The full upstream README, mirrored here for reference. Install config, tool schemas, adoption signals, and an original overview live on the Ve Gws listing page.
Most Google Workspace MCPs let you read. This one lets you write — a Python fork of taylorwilsdon/google_workspace_mcp with 28 additional authoring tools on top (deeper Slides, markdown-to-Docs, smart chips, Sheets data validation, recursive Drive copy, revisions). See Why VE-GWS (vs. upstream) below.
Part of Vibe Entrepreneurs — a community for any vibe coders shipping real work with AI: solo indie builders, product-minded devs, agency folks, side-project makers. You don't need to use ve-gws to join. Come say hi: vibeentrepreneurs.com.
Companion repo:
HuntsDesk/ve-kit— Vibe Coding Framework & Persistent Memory for Claude Code (persistent task board, process gates, Docker autonomous worker). Install standalone or alongside.
Full natural language control over Google Calendar, Drive, Gmail, Docs, Sheets, Slides, Forms, Tasks, Contacts, and Chat through all MCP clients, AI assistants and developer tools. Includes a full featured CLI for use with tools like Claude Code and Codex!
The most feature-complete Google Workspace MCP server, with Remote OAuth2.1 multi-user support and 1-click Claude installation. With native OAuth 2.1, stateless mode and external auth server support, it's the only Workspace MCP you can host for your whole organization centrally & securely!
HuntsDesk/ve-gws is a fork of taylorwilsdon/google_workspace_mcp that adds 28 tools in the gaps upstream doesn't cover — mostly around authoring workflows (building presentations, rendering formatted docs, managing structured sheets).
| Area | Additions |
|---|---|
| Slides | Create shapes + text boxes · set slide backgrounds · reorder slides · duplicate slides · read/write speaker notes · style shapes + text + paragraphs · delete elements |
| Docs | Insert native markdown (rendered, not as a code block) · insert person + file smart chips · read existing smart chips · find-and-replace · apply_continuous_numbering (convert plain-text "1. 2. 3." into a real numbered list that continues across intervening prompts and sub-bullets — idempotent) |
| Sheets | Data validation rules · named ranges · range protection · sheet tab management (add/rename/delete/reorder) |
| Drive | Recursive folder copy · list revision history · restore prior revisions |
Some feature ideas ported from blakesplay/apollo, which was itself based on piotr-agier/google-drive-mcp. See the Available Tools tables below — additions are tagged Extended or Complete.
Quality: 822 tests pass (803 upstream + 19 new). Upstream commits from Taylor's repo are merged in periodically — see Pulling Upstream Changes.
ve-* family: Companion to HuntsDesk/ve-kit (Vibe Coding Framework & Persistent Memory for Claude Code — task board, process gates, Docker autonomous worker). VE-GWS is the Google Workspace MCP piece of that toolchain — install standalone or alongside. See the intro at the top of this README for the community invite.
|
⚡ Start Quick Start · Prerequisites Google Cloud · Credentials |
🧰 Tools All Tools · Tool Tiers CLI · Start Server |
🔌 Connect 1-Click Install · Claude Desktop Claude Code · VS Code · LM Studio |
🚀 Deploy OAuth 2.1 · Stateless External OAuth · Reverse Proxy |
📐 Develop Architecture · Dev Setup Security · License |
See it in action:
Workspace MCP is the single most complete MCP server that integrates all major Google Workspace services with AI assistants. It supports both single-user operation and multi-user authentication via OAuth 2.1, making it a powerful backend for custom applications. Built with FastMCP for optimal performance, featuring advanced authentication handling, service caching, and streamlined development patterns. The entire toolset is available for CLI usage supporting both local and remote instances.
Simplified Setup: can use Google Desktop OAuth clients for local runs - no redirect URIs or port configuration needed!
12 services — Gmail · Drive · Calendar · Docs · Sheets · Slides · Forms · Chat · Apps Script · Tasks · Contacts · Search
|
📧 Gmail — Complete email management, end-to-end coverage |
⚡ Apps Script — Cross-application workflow automation ✅ Tasks — Task & list management with hierarchy 🔐 Authentication & Security |
|
For Security Teams This server sends no data anywhere except Google's APIs, on behalf of the authenticated user, using your own OAuth client credentials. There is no telemetry, no usage reporting, no analytics, no license server, and no SaaS dependency. The entire data path is: your infrastructure → Google APIs.
Full dependency tree in |
For Legal & Procurement This project is MIT licensed — not "open core," not "source available," not "free with a CLA." There is no dual licensing, no commercial tier gating features, and no contributor license agreement.
The license is 21 lines and says what it means. |
Set credentials → pick a launch command → connect your client
💡 New to Workspace MCP? Check out the Interactive Quick Start Guide → with step-by-step setup, screenshots, and troubleshooting tips!
|
Confidential Client Quick Start |
Secretless / Public OAuth 2.1 (PKCE) Quick Start |
Credential setup → · All launch options → · Tier details →
| Variable | Purpose | |
|---|---|---|
| 🔐 Authentication | ||
GOOGLE_OAUTH_CLIENT_ID | required | OAuth client ID from Google Cloud |
GOOGLE_OAUTH_CLIENT_SECRET | OAuth client secret for confidential clients; optional for public OAuth 2.1 PKCE clients | |
OAUTHLIB_INSECURE_TRANSPORT | required* | Set to 1 for development — allows http:// redirect |
USER_GOOGLE_EMAIL | Default email for single-user auth | |
GOOGLE_CLIENT_SECRET_PATH | Custom path to client_secret.json | |
GOOGLE_MCP_CREDENTIALS_DIR | Credential directory — default ~/.google_workspace_mcp/credentials | |
| 🖥️ Server | ||
WORKSPACE_MCP_BASE_URI | Base server URI (no port) — default http://localhost | |
WORKSPACE_MCP_PORT | Listening port — default 8000 | |
WORKSPACE_MCP_HOST | Bind host — default 0.0.0.0 | |
WORKSPACE_EXTERNAL_URL | External URL for reverse proxy setups | |
WORKSPACE_ATTACHMENT_DIR | Downloaded attachments dir — default ~/.workspace-mcp/attachments/ | |
WORKSPACE_MCP_URL | Remote MCP endpoint URL for CLI | |
ALLOWED_FILE_DIRS | Colon-separated allowlist for local file reads | |
| 🔑 OAuth 2.1 & Multi-User | ||
MCP_ENABLE_OAUTH21 | true to enable OAuth 2.1 multi-user support | |
EXTERNAL_OAUTH21_PROVIDER | true for external OAuth flow with bearer tokens | |
WORKSPACE_MCP_STATELESS_MODE | true for stateless container-friendly operation | |
GOOGLE_OAUTH_REDIRECT_URI | Override OAuth callback URL — default auto-constructed | |
OAUTH_CUSTOM_REDIRECT_URIS | Comma-separated additional redirect URIs | |
OAUTH_ALLOWED_ORIGINS | Comma-separated additional CORS origins | |
WORKSPACE_MCP_OAUTH_PROXY_STORAGE_BACKEND | memory, disk, or valkey — see storage backends | |
FASTMCP_SERVER_AUTH_GOOGLE_JWT_SIGNING_KEY | Custom encryption key for OAuth proxy storage; required for public OAuth 2.1 clients when GOOGLE_OAUTH_CLIENT_SECRET is omitted | |
| 🔧 Service Account | ||
GOOGLE_SERVICE_ACCOUNT_KEY_FILE | Path to service account JSON key file (domain-wide delegation) | |
GOOGLE_SERVICE_ACCOUNT_KEY_JSON | Inline service account JSON key (alternative to file) | |
| 🔍 Custom Search | ||
GOOGLE_PSE_API_KEY | API key for Programmable Search Engine | |
GOOGLE_PSE_ENGINE_ID | Search Engine ID for PSE |
*Required for development only. Claude Desktop stores credentials securely in the OS keychain — set them once in the extension pane.
.dxtbundles server, deps & manifest — download → double-click → done. No terminal, no JSON editing.
google_workspace_mcp.dxt from ReleasesPython 3.10+ · uv/uvx · Google Cloud Project with OAuth 2.0 credentials
Create Project — Open Console → → Create new project
Create OAuth Credentials — APIs & Services → Credentials → Create Credentials → OAuth Client ID
Enable APIs — APIs & Services → Library, then enable each service:
| Calendar | Drive | Gmail | Docs |
| Sheets | Slides | Forms | Tasks |
| Chat | People | Custom Search | Apps Script |
Set Credentials — see Environment Variable Reference above, or:
For public OAuth 2.1 PKCE clients, omit GOOGLE_OAUTH_CLIENT_SECRET and set FASTMCP_SERVER_AUTH_GOOGLE_JWT_SIGNING_KEY instead.
|
1. Create Search Engine |
2. Get API Key |
3. Set Variables Configure in environment |
≡ Quick Setup Guide ← Step-by-step instructionsComplete Setup Process:
| ||
📌 Transport Mode Guidance: Use streamable HTTP mode (
--transport streamable-http) for all modern MCP clients including Claude Code, VS Code MCP, and MCP Inspector. Stdio mode is only for clients with incomplete MCP specification support.
|
▶ Legacy Mode ⚠️ Stdio mode (incomplete MCP clients only) |
◆ HTTP Mode (Recommended) ✅ Full MCP spec compliance & OAuth 2.1 |
@ Single User Simplified authentication ⚠️ Cannot be used with OAuth 2.1 mode |
◆ Advanced Options ← Tool selection, tiers & Docker▶ Selective Tool Loading 🔒 Read-Only Mode Read-only mode provides secure, restricted access by:
🔐 Granular Permissions Granular permissions mode provides service-by-service scope control:
★ Tool Tiers ◆ Docker Deployment Available Services: | ||
The workspace-cli command lists tools and calls them against a running server — with encrypted, disk-backed OAuth token caching so you only authenticate once. On first run it opens a browser for Google consent; subsequent runs reuse the cached tokens automatically.
Tokens are stored encrypted at ~/.workspace-mcp/cli-tokens/ using a Fernet key auto-generated at ~/.workspace-mcp/.cli-encryption-key.
|
▶ List Tools View all available tools |
◆ Call a Tool Execute a tool with key=value arguments |
Set URL for remote endpoints with --url or the WORKSPACE_MCP_URL environment variable.
The upstream FastMCP CLI is also bundled and provides additional commands for schema inspection, client installation, and editor discovery. Note that fastmcp uses in-memory token storage, so each invocation may re-trigger the OAuth flow.
See fastmcp --help or the FastMCP CLI docs for the full command reference.
The server organizes tools into three progressive tiers for simplified deployment. Choose a tier that matches your usage needs and API quota requirements.
Available Tiers● Core ( ● Extended ( ● Complete ( |
Important Notes▶ Start with |
|
🚀 Environment Variables Best for production |
📁 File-based Traditional method |
⚡ .env File Best for development |
📖 Credential Loading Details ← Understanding priority & best practicesLoading Priority
Why Environment Variables?
| ||
Note: All tools support automatic authentication via
@require_google_service()decorators with 30-minute service caching.
📖 Looking for detailed parameters? Visit the Complete Documentation → for comprehensive tool reference, examples, and API guides!
calendar_tools.py| Tool | Tier | Description |
|---|---|---|
list_calendars | Core | List accessible calendars |
get_events | Core | Retrieve events with time range filtering |
manage_event | Core | Create, update, or delete calendar events |
create_calendar | Extended | Create a new secondary Google Calendar |
query_freebusy | Extended | Query free/busy information for calendars |
manage_out_of_office | Extended | Create, list, update, or delete Out of Office events |
manage_focus_time | Extended | Create, list, update, or delete Focus Time events |
drive_tools.py| Tool | Tier | Description |
|---|---|---|
search_drive_files | Core | Search files with query syntax |
get_drive_file_content | Core | Read file content (Office, PDF, image) |
get_drive_file_download_url | Core | Download Drive files to local disk |
create_drive_file | Core | Create files or fetch from URLs |
create_drive_folder | Core | Create empty folders in Drive or shared drives |
import_to_google_doc | Core | Import files (MD, DOCX, HTML, etc.) as Google Docs |
get_drive_shareable_link | Core | Get shareable links for a file |
list_drive_items | Extended | List folder contents |
copy_drive_file | Extended | Copy existing files (templates) with optional renaming |
update_drive_file | Extended | Update file metadata, move between folders |
manage_drive_access | Extended | Grant, update, revoke permissions, and transfer ownership |
set_drive_file_permissions | Extended | Set link sharing and file-level sharing settings |
get_drive_file_permissions | Complete | Get detailed file permissions |
check_drive_file_public_access | Complete | Check public sharing status |
copy_drive_folder | Complete | Recursively copy a folder tree (folders + files) to a new location |
get_drive_revisions | Complete | List a file's revision history (modified time, user, size) |
restore_drive_revision | Complete | Restore a binary file to a prior revision (native Docs/Sheets/Slides not supported — use Docs UI) |
gmail_tools.py| Tool | Tier | Description |
|---|---|---|
search_gmail_messages | Core | Search with Gmail operators |
get_gmail_message_content | Core | Retrieve message content |
get_gmail_messages_content_batch | Core | Batch retrieve message content |
send_gmail_message | Core | Send emails |
get_gmail_thread_content | Extended | Get full thread content |
modify_gmail_message_labels | Extended | Modify message labels |
list_gmail_labels | Extended | List available labels |
list_gmail_filters | Extended | List Gmail filters |
manage_gmail_label | Extended | Create/update/delete labels |
manage_gmail_filter | Extended | Create or delete Gmail filters |
draft_gmail_message | Extended | Create drafts |
get_gmail_threads_content_batch | Complete | Batch retrieve thread content |
batch_modify_gmail_message_labels | Complete | Batch modify labels |
start_google_auth | Complete | Legacy OAuth 2.0 auth (disabled when OAuth 2.1 is enabled) |
Both send_gmail_message and draft_gmail_message support attachments via two methods:
Option 1: File Path (local server only)
Reads file from disk, auto-detects MIME type. Optional filename override.
Option 2: Base64 Content (works everywhere)
⚠️ Centrally Hosted Servers: When the MCP server runs remotely (cloud, shared instance), it cannot access your local filesystem. Use Option 2 with base64-encoded content. Your MCP client must encode files before sending.
When downloading Gmail attachments (get_gmail_attachment_content) or Drive files (get_drive_file_download_url), files are saved to a persistent local directory rather than a temporary folder in the working directory.
Default location: ~/.workspace-mcp/attachments/
Files are saved with their original filename plus a short UUID suffix for uniqueness (e.g., invoice_a1b2c3d4.pdf). In stdio mode, the tool returns the absolute file path for direct filesystem access. In HTTP mode, it returns a download URL via the /attachments/{file_id} endpoint.
To customize the storage directory:
Saved files expire after 1 hour and are cleaned up automatically.
docs_tools.py| Tool | Tier | Description |
|---|---|---|
get_doc_content | Core | Extract document text |
create_doc | Core | Create new documents (set format_as_markdown=True to render markdown content natively) |
modify_doc_text | Core | Insert, replace, and richly format text with tab/segment targeting, append-to-segment support, advanced typography, link management, and native markdown rendering (format_as_markdown=True) |
search_docs | Extended | Find documents by name |
find_and_replace_doc | Extended | Find and replace text |
list_docs_in_folder | Extended | List docs in folder |
insert_doc_elements | Extended | Add tables, lists, page breaks |
update_paragraph_style | Extended | Apply advanced paragraph styling including headings, spacing, direction, pagination controls, shading, and bulleted/numbered/checkbox lists with nesting |
get_doc_as_markdown | Extended | Export document as formatted Markdown with optional comments |
insert_doc_markdown | Extended | Insert markdown content with native Docs formatting (headings, bold/italic, bullets, numbered lists); supports tab/segment targeting and end-of-segment append |
insert_doc_link | Extended | Insert clickable linked text at a specified index (tab-aware) |
list_doc_tabs | Extended | List all tabs (and nested child tabs) with tab IDs, titles, indices, and nesting depth |
insert_doc_image | Complete | Insert images from Drive/URLs |
update_doc_headers_footers | Complete | Create or update headers and footers with correct segment-aware writes |
batch_update_doc | Complete | Execute atomic multi-step Docs API operations including named ranges, section breaks, document/section layout, header/footer creation, segment-aware inserts, images, tables, and rich formatting |
inspect_doc_structure | Complete | Analyze document structure, including safe insertion points, tables, section breaks, headers/footers, and named ranges |
export_doc_to_pdf | Extended | Export document to PDF |
create_table_with_data | Complete | Create data tables |
debug_table_structure | Complete | Debug table issues |
list_document_comments | Complete | List all document comments |
manage_document_comment | Complete | Create, reply to, or resolve comments |
insert_doc_person_chip | Complete | Insert an @mention person smart chip by email |
insert_doc_file_chip | Complete | Insert a Drive file smart chip from its URL |
get_doc_smart_chips | Complete | Extract all person and rich-link smart chips from the document |
sheets_tools.py| Tool | Tier | Description |
|---|---|---|
read_sheet_values | Core | Read cell ranges |
modify_sheet_values | Core | Write/update/clear cells |
create_spreadsheet | Core | Create new spreadsheets |
list_spreadsheets | Extended | List accessible spreadsheets |
get_spreadsheet_info | Extended | Get spreadsheet metadata |
format_sheet_range | Extended | Apply colors, number formats, text wrapping, alignment, bold/italic, font size |
list_sheet_tables | Extended | List structured tables with IDs, names, ranges, and columns |
create_sheet | Complete | Add sheets to existing files |
append_table_rows | Complete | Append rows to a structured table, auto-extending the table range |
list_spreadsheet_comments | Complete | List all spreadsheet comments |
manage_spreadsheet_comment | Complete | Create, reply to, or resolve comments |
manage_conditional_formatting | Complete | Add, update, or delete conditional formatting rules |
add_sheet_data_validation | Complete | Add dropdowns, number bounds, date/text rules, or custom-formula validation to a range |
add_sheet_named_range | Complete | Create a named range that can be referenced by formulas |
protect_sheet_range | Complete | Protect a range with optional editor whitelist and warning-only mode |
manage_sheet_tabs | Complete | Rename, delete, or duplicate sheet tabs (single action-based tool) |
slides_tools.py| Tool | Tier | Description |
|---|---|---|
create_presentation | Core | Create new presentations |
get_presentation | Core | Retrieve presentation details |
batch_update_presentation | Extended | Apply multiple updates |
get_page | Extended | Get specific slide information |
get_page_thumbnail | Extended | Generate slide thumbnails |
format_slides_text | Extended | Apply text formatting (bold/italic/underline/strikethrough/color/font/size) to a slide element |
format_all_slides_text | Extended | Apply text formatting to EVERY text element on a slide, or across the whole presentation in one call |
format_slides_paragraph | Extended | Apply paragraph alignment, line spacing, spacing above/below, and bullet presets |
style_slides_shape | Extended | Style a shape's fill color, outline color/weight, and dash style |
set_slides_background | Extended | Set the background color of a slide |
create_slides_text_box | Extended | Create a positioned text box with initial text and optional formatting |
create_slides_shape | Extended | Create a positioned shape (rectangle, ellipse, triangle, star, arrow, etc.) |
get_slides_speaker_notes | Extended | Read speaker notes from a slide |
update_slides_speaker_notes | Extended | Replace speaker notes on a slide |
insert_slides_image | Extended | Insert an image onto a slide from a public URL |
delete_slides_element | Extended | Delete a slide or any page element by object ID |
replace_slides_text | Extended | Find and replace text across an entire presentation |
duplicate_slide | Extended | Duplicate a slide (or any object) and return the new object ID |
reorder_slides | Extended | Move one or more slides to a new position |
list_presentation_comments | Complete | List all presentation comments |
manage_presentation_comment | Complete | Create, reply to, or resolve comments |
forms_tools.py| Tool | Tier | Description |
|---|---|---|
create_form | Core | Create new forms |
get_form | Core | Retrieve form details & URLs |
set_publish_settings | Complete | Configure form settings |
get_form_response | Complete | Get individual responses |
list_form_responses | Extended | List all responses with pagination |
batch_update_form | Complete | Apply batch updates (questions, settings) |
tasks_tools.py| Tool | Tier | Description |
|---|---|---|
list_tasks | Core | List tasks with filtering |
get_task | Core | Retrieve task details |
manage_task | Core | Create, update, delete, or move tasks |
list_task_lists | Complete | List task lists |
get_task_list | Complete | Get task list details |
manage_task_list | Complete | Create, update, delete task lists, or clear completed tasks |
contacts_tools.py| Tool | Tier | Description |
|---|---|---|
search_contacts | Core | Search contacts by name, email, phone |
get_contact | Core | Retrieve detailed contact info |
list_contacts | Core | List contacts with pagination |
manage_contact | Core | Create, update, or delete contacts |
list_contact_groups | Extended | List contact groups/labels |
get_contact_group | Extended | Get group details with members |
manage_contacts_batch | Complete | Batch create, update, or delete contacts |
manage_contact_group | Complete | Create, update, delete groups, or modify membership |
chat_tools.py| Tool | Tier | Description |
|---|---|---|
list_spaces | Extended | List chat spaces/rooms |
get_messages | Core | Retrieve space messages |
send_message | Core | Send messages to spaces |
search_messages | Core | Search across chat history |
create_reaction | Core | Add emoji reaction to a message |
download_chat_attachment | Extended | Download attachment from a chat message |
search_tools.py| Tool | Tier | Description |
|---|---|---|
search_custom | Core | Perform web searches (supports site restrictions via sites parameter) |
get_search_engine_info | Complete | Retrieve search engine metadata |
apps_script_tools.py| Tool | Tier | Description |
|---|---|---|
list_script_projects | Core | List accessible Apps Script projects |
get_script_project | Core | Get complete project with all files |
get_script_content | Core | Retrieve specific file content |
create_script_project | Core | Create new standalone or bound project |
update_script_content | Core | Update or create script files |
run_script_function | Core | Execute function with parameters |
list_deployments | Extended | List all project deployments |
manage_deployment | Extended | Create, update, or delete script deployments |
list_script_processes | Extended | View recent executions and status |
Tool Tier Legend:
● Core — Essential tools for basic functionality · Minimal API usage · Getting started
● Extended — Core + additional features · Regular usage · Expanded capabilities
● Complete — All available tools including advanced features · Power users · Full API access
The server supports two transport modes:
⚠️ Important: Stdio mode is a legacy fallback for clients that don't properly implement the MCP specification with OAuth 2.1 and streamable HTTP support. Claude Code and other modern MCP clients should use streamable HTTP mode (
--transport streamable-http) for proper OAuth flow and multi-user support.
In general, you should use the one-click DXT installer package for Claude Desktop.
If you are unable to for some reason, you can configure it manually via claude_desktop_config.json
Manual Claude Configuration (Alternative)
Open Claude Desktop Settings → Developer → Edit Config
~/Library/Application Support/Claude/claude_desktop_config.json%APPDATA%\Claude\claude_desktop_config.jsonAdd the server configuration:
Add a new MCP server in LM Studio (Settings → MCP Servers) using the same JSON format:
If you’re developing, deploying to servers, or using another MCP-capable client, keep reading.
Note: Configure OAuth credentials before running. Supports environment variables,
.envfile, orclient_secret.json.
uv sync --group test installs only the testing stack if you need a slimmer environment.uv run main.py --transport streamable-http launches the server with your checked-out code for manual verification.dev group because pre-push hooks call ruff check automatically—run it locally before committing to avoid hook failures.The server includes OAuth 2.1 support for bearer token authentication, enabling multi-user session management. OAuth 2.1 automatically reuses your existing GOOGLE_OAUTH_CLIENT_ID and, for confidential clients, GOOGLE_OAUTH_CLIENT_SECRET credentials - no additional Google-side configuration needed. Public PKCE clients are also supported: if you omit GOOGLE_OAUTH_CLIENT_SECRET, set FASTMCP_SERVER_AUTH_GOOGLE_JWT_SIGNING_KEY explicitly.
When to use OAuth 2.1:
⚠️ Important: Mutually exclusive authentication modes
OAuth 2.1 mode (MCP_ENABLE_OAUTH21=true) cannot be used together with --single-user or service account mode:
Choose one authentication method - combining incompatible modes will result in a startup error.
Enabling OAuth 2.1:
To enable OAuth 2.1, set the MCP_ENABLE_OAUTH21 environment variable to true.
If MCP_ENABLE_OAUTH21 is not set to true, the server will use legacy authentication, which is suitable for clients that do not support OAuth 2.1.
FastMCP ships a native GoogleProvider that we now rely on directly. It solves the two tricky parts of using Google OAuth with MCP clients:
Dynamic Client Registration: Google still doesn't support OAuth 2.1 DCR, but the FastMCP provider exposes the full DCR surface and forwards registrations to Google using your fixed credentials. MCP clients register as usual and the provider hands them your Google client ID and, when configured, client secret under the hood.
CORS & Browser Compatibility: The provider includes an OAuth proxy that serves all discovery, authorization, and token endpoints with proper CORS headers. We no longer maintain custom /oauth2/* routes—the provider handles the upstream exchanges securely and advertises the correct metadata to clients.
The result is a leaner server that still enables any OAuth 2.1 compliant client (including browser-based ones) to authenticate through Google without bespoke code.
The server supports a stateless mode designed for containerized environments where file system writes should be avoided:
Enabling Stateless Mode:
Key Features:
Requirements:
MCP_ENABLE_OAUTH21=trueThis mode is ideal for:
MCP Inspector: No additional configuration needed with desktop OAuth client.
Claude Code: No additional configuration needed with desktop OAuth client.
The server supports pluggable storage backends for OAuth proxy state management via FastMCP 2.13.0+. Choose a backend based on your deployment needs.
Available Backends:
| Backend | Best For | Persistence | Multi-Server |
|---|---|---|---|
| Memory | Development, testing | ❌ | ❌ |
| Disk | Single-server production | ✅ | ❌ |
| Valkey/Redis | Distributed production | ✅ | ✅ |
Configuration:
Disk support requires
workspace-mcp[disk](orpy-key-value-aio[disk]) when installing from source. The official Docker image includes thediskextra by default. Valkey support is optional. Installworkspace-mcp[valkey](orpy-key-value-aio[valkey]) only if you enable the Valkey backend. Windows: buildingvalkey-glidefrom source requires MSVC C++ build tools with C11 support. If you seeaws-lc-sysC11 errors, setCFLAGS=/std:c11.
| Variable | Default | Description |
|---|---|---|
WORKSPACE_MCP_OAUTH_PROXY_VALKEY_HOST | localhost | Valkey/Redis host |
WORKSPACE_MCP_OAUTH_PROXY_VALKEY_PORT | 6379 | Port (6380 auto-enables TLS) |
WORKSPACE_MCP_OAUTH_PROXY_VALKEY_DB | 0 | Database number |
WORKSPACE_MCP_OAUTH_PROXY_VALKEY_USE_TLS | auto | Enable TLS (auto if port 6380) |
WORKSPACE_MCP_OAUTH_PROXY_VALKEY_USERNAME | - | Authentication username |
WORKSPACE_MCP_OAUTH_PROXY_VALKEY_PASSWORD | - | Authentication password |
WORKSPACE_MCP_OAUTH_PROXY_VALKEY_REQUEST_TIMEOUT_MS | 5000 | Request timeout for remote hosts |
WORKSPACE_MCP_OAUTH_PROXY_VALKEY_CONNECTION_TIMEOUT_MS | 10000 | Connection timeout for remote hosts |
Encryption: Disk and Valkey storage are encrypted with Fernet. The encryption key is derived from FASTMCP_SERVER_AUTH_GOOGLE_JWT_SIGNING_KEY if set, otherwise from GOOGLE_OAUTH_CLIENT_SECRET. Public OAuth 2.1 client setups without a client secret must set FASTMCP_SERVER_AUTH_GOOGLE_JWT_SIGNING_KEY.
The server supports an external OAuth 2.1 provider mode for scenarios where authentication is handled by an external system. In this mode, the MCP server does not manage the OAuth flow itself but expects valid bearer tokens in the Authorization header of tool calls.
Enabling External OAuth 2.1 Provider Mode:
How It Works:
initialize and tools/list) require a valid Bearer token, following the standard OAuth 2.1 flow. Unauthenticated requests receive a 401 with resource metadata pointing to Google's authorization server.ya29.*)/.well-known/oauth-protected-resource (RFC 9728) advertising Google as the authorization server and the required scopesKey Features:
/authorize, /token, or /register endpoints — only resource metadataAuthorization: Bearer <token> headersWORKSPACE_MCP_STATELESS_MODE=trueRequirements:
MCP_ENABLE_OAUTH21=trueGOOGLE_OAUTH_CLIENT_ID, optional GOOGLE_OAUTH_CLIENT_SECRET)Use Cases:
WARNING: This mode uses Google Workspace domain-wide delegation, which grants the service account the ability to impersonate any user in your domain for the configured scopes. This is powerful and dangerous — do not use this unless you fully understand the security implications. A misconfigured service account with broad scopes can read, modify, and delete data across every user in your organization. Only use this in tightly controlled environments where you know exactly what you're doing.
Service account mode allows the server to authenticate using a Google Cloud service account with domain-wide delegation instead of interactive OAuth flows. The service account impersonates a single configured domain user for all API calls.
When to use service account mode:
Enabling Service Account Mode:
Prerequisites:
USER_GOOGLE_EMAIL set to the domain user the service account will impersonateIncompatibilities:
--single-user modeMCP_ENABLE_OAUTH21=trueGOOGLE_SERVICE_ACCOUNT_KEY_FILE or GOOGLE_SERVICE_ACCOUNT_KEY_JSON, not bothKey Behaviors:
USER_GOOGLE_EMAIL — any email addresses supplied in tool calls (e.g., user_email parameters) are ignored. This differs from OAuth modes where each user authenticates separately.✅ Recommended: VS Code MCP extension properly supports the full MCP specification. Always use HTTP transport mode for proper OAuth 2.1 authentication.
Note: Make sure to start the server with --transport streamable-http when using VS Code MCP.
✅ Recommended: Claude Code is a modern MCP client that properly supports the full MCP specification. Always use HTTP transport mode with Claude Code for proper OAuth 2.1 authentication and multi-user support.
Or copy skills/managing-google-workspace into ~/.claude/skills/managing-google-workspace if you prefer not to symlink it.
If you're running the MCP server behind a reverse proxy (nginx, Apache, Cloudflare, etc.), you have two configuration options:
Problem: When behind a reverse proxy, the server constructs OAuth URLs using internal ports (e.g., http://localhost:8000) but external clients need the public URL (e.g., https://your-domain.com).
Solution 1: Set WORKSPACE_EXTERNAL_URL for all OAuth endpoints:
Solution 2: Set GOOGLE_OAUTH_REDIRECT_URI for just the callback:
You also have options for:
| OAUTH_CUSTOM_REDIRECT_URIS (optional) | Comma-separated list of additional redirect URIs |
| OAUTH_ALLOWED_ORIGINS (optional) | Comma-separated list of additional CORS origins |
Important:
WORKSPACE_EXTERNAL_URL when all OAuth endpoints should use the external URL (recommended for reverse proxy setups)GOOGLE_OAUTH_REDIRECT_URI when you only need to override the callback URL/oauth2callback, /oauth2/*, /.well-known/*) to the MCP serverRequires Python 3.10+ and uvx. The package is available on PyPI.
For development or customization:
Development Installation (For Contributors):
If you need to use HTTP mode with Claude Desktop:
Note: Make sure to start the server with --transport streamable-http when using HTTP mode.
The server uses Google Desktop OAuth for simplified authentication:
When calling a tool:
VE-GWS tracks taylorwilsdon/google_workspace_mcp as an upstream remote so improvements from the original project can be merged in periodically.
Because VE-GWS adds 25 tools and modifies gslides/slides_tools.py, gdocs/docs_tools.py, gsheets/sheets_tools.py, gdrive/drive_tools.py, and core/tool_tiers.yaml, merges will occasionally produce conflicts in those files. Resolve by keeping both sides' changes and re-running the test suite (uv run pytest tests/) before pushing.
SCOPE_GROUPS for easy maintenance@require_multiple_services() for complex toolsThe server includes an abstract credential store API and a default backend for managing Google OAuth credentials with support for multiple storage backends:
Features:
CredentialStore base class defines standard operations (get, store, delete, list users)LocalDirectoryCredentialStore implementation stores credentials as JSON filesGOOGLE_MCP_CREDENTIALS_DIR sets storage locationConfiguration:
Usage Example:
The credential store automatically handles credential serialization, expiry parsing, and provides error handling for storage operations.
.env, client_secret.json or the .credentials/ directory to source control!http://localhost:8000/oauth2callback for development (requires OAUTHLIB_INSECURE_TRANSPORT=1)file:// uploads) are restricted to the user's home directory by default. Override this with the ALLOWED_FILE_DIRS environment variable:
Regardless of the allowlist, access to sensitive paths (.env, .ssh/, .aws/, /etc/shadow, credential files, etc.) is always blocked.MIT License - see LICENSE file for details.