Google Workspace MCP Server

April 29, 2026 · View on GitHub

MCP server providing Claude access to Google Drive, Docs, Sheets, Slides, Calendar, Gmail, and Contacts.

Fork of @dguido/google-workspace-mcp with added support for:

  • Multi-workspace: Serve multiple Google accounts from a single process, selected by URL path (/mcp/personal, /mcp/business)
  • Email attachments: Send and receive file attachments via Gmail
  • Workspace signatures: Auto-append plain text and HTML signatures per workspace
  • Sender display name: Auto-inject From header with display name from workspace config

Quick Start

1. Set Up Google Cloud

  1. Go to the Google Cloud Console and create or select a project
  2. Enable all required APIs (one-click link)
  3. Go to APIs & Services > Credentials and create an OAuth 2.0 Client ID (Desktop app type)
  4. Copy the Client ID and Client Secret

2. Configure Claude Desktop

macOS: ~/Library/Application Support/Claude/claude_desktop_config.json Windows: %APPDATA%\Claude\claude_desktop_config.json

{
  "mcpServers": {
    "google-workspace": {
      "command": "npx",
      "args": ["@danielrosehill/google-workspace-mcp"],
      "env": {
        "GOOGLE_CLIENT_ID": "YOUR_CLIENT_ID.apps.googleusercontent.com",
        "GOOGLE_CLIENT_SECRET": "YOUR_CLIENT_SECRET",
        "GOOGLE_WORKSPACE_SERVICES": "drive,gmail,calendar"
      }
    }
  }
}

That's it. On first tool call, a browser window opens for Google OAuth consent. Tokens are saved automatically.

Alternative: file-based credentials

Download the credentials JSON from Google Cloud Console and save to ~/.config/google-workspace-mcp/credentials.json, then authenticate manually:

npx @dguido/google-workspace-mcp auth

See Advanced Configuration for file-based setup, named profiles, and multi-account setup.

What You Can Do

Create a Google Doc called "Project Plan" in /Work/Projects with an outline for Q1.
Search for files containing "budget" and organize them into the Finance folder.
Create a presentation called "Product Roadmap" with slides for Q1 milestones.

Google Cloud Setup

1. Create a Google Cloud Project

  • Go to the Google Cloud Console
  • Click "Select a project" > "New Project"
  • Name your project (e.g., "Google Drive MCP")

2. Enable Required APIs

  • Enable all APIs at once (one-click link)
  • Or manually: Go to "APIs & Services" > "Library" and enable: Google Drive API, Google Docs API, Google Sheets API, Google Slides API, Google Calendar API, Gmail API, People API
  • Go to "APIs & Services" > "OAuth consent screen"
  • Fill in app name, support email, and developer contact
  • Choose "External" (or "Internal" for Workspace)
  • Add your email as a test user
  • Add scopes: drive.file, documents, spreadsheets, presentations, drive, drive.readonly, calendar, gmail.modify, gmail.labels, contacts

4. Create OAuth 2.0 Credentials

  • Go to "APIs & Services" > "Credentials"
  • Click "+ CREATE CREDENTIALS" > "OAuth client ID"
  • Application type: Desktop app
  • Copy the Client ID and Client Secret (or download the JSON file)

Configuration

File Locations

Both credentials and tokens are stored in ~/.config/google-workspace-mcp/ by default:

FileDefault Path
OAuth credentials~/.config/google-workspace-mcp/credentials.json
Auth tokens~/.config/google-workspace-mcp/tokens.json

Environment Variables

VariableDescription
GOOGLE_CLIENT_IDOAuth Client ID (simplest setup — no credentials file needed)
GOOGLE_CLIENT_SECRETOAuth Client Secret (used with GOOGLE_CLIENT_ID)
GOOGLE_WORKSPACE_MCP_TOKEN_PATHCustom token storage location
GOOGLE_WORKSPACE_MCP_PROFILENamed profile for credential isolation
GOOGLE_WORKSPACE_SERVICESComma-separated list of services to enable

Token-Efficient Output (TOON)

For LLM-optimized responses that reduce token usage by 20-50%, enable TOON format:

{
  "mcpServers": {
    "google-workspace": {
      "command": "npx",
      "args": ["@danielrosehill/google-workspace-mcp"],
      "env": {
        "GOOGLE_WORKSPACE_SERVICES": "drive,gmail,calendar",
        "GOOGLE_WORKSPACE_TOON_FORMAT": "true"
      }
    }
  }
}

TOON (Token-Oriented Object Notation) encodes structured responses more compactly than JSON by eliminating repeated field names. Savings are highest for list operations (calendars, events, emails, filters).

Service Configuration

By default, we recommend enabling only the core services (drive,gmail,calendar) as shown in Quick Start. This provides file management, email, and calendar capabilities without the complexity of document editing tools.

To enable additional services, add them to GOOGLE_WORKSPACE_SERVICES:

{
  "mcpServers": {
    "google-workspace": {
      "command": "npx",
      "args": ["@danielrosehill/google-workspace-mcp"],
      "env": {
        "GOOGLE_WORKSPACE_SERVICES": "drive,gmail,calendar,docs,sheets,slides"
      }
    }
  }
}

Available services: drive, docs, sheets, slides, calendar, gmail, contacts

  • Omit GOOGLE_WORKSPACE_SERVICES entirely to enable all services
  • Unified tools (create_file, update_file, get_file_content) require drive, docs, sheets, and slides
  • When you limit services, only the OAuth scopes for those services are requested during authentication. If you change enabled services, re-authenticate to update granted scopes.

See Advanced Configuration for named profiles, multi-account setup, and environment variables.

Multi-Workspace Mode

Serve multiple Google accounts from a single process. Create a workspaces.json:

{
  "personal": {
    "email": "you@gmail.com",
    "senderName": "Your Name",
    "signature": "Your Name\nhttps://yoursite.com",
    "signatureHtml": "<b>Your Name</b><br><a href=\"https://yoursite.com\">yoursite.com</a>",
    "clientCredentials": "/path/to/personal/client.json",
    "tokenPath": "/path/to/personal/token.json"
  },
  "business": {
    "email": "you@company.com",
    "senderName": "Your Name",
    "signature": "Your Name\nCompany — https://company.com",
    "signatureHtml": "<b>Your Name</b><br><a href=\"https://company.com\">Company</a>",
    "clientCredentials": "/path/to/business/client.json",
    "tokenPath": "/path/to/business/token.json"
  }
}

Start the server with HTTP transport:

GWS_WORKSPACES_CONFIG=/path/to/workspaces.json \
GWS_MCP_PORT=3200 \
GWS_MCP_HOST=0.0.0.0 \
npx @danielrosehill/google-workspace-mcp start

Connect clients to workspace-specific URLs:

  • http://host:3200/mcp/personal — routes to the personal workspace
  • http://host:3200/mcp/business — routes to the business workspace

Each workspace gets its own OAuth tokens, sender name, and signature. The workspace parameter is auto-injected from the URL path — clients don't need to include it in tool calls.

Workspace Config Fields

FieldRequiredDescription
emailyesGoogle account email
clientCredentialsyesPath to OAuth client.json
tokenPathyesPath to store OAuth tokens
labelnoDisplay label (defaults to workspace name)
senderNamenoDisplay name for outgoing emails (e.g., "Daniel Rosehill")
signaturenoPlain text signature auto-appended to email body
signatureHtmlnoHTML signature auto-appended to email HTML part

Email Attachments

Send emails with file attachments:

Send an email to user@example.com with subject "Report" and attach the Q1 report PDF.

Attachments are passed as base64-encoded content with filename and MIME type. The server also supports downloading attachments from received emails via the download_attachment tool.

Available Tools

Drive (29 tools)

search listFolder createFolder createTextFile updateTextFile deleteItem renameItem moveItem copyFile getFileMetadata exportFile shareFile getSharing removePermission listRevisions restoreRevision downloadFile uploadFile getStorageQuota starFile resolveFilePath batchDelete batchRestore batchMove batchShare listTrash restoreFromTrash emptyTrash getFolderTree

Google Docs (8 tools)

createGoogleDoc updateGoogleDoc getGoogleDocContent appendToDoc insertTextInDoc deleteTextInDoc replaceTextInDoc formatGoogleDocRange

Google Sheets (7 tools)

createGoogleSheet updateGoogleSheet getGoogleSheetContent formatGoogleSheetCells mergeGoogleSheetCells addGoogleSheetConditionalFormat sheetTabs

Google Slides (10 tools)

createGoogleSlides updateGoogleSlides getGoogleSlidesContent formatSlidesText formatSlidesShape formatSlideBackground createGoogleSlidesTextBox createGoogleSlidesShape slidesSpeakerNotes listSlidePages

Calendar (7 tools)

listCalendars listEvents getEvent createEvent updateEvent deleteEvent findFreeTime

Gmail (14 tools)

sendEmail draftEmail readEmail searchEmails deleteEmail modifyEmail downloadAttachment listLabels getOrCreateLabel updateLabel deleteLabel createFilter listFilters deleteFilter

Contacts (6 tools)

listContacts getContact searchContacts createContact updateContact deleteContact

Unified (3 tools)

createFile updateFile getFileContent

Full API Reference

Troubleshooting

"OAuth credentials not found"

Set GOOGLE_CLIENT_ID and GOOGLE_CLIENT_SECRET env vars in your MCP config, or save your credentials file to ~/.config/google-workspace-mcp/credentials.json.

"Authentication failed" or browser doesn't open

Ensure credential type is "Desktop app" (not "Web application"). The server uses an ephemeral port assigned by the OS, so no specific ports need to be available.

"Tokens expired" or "Invalid grant"

Apps in "Testing" status expire tokens after 7 days. Re-authenticate:

rm ~/.config/google-workspace-mcp/tokens.json
npx @dguido/google-workspace-mcp auth

To avoid weekly re-authentication: Publish your OAuth app (see Avoiding Token Expiry below).

"API not enabled"

Enable the missing API in Google Cloud Console > APIs & Services > Library.

"Login Required" even with valid tokens

Revoke app access at Google Account Permissions, clear tokens, and re-authenticate.

Full Troubleshooting Guide

Security

  • RFC 8252-compliant OAuth 2.0 with PKCE (Proof Key for Code Exchange)
  • Loopback-only authentication server (127.0.0.1)
  • State parameter for CSRF protection
  • Automatic token refresh
  • Tokens stored with 0600 permissions
  • All processing happens locally
  • Never commit credentials or tokens to version control

Avoiding Token Expiry

OAuth apps in "Testing" status automatically expire tokens after 7 days. To avoid weekly re-authentication:

  1. Go to Google Cloud Console > APIs & Services > OAuth consent screen
  2. Click "PUBLISH APP"
  3. For personal use, you don't need to complete Google's verification process
  4. Published apps keep tokens valid until explicitly revoked

Note: Publishing makes your app available to any Google user, but since you control the OAuth credentials, only you can authenticate.

Option 2: Use Internal App (Workspace Only)

If you have a Google Workspace account:

  1. Set User Type to "Internal" on the OAuth consent screen
  2. Internal apps don't expire tokens and don't require publishing

Monitoring Token Age

Use get_status to check token age. Tokens older than 6 days show a warning automatically.

Development

npm install
npm run build    # Compile TypeScript
npm run check    # typecheck + lint + format check
npm test         # Run tests

See Contributing Guide for project structure and development workflow.

Origin

This project is a substantial rewrite of piotr-agier/google-drive-mcp, originally created by Piotr Agier.

License

MIT - See LICENSE file for details.