)
A Model Context Protocol (MCP) server for Google Sheets API integration. Enables reading, writing, and managing Google Sheets documents directly from your MCP client (e.g., Claude Code, Claude Desktop, Cursor, etc.).
Key Features
- Complete Google Sheets Integration: Read, write, and manage spreadsheets
- Advanced Operations: Batch operations, formatting, charts, and conditional formatting
- Flexible Authentication: Support for both file-based and JSON string credentials
- Production Ready: Built with TypeScript, comprehensive error handling, and full test coverage
Requirements
- Node.js v20 or higher
- Google Cloud Project with Sheets API enabled
- Service Account with JSON key file
- npm
Getting Started
Quick Install (Recommended)
Add the following config to your MCP client:
{
"mcpServers": {
"mcp-gsheets": {
"command": "npx",
"args": ["-y", "mcp-gsheets@latest"],
"env": {
"GOOGLE_PROJECT_ID": "your-project-id",
"GOOGLE_APPLICATION_CREDENTIALS": "/aca65998c41acOBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add mcp-gsheets --env GOOGLE_SERVICE_ACCOUNT_KEY=${GOOGLE_SERVICE_ACCOUNT_KEY} --env GOOGLE_PRIVATE_KEY=${GOOGLE_PRIVATE_KEY} -- npx -y [email protected]Exposed tools (56)
28 read · 21 write · 7 destructive. Blast radius: 7 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
analysisType | read | Type of analysis: |
chartType | read | Preferred chart type: |
create-chart-guide | write | Step-by-step guide to create a chart from spreadsheet data |
create-table | write | Guide for creating a new table with headers and data in a Google Spreadsheet |
dataDescription | write | Description of the data/table you want to create |
dataRange | read | The range containing data for the chart (e.g., |
format-report | read | Format existing data as a professional report with headers, borders, and styling |
range | read | The range containing data to format (e.g., |
reportStyle | read | Style preference: |
sheetName | write | Name of the sheet to create the table in (default: Sheet1) |
sheets_add_conditional_formatting | write | Add conditional formatting rules to a Google Sheet |
sheets_add_table | write | Create a native Google Sheets table with typed columns and optional dropdown values |
sheets_append_values | read | Append values to the end of a table in a Google Sheets spreadsheet. |
sheets_batch_delete_sheets | destructive | Delete multiple sheets from a Google Sheets spreadsheet in a single operation |
sheets_batch_format_cells | read | Format multiple cell ranges in a Google Sheet in a single operation |
sheets_batch_get_values | read | Get values from multiple ranges in a Google Sheets spreadsheet |
sheets_batch_update_values | write | Update values in multiple ranges of a Google Sheets spreadsheet |
sheets_check_access | read | Check access permissions for a spreadsheet. Returns information about what operations are allowed. |
sheets_clear_values | destructive | Clear values in a specified range of a Google Sheets spreadsheet |
sheets_compare_ranges | read | Compare cell formatting between two ranges of identical dimensions. |
sheets_copy_to | read | Copy a sheet to another Google Sheets spreadsheet |
sheets_create_chart | write | Create a chart in a Google Sheets spreadsheet. Sheet names with spaces should be quoted in ranges (e.g., |
sheets_create_spreadsheet | write | Create a new Google Sheets spreadsheet |
sheets_delete_chart | destructive | Delete a chart from a Google Sheets spreadsheet |
sheets_delete_columns | destructive | Delete one or more columns from a Google Sheet using a full-column A1 range |
sheets_delete_rows | destructive | Delete one or more rows from a Google Sheet using a full-row A1 range |
sheets_delete_sheet | destructive | Delete a sheet from a Google Sheets spreadsheet |
sheets_delete_table | destructive | Delete a native Google Sheets table by tableId |
sheets_duplicate_sheet | read | Duplicate a sheet within a Google Sheets spreadsheet |
sheets_format_cells | read | Format cells in a Google Sheet (colors, fonts, alignment, number formats) |
sheets_get_basic_filter | read | Read the Basic Filter (AutoFilter) configuration for a sheet, including the filtered range, |
sheets_get_border_map | read | Returns a visual tabular map of borders for a range. |
sheets_get_conditional_formatting | read | Read conditional formatting rules and banded ranges (alternating row/column colors) for a sheet. |
sheets_get_data_validation | read | Read data validation rules (checkboxes, dropdown lists, custom formulas, etc.) from a sheet or range. |
sheets_get_formatting_compact | read | Returns cell formatting for a range as compact A1Range→format pairs. |
sheets_get_full_sheet_snapshot | read | One-shot tool: reads all structural and formatting metadata for a sheet in a single API call. |
sheets_get_merged_cells | write | Get all merged cell ranges for a specific sheet. Returns each merge as A1 notation and GridRange coordinates. |
sheets_get_metadata | read | Get metadata about a Google Sheets spreadsheet including sheet names, IDs, and properties |
sheets_get_sheet_dimensions | read | Get column widths (pixelSize), row heights (pixelSize), hidden columns/rows, and frozen row/column counts for a sheet. |
sheets_get_sheet_formatting | read | Read cell formatting (background color, text color, font family, font size, bold, italic, |
sheets_get_sheet_structure | read | Lightweight tool returning ONLY structural/dimensional metadata for a sheet — no per-cell data. |
sheets_get_tables | read | Read native Google Sheets tables for a spreadsheet or a specific sheet |
sheets_get_values | read | Get values from a specified range in a Google Sheets spreadsheet |
sheets_insert_date | write | Insert properly formatted dates in Google Sheets with locale support and automatic detection |
sheets_insert_link | write | Insert clickable links in Google Sheets cells with custom display text |
sheets_insert_rows | write | Insert new rows at a specific position with optional data |
sheets_insert_sheet | write | Add a new sheet to an existing Google Sheets spreadsheet |
sheets_merge_cells | write | Merge cells in a Google Sheet |
sheets_unmerge_cells | read | Unmerge cells in a Google Sheet |
sheets_update_borders | write | Update borders of cells in a Google Sheet |
sheets_update_chart | write | Update an existing chart in a Google Sheets spreadsheet |
sheets_update_sheet_properties | write | Update properties of a sheet in a Google Sheets spreadsheet |
sheets_update_table | write | Update an existing native Google Sheets table by tableId |
sheets_update_values | write | Update values in a specified range of a Google Sheets spreadsheet. |
spreadsheetId | read | The ID of the target spreadsheet (from the URL) |
summarize-data | write | Analyze spreadsheet data and provide insights or create a summary |
Trust audit
BLOCKgrade D · trust 64/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- none-observed
- Shell
- declared (2 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (14)
# GOOGLE_PRIVATE_KEY='-----BEGIN PRIVATE KEY-----\nMIIEvgIBADANBgkqhkiG...\n-----END PRIVATE KEY-----\n'
'It should start with -----BEGIN PRIVATE KEY----- and end with -----END PRIVATE KEY-----'
"GOOGLE_SERVICE_ACCOUNT_KEY": "{\"type\":\"service_account\",\"project_id\":\"your-project\",\"private_key_id\":\"...\",\"private_key\":\"-----BEGIN PRIVATE KEY-----\\n...\\n-----END PRIVATE KEY-----\"GOOGLE_PRIVATE_KEY": "-----BEGIN PRIVATE KEY-----\\nMIIEvgIBADANBgkqhkiG9w0BAQEFAASCBKgwggSkAgEAAoIBAQCgR6bvMNOUHZ29\\n+YgbVHAXsT/s+L/jnXTCB193zikCzspSBSfxLu8VRDjkNq9WUoDxizTATzMFNvNf\\n...\\n-----EN
- The private key must include the `-----BEGIN PRIVATE KEY-----` and `-----END PRIVATE KEY-----` markers
sheets_batch_delete_sheets, sheets_clear_values, sheets_delete_chart, sheets_delete_columns, sheets_delete_rows, sheets_delete_sheet, sheets_delete_table
.prettierignore
.prettierrc.json
} from '../../../src/config/toolsets.js';
import * as tools from '../../../src/tools/index.js';
const INDEX_PATH = path.resolve(__dirname, '../../src/index.ts');
import { handleAppendValues } from '../../../src/tools/append-values.js';import * as googleAuth from '../../../src/utils/google-auth.js';
@modelcontextprotocol/sdk, googleapis, zod, @eslint/js, @types/node, @vitest/coverage-v8, @vitest/ui, dotenv
Gates applied: critical_finding, no_behavioural_pass.
ca65998c41acfull audit observations/trust-audit/mcp-server/freema__gsheets.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | ca65998c41ac | BLOCK | D | 64 | first audit |
Questions
What is the GSheets MCP server?
MCP server for Google Sheets - Read, write and manipulate spreadsheets through Claude Desktop
What tools does GSheets expose?
56 in total: 28 read-only, 21 that write, and 7 that can delete or overwrite (sheets_batch_delete_sheets, sheets_clear_values, sheets_delete_chart, sheets_delete_columns, sheets_delete_rows). Every one is listed on this page with its risk.
Is GSheets safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (64/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 7 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does GSheets need?
It reads GOOGLE_APPLICATION_CREDENTIALS, GOOGLE_PRIVATE_KEY and GOOGLE_SERVICE_ACCOUNT_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does GSheets run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as mcp-gsheets at 1.10.3.
How current is this page?
The grade is for one exact copy of the source (ca65998c41ac), read on 2026-10-07. The repository is watched and re-audited when it changes.