Google DriveCAUTION
A Model Context Protocol (MCP) server that provides secure integration with Google Drive, Docs, Sheets, Slides and Calendar. It allows Claude Desktop and other MCP clients to manage files in Google Drive through a standardized interface.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://mcptoplist.com/server/io.github.piotr-agier%2Fgoogle-drive-mcp)
Connect an MCP client to Google Drive, Docs, Sheets, Slides, and Calendar through one self-hosted server. Search and organize files, create and edit Workspace content, manage sharing, and automate multi-step workflows while keeping control of the Google identity and credentials used for every call.
Why this server
- Drive-first workflows: 130 tools cover file management, Shared Drives, permissions, revisions, rich Docs editing, Sheets formatting, Slides authoring, and Calendar events.
- Local or hosted: use stdio for a personal desktop client, Streamable HTTP for a hosted integration, or OAuth-protected team mode for a shared service.
- Identity control: local OAuth supports multiple Google accounts and per-tool account selection; service accounts and externally managed OAuth tokens are also supported.
- Agent-friendly access: tools expose targeted operations, while the optional
gdrive:///resource interface supports direct reading and discovery. - Open and self-hosted: credentials and tokens stay in the environment you operate.
This project remains focused on deep Drive and editor workflows rather than attempting to expose every Google Workspace API.
Client compatibility
Compatibility is determined by the transport and authentication flow a client supports.
See Client configuration for configuration examples and transport requirements.
Quick start
1
9feabad12272OBSERVED · 2026-10-06Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add google-drive-mcp --env GOOGLE_DRIVE_OAUTH_CREDENTIALS=${GOOGLE_DRIVE_OAUTH_CREDENTIALS} -- npx -y @piotr-agier/[email protected]Exposed tools (118)
54 read · 55 write · 9 destructive. Blast radius: 9 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
GOOGLE_DRIVE_OAUTH_CREDENTIALS | read | Path to a Google OAuth 2.0 Desktop app credentials JSON file. |
addComment | write | Add a comment quoting a text range, targeted by startIndex+endIndex or by textToFind. The comment appears in the document |
addDataValidation | write | Add data validation rules to a sheet range |
addDocumentTab | write | Add a new tab in a Google Doc |
addGoogleSheetConditionalFormat | write | Add conditional formatting to a Google Sheet |
addNamedRange | write | Create a named range |
addPermission | write | Add a sharing permission to a file. If the principal already holds a permission on the file, Drive updates that permission instead of creating a second one, and the requested role is applied even when it is a downgrade (asking for |
addSheet | read | Alias for addSpreadsheetSheet (adds a new sheet/tab) |
addSpreadsheetSheet | read | Adds a new sheet/tab to an existing Google Spreadsheet |
appendSpreadsheetRows | read | Appends rows of data to the end of a sheet in a Google Spreadsheet |
applyTextStyle | write | Apply text formatting (bold, italic, color, etc.) to a range or found text. Use EITHER startIndex+endIndex OR textToFind for targeting. |
authGetStatus | read | Show authentication/token status and scope diagnostics |
authListScopes | read | List configured/requested scopes and currently granted scopes |
authTestFileAccess | write | Run auth diagnostics against Drive API/file access |
autoResizeColumns | read | Auto-size one or more columns to fit their content. Indices are 0-based and the interval is half-open [startColumn, endColumn) — to auto-fit a single column at position 5, pass startColumn: 5, endColumn: 6. |
autoResizeRows | read | Auto-size one or more rows to fit their content. Indices are 0-based and the interval is half-open [startRow, endRow) — to auto-fit a single row at position 5, pass startRow: 5, endRow: 6. |
bulkConvertFolderPdfs | read | Convert all PDFs in a folder into Google Docs and return per-file results |
convertPdfToGoogleDoc | read | Convert an existing PDF in Drive into an editable Google Doc |
copyFile | read | Creates a copy of a Google Drive file or document |
createCalendarEvent | write | Create a new calendar event. Supports timed events, all-day events, and Google Meet integration. |
createFolder | write | Create a new folder in Google Drive |
createFootnote | write | Create a footnote in a Google Doc. Footnotes cannot be inserted inside equations, headers, footers, or other footnotes. For multi-tab docs, specify tabId to target a specific tab. |
createGoogleDoc | write | Create a new Google Doc |
createGoogleSheet | write | Create a new Google Sheet. By default uses RAW mode which stores values as-is. Set valueInputOption to |
createGoogleSlides | write | Create a new Google Slides presentation |
createGoogleSlidesShape | write | Create a shape in Google Slides |
createGoogleSlidesTextBox | write | Create a text box in Google Slides |
createParagraphBullets | destructive | Add or remove bullet points / numbered lists on paragraphs in a Google Doc. Target paragraphs by startIndex+endIndex or textToFind. Use bulletPreset= |
createShortcut | write | Create a shortcut (link) to a file or folder in Google Drive. Useful for referencing the same document from multiple locations without duplicating it. |
createTextFile | write | Create a new text or markdown file |
deleteCalendarEvent | destructive | Delete a calendar event |
deleteComment | destructive | Delete a comment from the document |
deleteGoogleSlide | destructive | Delete a slide from a presentation |
deleteItem | write | Move a file or folder to trash (can be restored from Google Drive trash) |
deleteRange | destructive | Delete content between start and end indices. Works on Google Docs and text/* files (e.g. text/plain, text/markdown). Index semantics differ by file type: Google Docs use the Docs API |
deleteSheet | destructive | Delete a sheet/tab by sheetId |
deleteSlideElement | destructive | Delete an element (image, text box, shape) from a Google Slides slide |
downloadFile | read | Download a Google Drive file to a local path. For Google Workspace files (Docs, Sheets, Slides, Drawings), exports to the specified format. For regular files, downloads as-is. Streams directly to disk. |
duplicateSlide | read | Duplicate a slide in a presentation |
editTableCell | write | Edit the content and/or style of a specific table cell. Requires knowing the table start index. For multi-tab docs, specify tabId to target a table in a specific tab. |
exportSlideThumbnail | read | Export a slide thumbnail URL |
formatGoogleDocParagraph | write | Apply paragraph formatting (alignment, indentation, spacing, heading style, borders, shading) in a Google Doc. Alias for applyParagraphStyle. |
formatGoogleDocText | write | Apply text formatting (bold, italic, font, color, links, superscript/subscript) to a range or found text in a Google Doc. Alias for applyTextStyle. |
formatGoogleSheetCells | read | Format cells in a Google Sheet (background, borders, alignment) |
formatGoogleSheetNumbers | write | Apply number formatting to cells in a Google Sheet |
formatGoogleSheetText | write | Apply text formatting to cells in a Google Sheet |
formatGoogleSlidesParagraph | write | Apply paragraph formatting to text in Google Slides |
formatGoogleSlidesText | write | Apply text formatting to elements in Google Slides |
getCalendarEvent | read | Get a single calendar event by ID |
getCalendarEvents | read | Get events from a Google Calendar with optional filtering |
getComment | read | Get a specific comment with its full thread of replies |
getDocumentInfo | read | Gets detailed information about a specific Google Document. |
getGoogleDocContent | read | Get content of a Google Doc with text indices for formatting |
getGoogleDocContentPaginated | read | Get a portion of a Google Doc with text indices for formatting, with pagination support. Use offset and limit to read large documents in chunks. |
getGoogleSheetContent | read | Get content of a Google Sheet with cell information. Each row is returned as |
getGoogleSlidesContent | read | Get content of Google Slides with element IDs for formatting |
getGoogleSlidesSpeakerNotes | read | Get speaker notes from a specific slide in Google Slides |
getRevisions | read | List revisions for a file |
getSlideElementInfo | read | Get position, size, and transform of all elements on a slide. Returns actual rendered bounds. |
getSpreadsheetInfo | read | Gets detailed information about a Google Spreadsheet including all sheets/tabs |
hideSheetDimension | read | Hide a range of columns or rows in a sheet (sets hiddenByUser=true). Indices are 0-based and the interval is half-open [startIndex, endIndex) — to hide a single column/row at position 5, pass startIndex: 5, endIndex: 6. |
insertImageFromUrl | write | Insert an inline image into a Google Document from a publicly accessible URL |
insertLocalImage | write | Upload a local image file to Google Drive and insert it into a Google Document |
insertSlidesImageFromUrl | write | Insert an image into a Google Slides slide from a publicly accessible URL |
insertSlidesLocalImage | write | Upload a local image file to Google Drive and insert it into a Google Slides slide |
insertSmartChip | write | Insert a person smart chip (mention) at a document index. Only person chips are supported by the Docs API; date and file chips are read-only. |
insertTable | write | Insert a new table with the specified dimensions at a given index. For multi-tab docs, specify tabId to target a specific tab. |
insertText | write | Insert text at a specific index (surgical edit, doesn |
listCalendars | read | List all accessible Google Calendars for the authenticated user |
listComments | read | List all comments in a Google Document |
listDimensionGroups | read | List the row and column groups of a spreadsheet, with each group |
listDocumentTabs | read | List all tabs in a Google Doc with their IDs and hierarchy |
listFolder | read | List contents of a folder (defaults to root) |
listGoogleDocs | read | Lists Google Documents from your Google Drive with optional filtering. |
listGoogleSheets | read | Lists Google Spreadsheets from your Google Drive with optional filtering |
listPermissions | read | List sharing permissions for a file |
listSharedDrives | read | List available Google Shared Drives |
listSheets | read | List tabs/sheets in a Google Spreadsheet |
lockFile | read | Lock a file to prevent editing by setting content restrictions. The file remains readable but cannot be modified until unlocked. |
manage_accounts | read | Manage connected Google accounts. action= |
mergeGoogleSheetCells | write | Merge cells in a Google Sheet |
moveItem | write | Move a file or folder |
moveSlideElement | write | Move and/or resize an element (image, text box, shape) on a Google Slides slide |
protectRange | read | Protect a range in a spreadsheet |
readGoogleDoc | read | Read content of a Google Doc with format options. Supports multi-tab documents. Text/markdown output leads with the document |
readGoogleDocPaginated | read | Read a portion of a Google Doc with pagination support. Use offset and limit to read large documents in chunks, avoiding output size limits. |
readSmartChips | read | Read smart chip-like elements (person mentions, rich links, date chips) from the default tab of a document |
readTextFile | read | Read content of a text file (any text/* MIME type, e.g. text/plain, text/markdown, text/csv). For Google Docs, use readGoogleDoc. |
removePermission | destructive | Remove a permission from a file (by permissionId or emailAddress) |
renameDocumentTab | write | Rename an existing Google Doc tab |
renameItem | write | Rename a file or folder |
renameSheet | write | Rename a sheet/tab by sheetId |
reorderSlides | read | Reorder one or more slides in a presentation |
replaceSlideImage | write | Replace an existing image in place, preserving its layering (z-order), position, size, and crop. Unlike delete+insert, which lands the new image on top of the stack, this keeps the image under any overlaid text. |
replyToComment | write | Add a reply to an existing comment |
restoreRevision | read | Restore a file to a selected revision (creates a new head revision). Note: workspace files (Docs, Sheets, Slides) are restored via export/import and may lose some formatting. |
search | read | Search for files in Google Drive. Results are sorted most-recently-modified first by default; use orderBy for a different order. Set rawQuery=true to pass a raw Google Drive API query supporting operators like modifiedTime, createdTime, mimeType, name contains, etc. |
setColumnWidth | write | Set the width (in pixels) of one or more columns in a sheet. Indices are 0-based and the interval is half-open [startColumn, endColumn) — to resize a single column at position 5, pass startColumn: 5, endColumn: 6. |
setElementText | destructive | Replace the entire text of one shape/text box by objectId (element-scoped delete+insert in one atomic call). Unlike replaceAllTextInSlides, this cannot hit other slides, masters, or layouts, and does not depend on matching existing text. Pass empty text to clear the element. |
setElementZOrder | write | Change the stacking order of page elements (updatePageElementsZOrder). Inserted images land on top of the stack and can cover overlay text — send them backward or to the back. All elements must be on the same page. |
setGoogleSheetBorders | write | Set borders for cells in a Google Sheet |
setGoogleSlidesBackground | write | Set background color for slides |
setRowHeight | write | Set the height (in pixels) of one or more rows in a sheet. Indices are 0-based and the interval is half-open [startRow, endRow) — to resize a single row at position 5, pass startRow: 5, endRow: 6. |
setSlideVisibility | read | Show or hide (skip) slides in one atomic call. Hidden slides are skipped in present mode and PDF export. |
shareFile | read | Convenience wrapper to share a file with a user email. If the user already holds a permission on the file, that permission |
showSheetDimension | read | Show (unhide) a range of columns or rows in a sheet (sets hiddenByUser=false). Indices are 0-based and the interval is half-open [startIndex, endIndex) — to unhide a single column/row at position 5, pass startIndex: 5, endIndex: 6. |
styleGoogleSlidesShape | read | Style shapes in Google Slides |
unlockFile | read | Unlock a previously locked file by removing content restrictions, restoring full edit access. |
updateCalendarEvent | write | Update an existing calendar event |
updateDimensionGroup | read | Collapse or expand an existing row or column group. Indices are 0-based and the interval is half-open [startIndex, endIndex). Use listDimensionGroups first to find the group |
updateGoogleDoc | write | Update an existing Google Doc (replaces all content). The replacement is one atomic batchUpdate, so a failure leaves the document unchanged rather than wiped. For multi-tab docs, specify tabId to replace a single tab |
updateGoogleSheet | write | Update an existing Google Sheet. By default uses RAW mode which stores values as-is. Set valueInputOption to |
updateGoogleSlides | write | Update an existing Google Slides presentation |
updateGoogleSlidesSpeakerNotes | write | Update speaker notes for a specific slide in Google Slides |
updatePermission | write | Update an existing permission role |
updateTextFile | write | Update an existing text or markdown file |
uploadFile | write | Upload a file (any type: image, audio, video, PDF, etc.) to Google Drive, either from a local path on the server or from base64-encoded content. When fileId is provided, uploads the content as a new version of that existing file (in-place update) instead of creating a new file. |
uploadPdfWithSplit | write | Upload PDF and optionally split into chunked parts (metadata split plan for now) |
Trust audit
CAUTIONgrade B · trust 80/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (2 observation(s))
- Network
- declared (3 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (22)
redirect_uris: (keys.redirect_uris as string[] | undefined) || ['http://127.0.0.1:3000/oauth2callback']
const secret = 'TOPSECRET-client-secret-DO-NOT-LEAK-abcdef';
const PRIVATE_KEY = '-----BEGIN PRIVATE KEY-----\nsuper-secret-key-material\n-----END PRIVATE KEY-----\n';
createParagraphBullets, deleteCalendarEvent, deleteComment, deleteGoogleSlide, deleteRange, deleteSheet, deleteSlideElement, removePermission, setElementText
.cursorignore
import { TimeoutError } from '../../utils/retry.js';import { AccountResolver, coversScopes } from '../../src/auth/accountResolver.js';import { AccountStore } from '../../src/auth/accountStore.js';import { SessionStore, STDIO_SESSION_ID } from '../../src/auth/sessionStore.js';import { AccountRecord } from '../../src/auth/types.js';- **auth:** use loopback IP `127.0.0.1` instead of `localhost` for the OAuth callback redirect URI, matching the IPv4-only callback-server bind so the redirect resolves to the bound address on dual-st
The callback server binds to the loopback interface and the OAuth redirect URI uses the loopback IP — `http://127.0.0.1:<port>/oauth2callback` (default range `127.0.0.1:3000`–`127.0.0.1:3004`). **Desk
"url": "http://127.0.0.1:3100/mcp"
4. **`redirect_uri_mismatch` (Web application clients only)**: The callback redirect URI uses the loopback IP `http://127.0.0.1:<port>/oauth2callback`. Switch to a "Desktop app" client (recommended),
@modelcontextprotocol/sdk, @types/express, express, google-auth-library, googleapis, jszip, open, pdf-lib
- **transport:** an HTTP client whose session has expired can now recover on its own instead of failing every call until the user reconnects by hand. The Streamable HTTP transport evicts a session aft
Stops a stalled OAuth token refresh from **hanging every call on the server**. The proactive refresh that runs five minutes before an access token expires awaited Google's token endpoint with no timeo
- **auth:** an OAuth token refresh that stalls no longer hangs every call on the server. The proactive refresh that runs five minutes before an access token expires awaited Google's token endpoint wit
- **team:** log lines now name the acting user. Team-mode dispatch, session lifecycle (created / idle timeout / closed), sign-in callback, and per-user tool logs carry the member's Google `sub` and em
With the Streamable HTTP transport in its default (single-user) mode, multiple MCP sessions sharing the same server process also share the same active default account. A `set_default` in one session i
When binding to `127.0.0.1` (default), DNS rebinding protection is automatically enabled. For remote deployments (`0.0.0.0`), prefer [Team Mode](#team-mode-multi-user-http-deployments), which authenti
- **Open and self-hosted:** credentials and tokens stay in the environment you operate.
Gates applied: no_behavioural_pass.
9feabad12272full audit observations/trust-audit/mcp-server/piotr-agier__google-drive-1.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-06 | 9feabad12272 | CAUTION | B | 80 | first audit |
Questions
What is the Google Drive MCP server?
A Model Context Protocol (MCP) server that provides secure integration with Google Drive, Docs, Sheets, Slides and Calendar. It allows Claude Desktop and other MCP clients to manage files in Google Drive through a standardized interface.
What tools does Google Drive expose?
118 in total: 54 read-only, 55 that write, and 9 that can delete or overwrite (createParagraphBullets, deleteCalendarEvent, deleteComment, deleteGoogleSlide, deleteRange). Every one is listed on this page with its risk.
Is Google Drive safe to connect to an agent?
With care. The audit graded it B (80/100) and found 22 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 9 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Google Drive need?
It reads GOOGLE_APPLICATION_CREDENTIALS, GOOGLE_CLIENT_SECRET_PATH, GOOGLE_DRIVE_MCP_ACCESS_TOKEN, GOOGLE_DRIVE_MCP_AUTH_PORT, GOOGLE_DRIVE_MCP_CLIENT_SECRET, GOOGLE_DRIVE_MCP_REFRESH_TOKEN, GOOGLE_DRIVE_MCP_TOKEN_PATH, GOOGLE_DRIVE_MCP_TOKEN_REFRESH_TIMEOUT, GOOGLE_DRIVE_OAUTH_CREDENTIALS and GOOGLE_TOKEN_PATH from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Google Drive run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @piotr-agier/google-drive-mcp at 2.12.0.
How current is this page?
The grade is for one exact copy of the source (9feabad12272), read on 2026-10-06. The repository is watched and re-audited when it changes.