ClaudeMod
Back to browse
MCP Servers

Google Workspace MCP

Gmail, Calendar, Drive, Docs, Sheets, and Slides via a single MCP server — read emails, create events, edit spreadsheets, and manage Drive files from Claude.

Taylor Wilsdon2,486 starsAdded 3 months ago

Google Workspace MCP Server

License: MIT Python 3.10+ PyPI PyPI Downloads Website

Full natural language control over Google Calendar, Drive, Gmail, Docs, Sheets, Slides, Forms, Tasks, Contacts, and Chat through all MCP clients, AI assistants and developer tools.

Includes a full featured CLI & Code Mode for use with tools like Claude Code and Codex!

The most feature-complete Google Workspace MCP server, it can do things that Google's own tooling and the built in integrations with Claude and ChatGPT can't even dream of. With Remote OAuth2.1 multi-user support, fine-grained editing tools and the most extensive coverage of any Google Workspace tool in existance, Workspace MCP is in a different class. Offering native OAuth 2.1, stateless mode and external auth server support, it's also the only Workspace MCP you can host for your whole organization centrally & securely!

Support for all free Google accounts & Google Workspace plans (Starter, Standard, Plus, Enterprise, Non Profit) with expanded app options like Chat & Spaces.

Interested in a private, managed cloud instance? That can be arranged.

Read the Docs
Quick Start Guide


See it in action:


Overview

Workspace MCP is the single most complete MCP server, the only that integrates all major Google Workspace services with AI assistants and all agent platforms. The entire toolset is available for CLI usage supporting both local and remote instances.

Features

12 services  —  Gmail · Drive · Calendar · Docs · Sheets · Slides · Forms · Chat · Apps Script · Tasks · Contacts · Search

📧 Gmail — Complete email management, end-to-end coverage
📁 Drive — File operations with sharing, permissions, Office files, PDFs & images
📅 Calendar — Full event management with advanced features
📝 Docs — Deep, fine-grained editing, formatting & comments
📊 Sheets — Flexible cell management, formatting & conditional rules
🖼️ Slides — Presentation creation, updates & content manipulation
📋 Forms — Creation, publish settings & response management
💬 Chat — Space management, messaging & reactions

⚡ Apps Script — Cross-application workflow automation
 Projects · deployments · versions · execution · debugging

✅ Tasks — Task & list management with hierarchy
👤 Contacts — People API with groups & batch operations
🔍 Custom Search — Programmable Search Engine integration


🔐 Authentication & Security
OAuth 2.0 & 2.1 · auto token refresh · multi-user bearer tokens · transport-aware callbacks · CORS proxy


Security & Compliance

For Security Teams

This server sends no data anywhere except Google's APIs, on behalf of the authenticated user, using your own OAuth client credentials. There is no telemetry, no usage reporting, no analytics, no license server, and no SaaS dependency. The entire data path is: your infrastructure → Google APIs.

  • Fully open source — every line is auditable in this repo
  • Your OAuth client, your GCP project — credentials never leave your environment
  • You control the scopes — read-only, granular per-service permissions, or full access
  • You control the network — deploy behind your reverse proxy, in your VPC, on your own terms
  • No third-party services — no intermediary servers, no token relays, no hosted backends
  • Stateless mode — zero disk writes for locked-down container environments
  • Sensitive path blocking — local file reads default to the managed attachment directory, and validate_file_path() still blocks .env* files plus common home-directory credential stores such as ~/.ssh/ and ~/.aws/ even if ALLOWED_FILE_DIRS is broadened

Full dependency tree in pyproject.toml, pinned in uv.lock.

For Legal & Procurement

This project is MIT licensed — not "open core," not "source available," not "free with a CLA." There is no dual licensing, no commercial tier gating features, and no contributor license agreement.

  • Use commercially without restriction — build products, sell services, deploy internally
  • Fork, embed, redistribute — MIT requires only attribution
  • No CLA — contributions remain under MIT
  • No telemetry to disclose — nothing to flag in a privacy review
  • No network effects — the server never contacts any endpoint you didn't configure
  • Standard dependency licenses — MIT, Apache 2.0, and BSD throughout the dependency chain; no copyleft, no AGPL

The license is 21 lines and says what it means.


Quick Start

Set credentials → pick a launch command → connect your client

💡 New to Workspace MCP? Check out the Interactive Quick Start Guide → with step-by-step setup, screenshots, and troubleshooting tips!

Confidential Client Quick Start

# 1. Credentials
export GOOGLE_OAUTH_CLIENT_ID="..."
export GOOGLE_OAUTH_CLIENT_SECRET="..."

# 2. Launch — pick a tier
uvx workspace-mcp --tool-tier core       # essential tools
uvx workspace-mcp --tool-tier extended   # core + management ops
uvx workspace-mcp --tool-tier complete   # everything

# Or cherry-pick services
uv run main.py --tools gmail drive calendar

Secretless / Public OAuth 2.1 (PKCE) Quick Start

# 1. Credentials
export MCP_ENABLE_OAUTH21=true
export GOOGLE_OAUTH_CLIENT_ID="..."
export WORKSPACE_MCP_PORT=8000
export GOOGLE_OAUTH_REDIRECT_URI="http://localhost:${WORKSPACE_MCP_PORT}/oauth2callback"
export OAUTHLIB_INSECURE_TRANSPORT=1
# Leave GOOGLE_OAUTH_CLIENT_SECRET unset for public PKCE clients
export FASTMCP_SERVER_AUTH_GOOGLE_JWT_SIGNING_KEY="$(openssl rand -hex 32)"

# 2. Launch — OAuth 2.1 requires HTTP transport
uvx workspace-mcp --transport streamable-http --tool-tier core
uvx workspace-mcp --transport streamable-http --tool-tier extended
uvx workspace-mcp --transport streamable-http --tool-tier complete

# Or cherry-pick services
uv run main.py --transport streamable-http --tools gmail drive calendar

Credential setup → · All launch options → · Tier details →

Environment Variable Reference
VariablePurpose
🔐 Authentication
GOOGLE_OAUTH_CLIENT_IDrequiredOAuth client ID from Google Cloud
GOOGLE_OAUTH_CLIENT_SECRETOAuth client secret for confidential clients; optional for public OAuth 2.1 PKCE clients
OAUTHLIB_INSECURE_TRANSPORTrequired*Set to 1 for development — allows http:// redirect
USER_GOOGLE_EMAILDefault email for single-user auth
GOOGLE_CLIENT_SECRET_PATHCustom path to client_secret.json
GOOGLE_MCP_CREDENTIALS_DIRCredential directory — default ~/.google_workspace_mcp/credentials
🖥️ Server
WORKSPACE_MCP_BASE_URIBase server URI (no port) — default http://localhost
WORKSPACE_MCP_PORTListening port — default 8000. Also controls the stdio-mode OAuth callback port. The PORT env var takes precedence if set.
WORKSPACE_MCP_HOSTBind host — default 0.0.0.0
WORKSPACE_MCP_TRANSPORTstdio or streamable-http; used when --transport is not passed
WORKSPACE_MCP_HTTP_PORTAdvanced legacy-stdio sidecar /mcp port for local workspace-cli access. Disabled when empty. Binds to 127.0.0.1 only and is accessible to local processes.
WORKSPACE_EXTERNAL_URLExternal URL for reverse proxy setups
WORKSPACE_ATTACHMENT_DIRDownloaded attachments dir and default trusted local attachment directory — default ~/.workspace-mcp/attachments/
WORKSPACE_MCP_URLRemote MCP endpoint URL for CLI
ALLOWED_FILE_DIRSColon-separated allowlist for local file reads
🧰 Tool Selection
WORKSPACE_MCP_TOOLSComma-separated services, e.g. gmail,drive,calendar; empty means all services
WORKSPACE_MCP_TOOL_TIERcore, extended, or complete; empty means all tools
WORKSPACE_MCP_READ_ONLYtrue, 1, or yes to request read-only scopes and filter write tools
WORKSPACE_MCP_PERMISSIONSSpace-separated service:level entries, e.g. gmail:send drive:readonly; mutually exclusive with tools and read-only
🔑 OAuth 2.1 & Multi-User
MCP_ENABLE_OAUTH21true to enable OAuth 2.1 multi-user support
EXTERNAL_OAUTH21_PROVIDERtrue for external OAuth flow with bearer tokens
WORKSPACE_MCP_STATELESS_MODEtrue for stateless container-friendly operation
GOOGLE_OAUTH_REDIRECT_URIOverride OAuth callback URL — default auto-constructed
OAUTH_CUSTOM_REDIRECT_URISComma-separated additional redirect URIs
OAUTH_ALLOWED_ORIGINSComma-separated additional CORS origins
WORKSPACE_MCP_OAUTH_PROXY_STORAGE_BACKENDmemory, disk, or valkey — see storage backends
FASTMCP_SERVER_AUTH_GOOGLE_JWT_SIGNING_KEYCustom encryption key for OAuth proxy storage; required for public OAuth 2.1 clients when GOOGLE_OAUTH_CLIENT_SECRET is omitted
WORKSPACE_MCP_ALLOWED_CLIENT_REDIRECT_URISComma-separated allowlist of redirect URIs that dynamically-registered OAuth clients may use. Default is unset (any URI permitted, per DCR). Supports FastMCP's glob patterns (*, *.example.com)
🗄️ Credential Store
WORKSPACE_MCP_CREDENTIAL_STORE_BACKENDlocal_directory (default) or gcs — see credential store system
WORKSPACE_MCP_CREDENTIALS_DIRDirectory for the local_directory backend
GOOGLE_MCP_CREDENTIALS_DIRBackward-compatible alias for WORKSPACE_MCP_CREDENTIALS_DIR
WORKSPACE_MCP_GCS_BUCKETRequired when backend is gcs — GCS bucket name
WORKSPACE_MCP_GCS_PREFIXOptional object-name prefix for the gcs backend
WORKSPACE_MCP_GCS_REQUIRE_CMEKtrue to require a bucket default KMS key at startup (fails fast if unset)
🔧 Service Account
GOOGLE_SERVICE_ACCOUNT_KEY_FILEPath to service account JSON key file (domain-wide delegation)
GOOGLE_SERVICE_ACCOUNT_KEY_JSONInline service account JSON key (alternative to file)
DWD_ALLOWED_DOMAINSComma-separated domain allowlist for per-request impersonation (optional)
🔍 Custom Search
GOOGLE_PSE_API_KEYAPI key for Programmable Search Engine
GOOGLE_PSE_ENGINE_IDSearch Engine ID for PSE

*Required for development only. Claude Desktop stores credentials securely in the OS keychain — set them once in the extension pane.


Quick Start — Connect Claude to Google Workspace

The recommended setup is to run an instance and connect Claude to it via a Connector. Full instructions at workspacemcp.com/quick-start.


Prerequisites

Python 3.10+ · uv/uvx · Google Cloud Project with OAuth 2.0 credentials

If you want the GCS credential store backend, install the optional dependency first:

uv sync --extra gcs
# or
pip install "workspace-mcp[gcs]"

Configuration

Google Cloud Setup
  1. Create ProjectOpen Console → → Create new project

  2. Create OAuth Credentials — APIs & Services → Credentials → Create Credentials → OAuth Client ID

    • Choose Desktop Application for a public PKCE client (no redirect URIs needed) or Web Application for a confidential client
    • Download and note your Client ID and, if issued, Client Secret
  3. Enable APIs — APIs & Services → Library, then enable each service:

  4. Set Credentials — see Environment Variable Reference above, or:

    export GOOGLE_OAUTH_CLIENT_ID="your-client-id"
    export GOOGLE_OAUTH_CLIENT_SECRET="your-secret"
    

    For public OAuth 2.1 PKCE clients, omit GOOGLE_OAUTH_CLIENT_SECRET and set FASTMCP_SERVER_AUTH_GOOGLE_JWT_SIGNING_KEY instead.

Full OAuth documentation → · Credential setup details →

Google Custom Search Setup

Custom Search Configuration ← Enable web search capabilities

1. Create Search Engine

programmablesearchengine.google.com
/controlpanel/create

→ Configure sites or entire web
→ Note your Engine ID (cx)

Open Control Panel →

2. Get API Key

developers.google.com
/custom-search/v1/overview

→ Create/select project
→ Enable Custom Search API
→ Create credentials (API Key)

Get API Key →

3. Set Variables

export GOOGLE_PSE_API_KEY=\
  "your-api-key"
export GOOGLE_PSE_ENGINE_ID=\
  "your-engine-id"

Configure in environment

Quick Setup Guide ← Step-by-step instructions

Complete Setup Process:

  1. Create Search Engine - Visit the Control Panel

    • Choose "Search the entire web" or specify sites
    • Copy the Search Engine ID (looks like: 017643444788157684527:6ivsjbpxpqw)
  2. Enable API & Get Key - Visit Google Developers Console

    • Enable "Custom Search API" in your project
    • Create credentials → API Key
    • Restrict key to Custom Search API (recommended)
  3. Configure Environment - Add to your shell or .env:

    export GOOGLE_PSE_API_KEY="AIzaSy..."
    export GOOGLE_PSE_ENGINE_ID="01764344478..."
    

Full Documentation →

Start the Server

📌 Transport Mode Guidance: Use streamable HTTP mode (--transport streamable-http) for all modern MCP clients including Claude Code, VS Code MCP, and MCP Inspector. For Claude Desktop, run an instance and connect via a Connector. Stdio mode is a legacy fallback. For deployments, prefer OAuth 2.1 with stateless mode (MCP_ENABLE_OAUTH21=true, WORKSPACE_MCP_STATELESS_MODE=true) unless you need local attachment or credential storage.

OAuth state safety: Legacy stdio starts a local-only OAuth callback server. In single-user mode only, it may recover a missing Google state parameter by consuming the most recent pending local OAuth state. This fallback is intentionally disabled outside single-user mode because it can cross session boundaries. Do not enable or emulate this behavior in streamable HTTP, hosted, or multi-user deployments; those modes must require an explicit state match.

Launch Commands ← Choose your startup mode

▶ Legacy Mode

uv run main.py

⚠️ Stdio mode (incomplete MCP clients only)

◆ HTTP Mode (Recommended)

uv run main.py \
  --transport streamable-http

✅ Full MCP spec compliance & OAuth 2.1

@ Single User

uv run main.py \
  --single-user

Simplified authentication ⚠️ Cannot be used with OAuth 2.1 mode

Advanced Options ← Tool selection, tiers & Docker

▶ Selective Tool Loading

# Load specific services only
uv run main.py --tools gmail drive calendar
uv run main.py --tools sheets docs

# Combine with other flags
uv run main.py --single-user --tools gmail

🔒 Read-Only Mode

# Requests only read-only scopes & disables write tools
uv run main.py --read-only

# Combine with specific tools or tiers
uv run main.py --tools gmail drive --read-only
uv run main.py --tool-tier core --read-only

Read-only mode provides secure, restricted access by:

  • Requesting only *.readonly OAuth scopes (e.g., gmail.readonly, drive.readonly)
  • Automatically filtering out tools that require write permissions at startup
  • Allowing read operations: list, get, search, and export across all services

🔐 Granular Permissions

# Per-service permission levels
uv run main.py --permissions gmail:organize drive:readonly

# Combine permissions with tier filtering
uv run main.py --permissions gmail:send drive:full --tool-tier core

Granular permissions mode provides service-by-service scope control:

  • Format: service:level (one entry per service)
  • Gmail levels: readonly, organize, drafts, send, full (cumulative)
  • Tasks levels: readonly, manage, full (cumulative; manage allows create/update/move but denies delete and clear_completed)
  • Other services currently support: readonly, full
  • --permissions and --read-only are mutually exclusive
  • --permissions cannot be combined with --tools; enabled services are determined by the --permissions entries (optionally filtered by --tool-tier)
  • With --tool-tier, only tier-matched tools are enabled and only services that have tools in the selected tier are imported

The WORKSPACE_MCP_TOOLS, WORKSPACE_MCP_TOOL_TIER, WORKSPACE_MCP_READ_ONLY, and WORKSPACE_MCP_PERMISSIONS environment variables provide the same controls for plugin and container installs. Empty strings are ignored. Non-empty malformed values fail closed at startup. Explicit CLI flags take precedence over mutually exclusive env vars.

Advanced legacy stdio sidecar

# Optional bridge only for local legacy stdio sessions
WORKSPACE_MCP_HTTP_PORT=8001 uv run main.py
workspace-cli --url http://127.0.0.1:8001/mcp list

The sidecar is disabled unless WORKSPACE_MCP_HTTP_PORT is set. It only exists to bridge local workspace-cli calls into a legacy stdio server. Do not use it for normal Claude Code, VS Code, hosted, or multi-user deployments; use streamable HTTP with OAuth 2.1 instead. When enabled, it validates ports in the 1..65535 range, binds to 127.0.0.1, and logs a warning if the port is already in use while keeping stdio running.

★ Tool Tiers

uv run main.py --tool-tier core      # ● Essential tools only
uv run main.py --tool-tier extended  # ◐ Core + additional
uv run main.py --tool-tier complete  # ○ All available tools

◆ Docker Deployment

docker build -t workspace-mcp .
docker run -p 8000:8000 -v $(pwd):/app \
  workspace-mcp --transport streamable-http

# With tool selection via environment variables
docker run -e TOOL_TIER=core workspace-mcp
docker run -e TOOLS="gmail drive calendar" workspace-mcp

Available Services: gmaildrivecalendardocssheetsformstaskscontactschatsearch

CLI

The workspace-cli command lists tools and calls them against a running server — with encrypted, disk-backed OAuth token caching so you only authenticate once. On first run it opens a browser for Google consent; subsequent runs reuse the cached tokens automatically.

Tokens are stored encrypted at ~/.workspace-mcp/cli-tokens/ using a Fernet key auto-generated at ~/.workspace-mcp/.cli-encryption-key.

To use workspace-cli globally, you'll want to start in this repo and run uv tool install .

Once complete, you'll have workspace-cli available globally via workspace-cli

Note: there is a public (but abandoned) pypi package with the same name - do not use uvx, as it will pull the wrong thing.

workspace-cli Commands ← Persistent OAuth, no re-auth on every call

▶ List Tools

uv run workspace-cli list
uv run workspace-cli --url https://custom.server/mcp list

# Or, if installed globally:
workspace-cli list
workspace-cli --url https://custom.server/mcp list

View all available tools

◆ Call a Tool

uv run workspace-cli call search_gmail_messages \
  query="is:unread" max_results=5

Execute a tool with key=value arguments

Set URL for remote endpoints with --url or the WORKSPACE_MCP_URL environment variable.

Advanced: FastMCP CLI ← inspect, install, discover

The upstream FastMCP CLI is also bundled and provides additional commands for schema inspection, client installation, and editor discovery. Note that fastmcp uses in-memory token storage, so each invocation may re-trigger the OAuth flow.

fastmcp inspect fastmcp_server.py                        # print tools, resources, prompts
fastmcp install claude-code fastmcp_server.py             # one-command client setup
fastmcp install cursor fastmcp_server.py
fastmcp discover                                          # find servers configured in editors

See fastmcp --help or the FastMCP CLI docs for the full command reference.

Tool Tiers

The server organizes tools into three progressive tiers for simplified deployment. Choose a tier that matches your usage needs and API quota requirements.

Available Tiers

Core (--tool-tier core) Essential tools for everyday tasks. Perfect for light usage with minimal API quotas. Includes search, read, create, and basic modify operations across all services.

Extended (--tool-tier extended) Core functionality plus management tools. Adds labels, folders, batch operations, and advanced search. Ideal for regular usage with moderate API needs.

Complete (--tool-tier complete) Full API access including comments, headers/footers, publishing settings, and administrative functions. For power users needing maximum functionality.

Important Notes

Start with core and upgrade as needed Tiers are cumulative – each includes all previous Mix and match with --tools for specific services Configuration in core/tool_tiers.yaml Authentication included in all tiers

Usage Examples

# Basic tier selection
uv run main.py --tool-tier core                            # Start with essential tools only
uv run main.py --tool-tier extended                        # Expand to include management features
uv run main.py --tool-tier complete                        # Enable all available functionality

# Selective service loading with tiers
uv run main.py --tools gmail drive --tool-tier core        # Core tools for specific services
uv run main.py --tools gmail --tool-tier extended          # Extended Gmail functionality only
uv run main.py --tools docs sheets --tool-tier complete    # Full access to Docs and Sheets

# Combine tier selection with granular permission levels
uv run main.py --permissions gmail:organize drive:full --tool-tier core

📋 Credential Configuration

🔑 OAuth Credentials Setup ← Essential for all installations

🚀 Environment Variables

export GOOGLE_OAUTH_CLIENT_ID=\
  "your-client-id"
export GOOGLE_OAUTH_CLIENT_SECRET=\
  "your-secret"

Best for production

📁 File-based

# Download & place in project root
client_secret.json

# Or specify custom path
export GOOGLE_CLIENT_SECRET_PATH=\
  /path/to/secret.json

Traditional method

⚡ .env File

cp .env.oauth21 .env
# Edit .env with credentials

Best for development

📖 Credential Loading Details ← Understanding priority & best practices

Loading Priority

  1. Environment variables (export VAR=value)
  2. .env file in project root (warning - if you run via uvx rather than uv run from the repo directory, you are spawning a standalone process not associated with your clone of the repo and it will not find your .env file without specifying it directly)
  3. client_secret.json via GOOGLE_CLIENT_SECRET_PATH
  4. Default client_secret.json in project root

Why Environment Variables?

  • Docker/K8s ready - Native container support
  • Cloud platforms - Heroku, Railway, Vercel
  • CI/CD pipelines - GitHub Actions, Jenkins
  • No secrets in git - Keep credentials secure
  • Easy rotation - Update without code changes

🧰 Available Tools

Note: All tools support automatic authentication via @require_google_service() decorators with 30-minute service caching.

📖 Looking for detailed parameters? Visit the Complete Documentation → for comprehensive tool reference, examples, and API guides!

📅 Google Calendar calendar_tools.py

ToolTierDescription
list_calendarsCoreList accessible calendars
get_eventsCoreRetrieve events with time range filtering
manage_eventCoreCreate, update, or delete calendar events
create_calendarExtendedCreate a new secondary Google Calendar
query_freebusyExtendedQuery free/busy information for calendars
manage_out_of_officeExtendedCreate, list, update, or delete Out of Office events
manage_focus_timeExtendedCreate, list, update, or delete Focus Time events

📁 Google Drive drive_tools.py

ToolTierDescription
search_drive_filesCoreSearch files with query syntax
get_drive_file_contentCoreRead file content (Office, PDF, image)
get_drive_file_download_urlCoreDownload Drive files to local disk
create_drive_fileCoreCreate files or fetch from URLs
create_drive_folderCoreCreate empty folders in Drive or shared drives
import_to_google_docCoreImport files (MD, DOCX, HTML, etc.) as Google Docs
get_drive_shareable_linkCoreGet shareable links for a file
list_drive_itemsExtendedList folder contents or shared drives
copy_drive_fileExtendedCopy existing files (templates) with optional renaming
update_drive_fileExtendedUpdate file metadata, move between folders
manage_drive_accessExtendedGrant, update, revoke permissions, and transfer ownership
set_drive_file_permissionsExtendedSet link sharing and file-level sharing settings
get_drive_file_permissionsCompleteGet file metadata, parents, and permissions
check_drive_file_public_accessCompleteCheck public sharing status

📧 Gmail gmail_tools.py

ToolTierDescription
search_gmail_messagesCoreSearch with Gmail operators
get_gmail_message_contentCoreRetrieve message content
get_gmail_messages_content_batchCoreBatch retrieve message content
send_gmail_messageCoreSend emails
get_gmail_thread_contentExtendedGet full thread content
modify_gmail_message_labelsExtendedModify message labels
list_gmail_labelsExtendedList available labels
list_gmail_filtersExtendedList Gmail filters
manage_gmail_labelExtendedCreate/update/delete labels
manage_gmail_filterExtendedCreate or delete Gmail filters
draft_gmail_messageExtendedCreate drafts
get_gmail_threads_content_batchCompleteBatch retrieve thread content
batch_modify_gmail_message_labelsCompleteBatch modify labels
start_google_authCompleteLegacy OAuth 2.0 auth (disabled when OAuth 2.1 is enabled)
📎 Email Attachments ← Send emails with files

Both send_gmail_message and draft_gmail_message support attachments via two methods:

Option 1: File Path (local server only)

attachments=[{"path": "/path/to/report.pdf"}]

Reads file from disk, auto-detects MIME type. Optional filename override.

Option 2: Base64 Content (works everywhere)

attachments=[{
    "filename": "report.pdf",
    "content": "JVBERi0xLjQK...",  # base64-encoded
    "mime_type": "application/pdf"   # optional
}]

⚠️ Centrally Hosted Servers: When the MCP server runs remotely (cloud, shared instance), it cannot access your local filesystem. Use Option 2 with base64-encoded content. Your MCP client must encode files before sending.

📥 Downloaded Attachment Storage ← Where downloaded files are saved

When downloading Gmail attachments (get_gmail_attachment_content) or Drive files (get_drive_file_download_url), files are saved to a persistent local directory rather than a temporary folder in the working directory.

Default location: ~/.workspace-mcp/attachments/

Files are saved with their original filename plus a short UUID suffix for uniqueness (e.g., invoice_a1b2c3d4.pdf). In stdio mode, the tool returns the absolute file path for direct filesystem access. In HTTP mode, it returns a download URL via the /attachments/{file_id} endpoint.

To customize the storage directory:

export WORKSPACE_ATTACHMENT_DIR="/path/to/custom/dir"

Saved files expire after 1 hour and are cleaned up automatically.

📝 Google Docs docs_tools.py

ToolTierDescription
get_doc_contentCoreExtract document text
create_docCoreCreate new documents
modify_doc_textCoreInsert, replace, and richly format text with tab/segment targeting, append-to-segment support, advanced typography, and link management
search_docsExtendedFind documents by name
find_and_replace_docExtendedFind and replace text
list_docs_in_folderExtendedList docs in folder
insert_doc_elementsExtendedAdd tables, lists, page breaks
update_paragraph_styleExtendedApply advanced paragraph styling including headings, spacing, direction, pagination controls, shading, and bulleted/numbered/checkbox lists with nesting
get_doc_as_markdownExtendedExport document as formatted Markdown with optional comments
insert_doc_imageCompleteInsert images from Drive/URLs
update_doc_headers_footersCompleteCreate or update headers and footers with correct segment-aware writes
batch_update_docCompleteExecute atomic multi-step Docs API operations including named ranges, section breaks, document/section layout, header/footer creation, segment-aware inserts, images, tables, and rich formatting
inspect_doc_structureCompleteAnalyze document structure, including safe insertion points, tables, section breaks, headers/footers, and named ranges
export_doc_to_pdfExtendedExport document to PDF
create_table_with_dataCompleteCreate data tables
debug_table_structureCompleteDebug table issues
list_document_commentsCompleteList all document comments
manage_document_commentCompleteCreate, reply to, or resolve comments
manage_doc_tabCompleteCreate, rename, delete, or populate tabs from markdown

📊 Google Sheets sheets_tools.py

ToolTierDescription
read_sheet_valuesCoreRead cell ranges
modify_sheet_valuesCoreWrite/update/clear cells
create_spreadsheetCoreCreate new spreadsheets
list_spreadsheetsExtendedList accessible spreadsheets
get_spreadsheet_infoExtendedGet spreadsheet metadata
format_sheet_rangeExtendedApply colors, number formats, text wrapping, alignment, bold/italic, font size
list_sheet_tablesExtendedList structured tables with IDs, names, ranges, and columns
create_sheetCompleteAdd sheets to existing files
move_sheet_rowsCompleteMove rows between sheets within a spreadsheet
append_table_rowsCompleteAppend rows to a structured table, auto-extending the table range
list_spreadsheet_commentsCompleteList all spreadsheet comments
manage_spreadsheet_commentCompleteCreate, reply to, or resolve comments
manage_conditional_formattingCompleteAdd, update, or delete conditional formatting rules

🖼️ Google Slides slides_tools.py

ToolTierDescription
create_presentationCoreCreate new presentations
get_presentationCoreRetrieve presentation details
batch_update_presentationExtendedApply multiple updates
get_pageExtendedGet specific slide information
get_page_thumbnailExtendedGenerate slide thumbnails
list_presentation_commentsCompleteList all presentation comments
manage_presentation_commentCompleteCreate, reply to, or resolve comments

📋 Google Forms forms_tools.py

ToolTierDescription
create_formCoreCreate new forms
get_formCoreRetrieve form details & URLs
set_publish_settingsCompleteConfigure form settings
get_form_responseCompleteGet individual responses
list_form_responsesExtendedList all responses with pagination
batch_update_formCompleteApply batch updates (questions, settings)

✓ Google Tasks tasks_tools.py

ToolTierDescription
list_tasksCoreList tasks with filtering
get_taskCoreRetrieve task details
manage_taskCoreCreate, update, delete, or move tasks
list_task_listsCompleteList task lists
get_task_listCompleteGet task list details
manage_task_listCompleteCreate, update, delete task lists, or clear completed tasks

👤 Google Contacts contacts_tools.py

ToolTierDescription
search_contactsCoreSearch contacts by name, email, phone
get_contactCoreRetrieve detailed contact info
list_contactsCoreList contacts with pagination
manage_contactCoreCreate, update, or delete contacts
list_contact_groupsExtendedList contact groups/labels
get_contact_groupExtendedGet group details with members
manage_contacts_batchCompleteBatch create, update, or delete contacts
manage_contact_groupCompleteCreate, update, delete groups, or modify membership

💬 Google Chat chat_tools.py

ToolTierDescription
list_spacesExtendedList chat spaces/rooms
get_messagesCoreRetrieve space messages
send_messageCoreSend messages to spaces
search_messagesCoreSearch across chat history
create_reactionCoreAdd emoji reaction to a message
download_chat_attachmentExtendedDownload attachment from a chat message

🔍 Google Custom Search search_tools.py

ToolTierDescription
search_customCorePerform web searches (supports site restrictions via sites parameter)
get_search_engine_infoCompleteRetrieve search engine metadata

⚡ Google Apps Script apps_script_tools.py

ToolTierDescription
list_script_projectsCoreList accessible Apps Script projects
get_script_projectCoreGet complete project with all files
get_script_contentCoreRetrieve specific file content
create_script_projectCoreCreate new standalone or bound project
update_script_contentCoreUpdate or create script files
run_script_functionCoreExecute function with parameters
list_deploymentsExtendedList all project deployments
manage_deploymentExtendedCreate, update, or delete script deployments
list_script_processesExtendedView recent executions and status

Tool Tier Legend:
Core — Essential tools for basic functionality · Minimal API usage · Getting started
Extended — Core + additional features · Regular usage · Expanded capabilities
Complete — All available tools including advanced features · Power users · Full API access


Connect to Claude Desktop

The recommended way to use Google Workspace MCP with Claude Desktop is to run a server instance and connect Claude to it via a Connector. This provides proper OAuth flow, multi-user support, and the best experience.

See the Quick Start Guide for setup instructions.

📝 Legacy: Manual stdio configuration ← For clients without Connector support

⚠️ Note: Stdio mode is a legacy fallback for clients that don't support Connectors. Prefer the Connector-based approach above.

OAuth callback caveat: The legacy stdio callback path includes a local recovery fallback for rare Google redirects that omit the state parameter, but only when --single-user is active. That recovery can only be safe in a single-user local process; in HTTP or hosted multi-user scenarios it could consume another user's pending OAuth state. There is no environment variable to enable this globally.

  1. Open Claude Desktop Settings → Developer → Edit Config

    • macOS: ~/Library/Application Support/Claude/claude_desktop_config.json
    • Windows: %APPDATA%\Claude\claude_desktop_config.json
  2. Add the server configuration:

{
  "mcpServers": {
    "google_workspace": {
      "command": "uvx",
      "args": ["workspace-mcp"],
      "env": {
        "GOOGLE_OAUTH_CLIENT_ID": "your-client-id",
        "GOOGLE_OAUTH_CLIENT_SECRET": "your-secret",
        "OAUTHLIB_INSECURE_TRANSPORT": "1"
      }
    }
  }
}

Connect to LM Studio

Add a new MCP server in LM Studio (Settings → MCP Servers) using the same JSON format:

{
  "mcpServers": {
    "google_workspace": {
      "command": "uvx",
      "args": ["workspace-mcp"],
      "env": {
        "GOOGLE_OAUTH_CLIENT_ID": "your-client-id",
        "GOOGLE_OAUTH_CLIENT_SECRET": "your-secret",
        "OAUTHLIB_INSECURE_TRANSPORT": "1",
      }
    }
  }
}

2. Advanced / Cross-Platform Installation

If you’re developing, deploying to servers, or using another MCP-capable client, keep reading.

Instant CLI (uvx)

Quick Start with uvx ← No installation required!
# Requires Python 3.10+ and uvx
# First, set credentials (see Credential Configuration above)
uvx workspace-mcp --tool-tier core  # or --tools gmail drive calendar

Note: Configure OAuth credentials before running. Supports environment variables, .env file, or client_secret.json.

Local Development Setup

🛠️ Developer Workflow ← Install deps, lint, and test

More MCP Servers

MCP Servers

Playwright MCP

Official Microsoft Playwright MCP server — give Claude full browser automation: navigate pages, click elements, fill forms, take screenshots, and scrape content.

playwrightbrowserautomation+3
by Microsoft
GitHub
MCP Servers

Container Use (Dagger)

Official Dagger MCP server — give Claude isolated container environments per task. Each agent gets its own container with configurable tools, filesystem, and network access.

daggercontainersdocker+4
by Dagger
GitHub
MCP Servers

E2B Code Sandbox MCP

Official E2B MCP server — execute arbitrary code in secure cloud sandboxes, run scripts in isolated environments, and get output back in Claude without local execution risks.

e2bsandboxcode-execution+4
by E2B
GitHub

Command Palette

Search for a command to run...