Google Workspace MCP Server & CLI
A free, open source Google Workspace MCP server and CLI that lets Claude Code, Codex, Cursor and other AI agents work across Gmail, Drive, Sheets, Docs, Calendar and more.
This free Google Workspace MCP server and CLI gives your AI real access to Gmail, Drive, Sheets, Docs, Slides, Calendar, Tasks, Forms and Contacts. It works through Google's own Workspace CLI, so your credential is created by you and never leaves your computer.
It's one install with 2 ways in. Claude, Codex, Cursor or any other MCP app calls its 38 tools for you, and the same tools work as a CLI that agents like Claude Code, Codex and OpenCode run, or that you type yourself.
Here's what the Google Workspace MCP server and CLI is, how to set it up in each app, and every tool it has.
What is the Google Workspace MCP server & CLI?
The Google Workspace MCP server & CLI is a free, open source program that lets AI agents work across Gmail, Drive, Sheets, Docs, Calendar and the rest of Google Workspace for you, in 2 ways. The MCP server is what an AI app like Claude, Codex or Cursor connects to, through MCP (Model Context Protocol), the open standard AI apps use to call outside tools.
You ask in plain language. Your AI picks the right tool, and the server makes the call through Google's official Workspace CLI, gws.
The CLI is the same program as commands. google-workspace-cli calendar-list-events runs the same code your AI runs when you ask what's on your calendar, whether an agent like Claude Code runs it or you do.
What can you ask it?
Once it's set up, you ask the way you'd ask an assistant. These are real prompts it handles:
Try askingWhat did I agree to with the agency, and is it in the calendar?
Summarize every unread email from this week and tell me which need a reply.
Draft replies to the three that matter. Don't send them.
Find the pricing spreadsheet and tell me what changed since March.
Pull every response to the onboarding form into a new sheet.
What's on my calendar next week that I could move?
The first one shows why this is useful. It reads your mail and your calendar together, which no single Google product does for you.
How to install the Google Workspace MCP server
Pick your app in the box at the top of this page. Each one is a single command or a pasted block, after you install Google's Workspace CLI and sign in to it once.
Pro tip: Your Google credential belongs to gws, not to this server. That also sidesteps the security review a third-party app needs for mailbox and Drive access.
Set up Google Workspace
The server talks to Google through gws, Google's own Workspace CLI, so the only setup is installing it and signing in once.
brew install googleworkspace/tap/gws. Other systems download a binary from its releases.gws auth login.To limit what it can touch, sign in with gws auth login --services drive,gmail,calendar, or gws auth login --readonly.
Google shows an "unverified app" warning for any app it hasn't reviewed. Click Advanced, then Go to your app. If you'd rather not see it, gws auth setup walks you through a Google Cloud project of your own.
Check that it works
Run the doctor. It checks that gws is installed and signed in, and makes a live Drive call.
npx -y @thenavidm/google-workspace-mcp-cli doctor"Not authenticated" means run gws auth login on the computer running the server.
Use the Google Workspace CLI
The CLI is the same 38 tools as commands. AI agents that run commands, like Claude Code, Codex and OpenCode, use it on their own, and you can type the same commands in a terminal or a script.
Every tool name becomes a command with dashes, so gmail_search runs as google-workspace-cli gmail-search.
npm install -g @thenavidm/google-workspace-mcp-cli
google-workspace-cli
google-workspace-cli gmail-search --q "is:unread newer_than:2d" --max 5
google-workspace-cli calendar-list-events
google-workspace-cli drive-search --q "name contains 'invoice'"The bare google-workspace-cli lists every command, and google-workspace-cli <command> --help shows what a command takes. Sending a draft, trashing a file, deleting an event and the raw API tool ask for --confirm first, like they do for your AI.
These flags work on every command:
| Flag | What it does |
|---|---|
--json | Prints JSON |
--compact | Prints the JSON on one line |
--agent | Machine mode: JSON, compact, no prompts and no color |
--select a,b.c | Keeps only those fields, and a dotted path goes deeper |
--confirm | Lets a write that asks first go ahead |
A script can branch on the exit code:
| Exit code | What it means |
|---|---|
| 0 | It worked |
| 2 | The command was typed wrong, or a write needed --confirm |
| 3 | It wasn't found |
| 4 | Google Workspace rejected the credentials |
| 5 | Google Workspace's API failed |
| 7 | You hit a rate limit, so wait and try again |
| 10 | Nothing is set up yet |
MCP server or CLI: which one?
Both are the same program with the same 38 tools. The difference is when your AI pays for them, in the tokens it reads.
- MCP server
- 6,700 tokens
- CLI
- Nothing
- MCP server
- 810 tokens
- CLI
- Nothing
- MCP server
- Nothing more, or in Claude Code the tools it picks
- CLI
- 1,800 tokens, once
- MCP server
- 134,000 tokens
- CLI
- 1,800 tokens
- MCP server
- Yes
- CLI
- No, there's no terminal there
- MCP server
- No
- CLI
- Yes
An app that loads every tool up front sends the full list with every message, whether you mention Google Workspace or not. Claude Code doesn't by default: its tool search sends only the tool names and the server's instructions, and loads a tool's full definition when your AI reaches for it.
The CLI costs nothing until Google Workspace comes up. Then your agent reads its skill file once and runs the commands it needs. With the skill added, Claude Code also lists its one-line description with every message, about 140 tokens.
When the whole conversation is about Google Workspace, the gap closes. Then the MCP server is the better experience, because you ask in plain language and your AI never has to look up a command.
How to spend less
In Claude Code, leave tool search on, which it is unless you've set ENABLE_TOOL_SEARCH=false.
Turn the server off when you aren't using it, with your AI app's own switch. GWS_SERVICES=gmail,calendar registers only the services you name, and the rest cost nothing.
Or install the CLI and connect the server later, on the days it earns its place. Every tool stays in reach, and the standing cost drops to nothing.
Every number here was measured on September 27, 2026 in Claude Code 2.1.257 with Claude Opus 5. It's the same one-line prompt with and without the server connected, once with tool search off so every tool loads, and once with Claude Code's default. The skill was measured the same way, and other apps and models count tokens a little differently.
Email is drafted, not sent
gmail_create_draft writes to your Drafts folder and stops, so you can read it before anything goes out. Sending is a separate tool, gmail_send_draft, and it asks for a confirm check first, because a sent email can't be recalled.
Nothing is deleted for good either. drive_trash moves a file to the trash, where it stays recoverable for 30 days, and there is no hard delete.
Reach anything else
The named tools cover what people ask for most. workspace_raw reaches the roughly 400 other Workspace API methods, and workspace_schema shows the exact fields one of them takes, so your AI never has to guess them.
Every Google Workspace tool
All 38 tools, grouped the way the repo groups them. 20 only read, and 18 change something in your Google account.
Gmail
gmail_search- What it does
- Search the mailbox with Gmail's own query syntax (from:, to:, subject:, has:attachment, newer_than:7d, is:unread).
- Kind
- Reads
gmail_get_message- What it does
- One message in full, including the body and headers.
- Kind
- Reads
gmail_get_thread- What it does
- A whole conversation in order.
- Kind
- Reads
gmail_create_draft- What it does
- Write a draft.
- Kind
- Writes
gmail_send_draft- What it does
- Send a draft that already exists.
- Kind
- Asks first
gmail_modify_labels- What it does
- Add or remove labels on a message.
- Kind
- Writes
gmail_list_labels- What it does
- Every label with its id.
- Kind
- Reads
Calendar
calendar_list_events- What it does
- Events in a window.
- Kind
- Reads
calendar_create_event- What it does
- Create an event.
- Kind
- Writes
calendar_update_event- What it does
- Change an existing event.
- Kind
- Writes
calendar_delete_event- What it does
- Delete an event.
- Kind
- Asks first
calendar_list_calendars- What it does
- Every calendar this account can see, with its id.
- Kind
- Reads
Drive
drive_search- What it does
- Find files with Drive query syntax (name contains 'x', mimeType='application/pdf', modifiedTime > '2026-01-01').
- Kind
- Reads
drive_get_file- What it does
- Metadata for one file: name, type, size, owners, sharing and link.
- Kind
- Reads
drive_export- What it does
- Read the CONTENT of a Google Doc, Sheet or Slide as text.
- Kind
- Reads
drive_create_folder- What it does
- Create a folder, optionally inside another.
- Kind
- Writes
drive_share- What it does
- Grant someone access to a file.
- Kind
- Writes
drive_trash- What it does
- Move a file to the trash.
- Kind
- Asks first
Sheets
sheets_read- What it does
- Read a cell range, e.g.
- Kind
- Reads
sheets_write- What it does
- Overwrite a range with new values.
- Kind
- Writes
sheets_append- What it does
- Add rows to the end of a sheet without touching what is there.
- Kind
- Writes
sheets_get- What it does
- Spreadsheet structure: every sheet name, id, and dimensions.
- Kind
- Reads
sheets_create- What it does
- Create a new spreadsheet and return its id.
- Kind
- Writes
Docs
docs_get- What it does
- Read a Google Doc's full structured content.
- Kind
- Reads
docs_create- What it does
- Create a new Google Doc with a title, and optionally an opening body of text.
- Kind
- Writes
docs_append- What it does
- Add text to the end of a Doc without touching what is already there.
- Kind
- Writes
Slides
slides_get- What it does
- A presentation's structure and the text on every slide.
- Kind
- Reads
slides_create- What it does
- Create an empty presentation and return its id.
- Kind
- Writes
Tasks
tasks_lists- What it does
- Every task list with its id.
- Kind
- Reads
tasks_list- What it does
- Tasks in a list.
- Kind
- Reads
tasks_create- What it does
- Add a task.
- Kind
- Writes
tasks_complete- What it does
- Mark a task done.
- Kind
- Writes
Forms
forms_get- What it does
- A form's questions and settings.
- Kind
- Reads
forms_responses- What it does
- Every response to a form.
- Kind
- Reads
Contacts
contacts_search- What it does
- Search your own contacts by name, email or company.
- Kind
- Reads
contacts_list- What it does
- All your contacts, paged.
- Kind
- Reads
Everything else
workspace_raw- What it does
- Call any Google Workspace API method the curated tools do not cover.
- Kind
- Asks first
workspace_schema- What it does
- The exact parameters and request body a method expects, straight from Google's discovery service.
- Kind
- Reads
Is the Google Workspace MCP server safe?
Writes work from the start, because drafting, filing and scheduling are the point of the tool. The ones that can't be undone ask first.
gmail_send_draft, drive_trash, calendar_delete_event and workspace_raw ask for a confirm check first, marked Asks first in the tool tables above.
Make it read-only
Set GWS_READ_ONLY=1 and every write is refused. GWS_SERVICES=drive,calendar goes further: the other services aren't even registered, so your AI can't reach for them.
Watch out: Anything read from a mailbox or a shared document was written by someone else and can contain text shaped like an instruction. The server tells your AI to treat it as data, but for an agent working on its own, GWS_READ_ONLY=1 is the real defense.
Your data
There's no server of ours in between. Your Google data goes from Google to your computer, and from there to the AI app you connected.
Your credential stays with gws, and this server never sees or stores it. Whatever your AI reads, it sends to its own model provider, the same as anything you paste into a chat.
Google Workspace MCP server settings
Every setting is an environment variable in your app's config. None of them are required.
GWS_BIN- Default
gwson your PATH- What it does
- Points at the gws binary, when your app can't find it
GWS_READ_ONLY- Default
- off
- What it does
1refuses every write
GWS_SERVICES- Default
- all
- What it does
- Registers only these services, for example
drive,gmail,calendar
GWS_MCP_TOKEN- Default
- none
- What it does
- Sets the bearer token, which
--httprequires
Troubleshooting
Run the doctor first. It names the step that failed and the fix.
| What you see | What to do |
|---|---|
| "The gws CLI was not found" | Install it, or set GWS_BIN to its full path |
| "Not authenticated" | Run gws auth login on the computer running the server |
| It works in a terminal, not in Claude Desktop | Claude Desktop doesn't read your shell's PATH, so use full paths |
| An "unverified app" warning | That's expected. Click Advanced, then Go to your app |
| A tool says its service is disabled | GWS_SERVICES is set and leaves that service out |
If the server doesn't show up in your app at all, run the command your app runs, in a terminal, and read the error.
More free tools for your work
Turn a doc into a presentation, or make a QR code for a meeting link.
Google Workspace MCP Server FAQs
Here are the questions people ask most about the Google Workspace MCP server and CLI.
The Google Workspace MCP server & CLI is a free, open source program that lets an AI app like Claude, Codex or Cursor work across Gmail, Drive, Sheets, Docs, Calendar and the rest of Google Workspace.
It has 38 tools for Gmail, Drive, Sheets, Docs, Slides, Calendar, Tasks, Forms and Contacts, and the same tools run as a CLI that agents like Claude Code and Codex use, or that you type yourself.
An MCP server is a standard way to give an AI app real access to a tool, so it can act instead of guessing.
MCP stands for Model Context Protocol, and Claude, Codex, Cursor and many other AI apps speak it.
The Google Workspace CLI is the same program as the Google Workspace MCP server, run as commands.
AI agents like Claude Code, Codex and OpenCode run them for you, and you can type them in a terminal or a script.
Use the Google Workspace MCP server in an AI app with no terminal, like Claude Desktop's chat, and the CLI in a terminal, a script or a cron job.
In an AI app that can run commands, like Claude Code, Codex or Cursor, the CLI is the lighter choice, because it costs nothing until it runs.
Yes, the Google Workspace MCP server is free and open source under the MIT license, Google's Workspace CLI is free, and the Workspace APIs cost nothing at the volume a person uses.
The only thing you pay for is your own AI app.
No, the Google Workspace MCP server drafts email and stops.
Sending is a separate tool that asks for a confirm check first, because a sent email can't be recalled.
No, your credential belongs to Google's Workspace CLI, and the server never sees or stores it.
Signing in happens in your own browser.
Yes, run a second copy with GOOGLE_WORKSPACE_CLI_CONFIG_DIR pointing at another folder.
Add it to your app under a different name.
No, drive_trash moves a file to the trash, where it stays recoverable for 30 days, and there is no hard delete.
Trashing asks for a confirm check first.
The Google Workspace MCP server works with any app that speaks MCP.
That includes Claude Code, Claude Desktop, Codex, Cursor, VS Code, GitHub Copilot CLI, Gemini CLI, OpenCode, OpenClaw, Antigravity and Hermes.
Navid.me is reader-supported. When you buy through links on this site, I may earn an affiliate commission. Learn more.
More MCP servers & CLIs
The most actionable AI newsletter for founders
Every week, get proven AI strategies, curated tools, and step-by-step systems to grow your audience, create better content, and build a profitable creator business.
No fluff, no filler, no BS. Just five minutes each week that might level up your online business and life.
P.S. Sign up now to get free access to my ultimate AI tools guide for creators.


