You're Invited:Meet the Socket Team at BlackHat and DEF CON in Las Vegas, Aug 4-6.RSVP β†’
Socket
Book a DemoInstallSign in
Socket

workspace-mcp

Package Overview
Dependencies
Maintainers
1
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

workspace-mcp

Comprehensive, highly performant Google Workspace Streamable HTTP & SSE MCP Server for Calendar, Gmail, Docs, Sheets, Slides & Drive

1.1.17
pipPyPI
Maintainers
1

Google Workspace MCP Server

License: MIT Python 3.10+ PyPI PyPI Downloads Website Verified on MseeP

This is the single most feature-complete Google Workspace MCP server now with 1-click Claude installation

Full natural language control over Google Calendar, Drive, Gmail, Docs, Sheets, Slides, Forms, Tasks, and Chat through all MCP clients, AI assistants and developer tools.

Support for all free Google accounts (Gmail, Docs, Drive etc) & Google Workspace plans (Starter, Standard, Plus, Enterprise, Non Profit etc) with their expanded app options like Chat & Spaces.

See it in action:

A quick plug for AI-Enhanced Docs

But why?

This README was written with AI assistance, and here's why that matters

As a solo dev building open source tools that many never see outside use, comprehensive documentation often wouldn't happen without AI help. Using agentic dev tools like Roo & Claude Code that understand the entire codebase, AI doesn't just regurgitate generic content - it extracts real implementation details and creates accurate, specific documentation.

In this case, Sonnet 4 took a pass & a human (me) verified them 7/10/25.

Overview

A production-ready MCP server that integrates all major Google Workspace services with AI assistants. Built with FastMCP for optimal performance, featuring advanced authentication handling, service caching, and streamlined development patterns.

Features

  • πŸ” Advanced OAuth 2.0: Secure authentication with automatic token refresh, transport-aware callback handling, session management, and centralized scope management
  • πŸ“… Google Calendar: Full calendar management with event CRUD operations
  • πŸ“ Google Drive: File operations with native Microsoft Office format support (.docx, .xlsx)
  • πŸ“§ Gmail: Complete email management with search, send, and draft capabilities
  • πŸ“„ Google Docs: Document operations including content extraction, creation, and comment management
  • πŸ“Š Google Sheets: Comprehensive spreadsheet management with flexible cell operations and comment management
  • πŸ–ΌοΈ Google Slides: Presentation management with slide creation, updates, content manipulation, and comment management
  • πŸ“ Google Forms: Form creation, retrieval, publish settings, and response management
  • βœ“ Google Tasks: Complete task and task list management with hierarchy, due dates, and status tracking
  • πŸ’¬ Google Chat: Space management and messaging capabilities
  • πŸ” Google Custom Search: Programmable Search Engine (PSE) integration for custom web searches
  • πŸ”„ All Transports: Stdio, Streamable HTTP & SSE, OpenAPI compatibility via mcpo
  • ⚑ High Performance: Service caching, thread-safe sessions, FastMCP integration
  • 🧩 Developer Friendly: Minimal boilerplate, automatic service injection, centralized configuration

πŸš€ Quick Start

  • Download: Grab the latest google_workspace_mcp.dxt from the β€œReleases” page
  • Install: Double-click the file – Claude Desktop opens and prompts you to Install
  • Configure: In Claude Desktop β†’ Settings β†’ Extensions β†’ Google Workspace MCP, paste your Google OAuth credentials
  • Use it: Start a new Claude chat and call any Google Workspace tool

Why DXT?

Desktop Extensions (.dxt) bundle the server, dependencies, and manifest so users go from download β†’ working MCP in one click – no terminal, no JSON editing, no version conflicts.

Required Configuration

Environment - you will configure these in Claude itself, see screenshot:
VariablePurpose
GOOGLE_OAUTH_CLIENT_IDOAuth client ID from Google Cloud
GOOGLE_OAUTH_CLIENT_SECRETOAuth client secret
USER_GOOGLE_EMAIL (optional)Default email for single-user auth
GOOGLE_PSE_API_KEY (optional)API key for Google Custom Search - see Custom Search Setup
GOOGLE_PSE_ENGINE_ID (optional)Programmable Search Engine ID for Custom Search
OAUTHLIB_INSECURE_TRANSPORT=1Development only (allows http:// redirect)

Claude Desktop stores these securely in the OS keychain; set them once in the extension pane.

---

Prerequisites

  • Python 3.10+
  • uvx (for instant installation) or uv (for development)
  • Google Cloud Project with OAuth 2.0 credentials

Configuration

  • Google Cloud Setup:
    • Create OAuth 2.0 credentials (web application) in Google Cloud Console

    • Create a new project (or use an existing one) for your MCP server.

    • Navigate to APIs & Services β†’ Credentials.

    • Click Create Credentials β†’ OAuth Client ID.

    • Choose Web Application as the application type.

    • Add redirect URI: http://localhost:8000/oauth2callback

    • Enable APIs:

    • In the Google Cloud Console, go to APIs & Services β†’ Library.

    • Search for & enable Calendar, Drive, Gmail, Docs, Sheets, Slides, Forms, Tasks, Chat

    • Expand the section below marked "API Enablement Links" for direct links to each!

API Enablement Links You can enable each one by clicking the links below (make sure you're logged into the Google Cloud Console and have the correct project selected):

1.1. Credentials:

  • Configure credentials using one of these methods:

    Option A: Environment Variables (Recommended for Production)

    export GOOGLE_OAUTH_CLIENT_ID="your-client-id.apps.googleusercontent.com"
    export GOOGLE_OAUTH_CLIENT_SECRET="your-client-secret"
    export GOOGLE_OAUTH_REDIRECT_URI="http://localhost:8000/oauth2callback"  # Optional
    

    Option B: File-based (Traditional)

    • Download credentials as client_secret.json in project root
    • To use a different location, set GOOGLE_CLIENT_SECRET_PATH (or legacy GOOGLE_CLIENT_SECRETS) environment variable with the file path

Credential Loading Priority:

  • Environment variables (GOOGLE_OAUTH_CLIENT_ID, GOOGLE_OAUTH_CLIENT_SECRET)
  • File specified by GOOGLE_CLIENT_SECRET_PATH or GOOGLE_CLIENT_SECRETS environment variable
  • Default file (client_secret.json in project root)

Why Environment Variables?

  • βœ… Containerized deployments (Docker, Kubernetes)
  • βœ… Cloud platforms (Heroku, Railway, etc.)
  • βœ… CI/CD pipelines
  • βœ… No secrets in version control
  • βœ… Easy credential rotation
  • Environment:

    export OAUTHLIB_INSECURE_TRANSPORT=1  # Development only
    export USER_GOOGLE_EMAIL=your.email@gmail.com  # Optional: Default email for auth - use this for single user setups and you won't need to set your email in system prompt for magic auth
    export GOOGLE_PSE_API_KEY=your-custom-search-api-key  # Optional: Only needed for Google Custom Search tools
    export GOOGLE_PSE_ENGINE_ID=your-search-engine-id  # Optional: Only needed for Google Custom Search tools
    
  • Server Configuration: The server's base URL and port can be customized using environment variables:

    • WORKSPACE_MCP_BASE_URI: Sets the base URI for the server (default: http://localhost). This affects the server_url used to construct the default OAUTH_REDIRECT_URI if GOOGLE_OAUTH_REDIRECT_URI is not set.
    • WORKSPACE_MCP_PORT: Sets the port the server listens on (default: 8000). This affects the server_url, port, and OAUTH_REDIRECT_URI.
    • USER_GOOGLE_EMAIL: Optional default email for authentication flows. If set, the LLM won't need to specify your email when calling start_google_auth.
    • GOOGLE_OAUTH_REDIRECT_URI: Sets an override for OAuth redirect specifically, must include a full address (i.e. include port if necessary). Use this if you want to run your OAuth redirect separately from the MCP. This is not recommended outside of very specific cases

Google Custom Search Setup

To use the Google Custom Search tools, you need to:

  • Create a Programmable Search Engine:

  • Get an API Key:

    • Visit Google Developers Console
    • Create or select a project
    • Enable the Custom Search API
    • Create credentials (API Key)
    • Set the GOOGLE_PSE_API_KEY environment variable with your API key
  • Configure Environment Variables:

    • Set GOOGLE_PSE_API_KEY to your Custom Search API key
    • Set GOOGLE_PSE_ENGINE_ID to your Search Engine ID (the cx parameter from step 1)

For detailed setup instructions, see the Custom Search JSON API documentation.

Start the Server

# Default (stdio mode for MCP clients)
uv run main.py

# HTTP mode (for web interfaces and debugging)
uv run main.py --transport streamable-http

# Single-user mode (simplified authentication)
uv run main.py --single-user

# Selective tool registration (only register specific tools)
uv run main.py --tools gmail drive calendar tasks
uv run main.py --tools sheets docs
uv run main.py --single-user --tools gmail  # Can combine with other flags

# Docker
docker build -t workspace-mcp .
docker run -p 8000:8000 -v $(pwd):/app workspace-mcp --transport streamable-http

Available Tools for --tools flag: gmail, drive, calendar, docs, sheets, forms, tasks, chat, search

Connect to Claude Desktop

The server supports two transport modes:

Guided Setup (Recommended if not using DXT)

python install_claude.py

This script automatically:

  • Prompts you for your Google OAuth credentials (Client ID and Secret)
  • Creates the Claude Desktop config file in the correct location
  • Sets up all necessary environment variables
  • No manual file editing required!

After running the script, just restart Claude Desktop and you're ready to go.

Manual Claude Configuration (Alternative)

  • Open Claude Desktop Settings β†’ Developer β†’ Edit Config
    • macOS: ~/Library/Application Support/Claude/claude_desktop_config.json
    • Windows: %APPDATA%\Claude\claude_desktop_config.json
  • Add the server configuration:
    {
      "mcpServers": {
        "google_workspace": {
          "command": "uvx",
          "args": ["workspace-mcp"],
          "env": {
            "GOOGLE_OAUTH_CLIENT_ID": "your-client-id.apps.googleusercontent.com",
            "GOOGLE_OAUTH_CLIENT_SECRET": "your-client-secret",
            "OAUTHLIB_INSECURE_TRANSPORT": "1"
          }
        }
      }
    }
    

2. Advanced / Cross-Platform Installation

If you’re developing, deploying to servers, or using another MCP-capable client, keep reading.

Instant CLI (uvx)

# Requires Python 3.10+ and uvx
export GOOGLE_OAUTH_CLIENT_ID="xxx"
export GOOGLE_OAUTH_CLIENT_SECRET="yyy"
uvx workspace-mcp --tools gmail drive calendar

Run instantly without manual installation - you must configure OAuth credentials when using uvx. You can use either environment variables (recommended for production) or set the GOOGLE_CLIENT_SECRET_PATH (or legacy GOOGLE_CLIENT_SECRETS) environment variable to point to your client_secret.json file.

# Set OAuth credentials via environment variables (recommended)
export GOOGLE_OAUTH_CLIENT_ID="your-client-id.apps.googleusercontent.com"
export GOOGLE_OAUTH_CLIENT_SECRET="your-client-secret"

# Start the server with all Google Workspace tools
uvx workspace-mcp

# Start with specific tools only
uvx workspace-mcp --tools gmail drive calendar tasks

# Start in HTTP mode for debugging
uvx workspace-mcp --transport streamable-http

Requires Python 3.10+ and uvx. The package is available on PyPI.

Development Installation

For development or customization:

git clone https://github.com/taylorwilsdon/google_workspace_mcp.git
cd google_workspace_mcp
uv run main.py

Development Installation (For Contributors):

{
  "mcpServers": {
    "google_workspace": {
      "command": "uv",
      "args": [
        "run",
        "--directory",
        "/path/to/repo/google_workspace_mcp",
        "main.py"
      ],
      "env": {
        "GOOGLE_OAUTH_CLIENT_ID": "your-client-id.apps.googleusercontent.com",
        "GOOGLE_OAUTH_CLIENT_SECRET": "your-client-secret",
        "OAUTHLIB_INSECURE_TRANSPORT": "1"
      }
    }
  }
}

HTTP Mode (For debugging or web interfaces)

If you need to use HTTP mode with Claude Desktop:

{
  "mcpServers": {
    "google_workspace": {
      "command": "npx",
      "args": ["mcp-remote", "http://localhost:8000/mcp"]
    }
  }
}

Note: Make sure to start the server with --transport streamable-http when using HTTP mode.

First-Time Authentication

The server features transport-aware OAuth callback handling:

  • Stdio Mode: Automatically starts a minimal HTTP server on port 8000 for OAuth callbacks
  • HTTP Mode: Uses the existing FastAPI server for OAuth callbacks
  • Same OAuth Flow: Both modes use http://localhost:8000/oauth2callback for consistency

When calling a tool:

  • Server returns authorization URL
  • Open URL in browser and authorize
  • Server handles OAuth callback automatically (on port 8000 in both modes)
  • Retry the original request

🧰 Available Tools

Note: All tools support automatic authentication via @require_google_service() decorators with 30-minute service caching.

πŸ“… Google Calendar (calendar_tools.py)

ToolDescription
list_calendarsList accessible calendars
get_eventsRetrieve events with time range filtering
get_eventFetch detailed information of a single event by ID
create_eventCreate events (all-day or timed) with optional Drive file attachments
modify_eventUpdate existing events
delete_eventRemove events

πŸ“ Google Drive (drive_tools.py)

ToolDescription
search_drive_filesSearch files with query syntax
get_drive_file_contentRead file content (supports Office formats)
list_drive_itemsList folder contents
create_drive_fileCreate new files or fetch content from public URLs

πŸ“§ Gmail (gmail_tools.py)

ToolDescription
search_gmail_messagesSearch with Gmail operators
get_gmail_message_contentRetrieve message content
send_gmail_messageSend emails
draft_gmail_messageCreate drafts

πŸ“ Google Docs (docs_tools.py)

ToolDescription
search_docsFind documents by name
get_doc_contentExtract document text
list_docs_in_folderList docs in folder
create_docCreate new documents
read_doc_commentsRead all comments and replies
create_doc_commentCreate new comments
reply_to_commentReply to existing comments
resolve_commentResolve comments

πŸ“Š Google Sheets (sheets_tools.py)

ToolDescription
list_spreadsheetsList accessible spreadsheets
get_spreadsheet_infoGet spreadsheet metadata
read_sheet_valuesRead cell ranges
modify_sheet_valuesWrite/update/clear cells
create_spreadsheetCreate new spreadsheets
create_sheetAdd sheets to existing files
read_sheet_commentsRead all comments and replies
create_sheet_commentCreate new comments
reply_to_sheet_commentReply to existing comments
resolve_sheet_commentResolve comments

πŸ–ΌοΈ Google Slides (slides_tools.py)

ToolDescription
create_presentationCreate new presentations
get_presentationRetrieve presentation details
batch_update_presentationApply multiple updates at once
get_pageGet specific slide information
get_page_thumbnailGenerate slide thumbnails
read_presentation_commentsRead all comments and replies
create_presentation_commentCreate new comments
reply_to_presentation_commentReply to existing comments
resolve_presentation_commentResolve comments

πŸ“ Google Forms (forms_tools.py)

ToolDescription
create_formCreate new forms with title and description
get_formRetrieve form details, questions, and URLs
set_publish_settingsConfigure form template and authentication settings
get_form_responseGet individual form response details
list_form_responsesList all responses to a form with pagination

βœ“ Google Tasks (tasks_tools.py)

ToolDescription
list_task_listsList all task lists with pagination support
get_task_listRetrieve details of a specific task list
create_task_listCreate new task lists with custom titles
update_task_listModify existing task list titles
delete_task_listRemove task lists and all contained tasks
list_tasksList tasks in a specific list with filtering options
get_taskRetrieve detailed information about a specific task
create_taskCreate new tasks with title, notes, due dates, and hierarchy
update_taskModify task properties including title, notes, status, and due dates
delete_taskRemove tasks from task lists
move_taskReposition tasks within lists or move between lists
clear_completed_tasksHide all completed tasks from a list

πŸ’¬ Google Chat (chat_tools.py)

ToolDescription
list_spacesList chat spaces/rooms
get_messagesRetrieve space messages
send_messageSend messages to spaces
search_messagesSearch across chat history

πŸ” Google Custom Search (search_tools.py)

ToolDescription
search_customPerform web searches using Programmable Search Engine
get_search_engine_infoRetrieve search engine metadata and configuration
search_custom_siterestrictSearch within specific sites/domains

πŸ› οΈ Development

Project Structure

google_workspace_mcp/
β”œβ”€β”€ auth/              # Authentication system with decorators
β”œβ”€β”€ core/              # MCP server and utilities
β”œβ”€β”€ g{service}/        # Service-specific tools
β”œβ”€β”€ main.py            # Server entry point
β”œβ”€β”€ client_secret.json # OAuth credentials (not committed)
└── pyproject.toml     # Dependencies

Adding New Tools

from auth.service_decorator import require_google_service

@require_google_service("drive", "drive_read")  # Service + scope group
async def your_new_tool(service, param1: str, param2: int = 10):
    """Tool description"""
    # service is automatically injected and cached
    result = service.files().list().execute()
    return result  # Return native Python objects

Architecture Highlights

  • Service Caching: 30-minute TTL reduces authentication overhead
  • Scope Management: Centralized in SCOPE_GROUPS for easy maintenance
  • Error Handling: Native exceptions instead of manual error construction
  • Multi-Service Support: @require_multiple_services() for complex tools

πŸ”’ Security

  • Credentials: Never commit client_secret.json or .credentials/ directory
  • OAuth Callback: Uses http://localhost:8000/oauth2callback for development (requires OAUTHLIB_INSECURE_TRANSPORT=1)
  • Transport-Aware Callbacks: Stdio mode starts a minimal HTTP server only for OAuth, ensuring callbacks work in all modes
  • Production: Use HTTPS for callback URIs and configure accordingly
  • Network Exposure: Consider authentication when using mcpo over networks
  • Scope Minimization: Tools request only necessary permissions

🌐 Integration with Open WebUI

To use this server as a tool provider within Open WebUI:

Instant Start (No Config Needed)

Just copy and paste the below, set your values and you're off!

GOOGLE_OAUTH_CLIENT_ID="your_client_id" GOOGLE_OAUTH_CLIENT_SECRET="your_client_secret" uvx mcpo --port 8000 --api-key "top-secret" -- uvx workspace-mcp

Otherwise:

1. Create MCPO Configuration

Create a file named config.json with the following structure to have mcpo make the streamable HTTP endpoint available as an OpenAPI spec tool:

{
  "mcpServers": {
    "google_workspace": {
      "type": "streamablehttp",
      "url": "http://localhost:8000/mcp"
    }
  }
}

2. Start the MCPO Server

mcpo --port 8001 --config config.json --api-key "your-optional-secret-key"

This command starts the mcpo proxy, serving your active (assuming port 8000) Google Workspace MCP on port 8001.

3. Configure Open WebUI

  • Navigate to your Open WebUI settings
  • Go to "Connections" β†’ "Tools"
  • Click "Add Tool"
  • Enter the Server URL: http://localhost:8001/google_workspace (matching the mcpo base URL and server name from config.json)
  • If you used an --api-key with mcpo, enter it as the API Key
  • Save the configuration

The Google Workspace tools should now be available when interacting with models in Open WebUI.

πŸ“„ License

MIT License - see LICENSE file for details.

Gmail Integration Calendar Management Batch Emails

Keywords

mcp

FAQs

Did you know?

Socket

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Install

Related posts