Google Docs, Sheets, Drive, Gmail & Calendar MCP Server


Connect Claude Desktop, Cursor, or any MCP client to your Google Docs, Google Sheets, Google Drive, Gmail, and Google Calendar.
Quick Start
1. Create a Google Cloud OAuth Client
- Go to the Google Cloud Console
- Create or select a project
- Enable the Google Docs API, Google Sheets API, Google Drive API, Gmail API, and Google Calendar API
- Configure the OAuth consent screen (External, add your email as a test user, and add the
gmail.modify and calendar.events scopes alongside the Docs/Sheets/Drive scopes)
- Create an OAuth client ID (Desktop app type)
- Copy the Client ID and Client Secret from the confirmation screen
Need more detail? See step-by-step instructions at the bottom of this page.
2. Authorize
GOOGLE_CLIENT_ID="your-client-id" \
GOOGLE_CLIENT_SECRET="your-client-secret" \
npx -y @a-bonus/google-docs-mcp auth
This opens your browser for Google authorization. After you approve, the refresh token is saved to ~/.config/google-docs-mcp/token.json.
3. Add to Your MCP Client
Claude Desktop / Cursor / Windsurf:
{
"mcpServers": {
"google-docs": {
"command": "npx",
"args": ["-y", "@a-bonus/google-docs-mcp"],
"env": {
"GOOGLE_CLIENT_ID": "your-client-id",
"GOOGLE_CLIENT_SECRET": "your-client-secret"
}
}
}
}
The server starts automatically when your MCP client needs it.
Remote Deployment (Cloud Run)
Deploy once for your team -- no local installs required. The server uses MCP OAuth 2.1 so your MCP client handles authentication automatically.
gcloud run deploy google-docs-mcp \
--source . \
--region europe-west3 \
--port 8080 \
--allow-unauthenticated \
--set-env-vars "^|^MCP_TRANSPORT=httpStream|BASE_URL=https://your-service.run.app|GOOGLE_CLIENT_ID=...|GOOGLE_CLIENT_SECRET=...|TOKEN_STORE=firestore|JWT_SIGNING_KEY=your-secret-key"
Then each user just adds the URL to their MCP client -- no npx, no tokens, no local setup:
{
"mcpServers": {
"google-docs": {
"type": "streamableHttp",
"url": "https://your-service.run.app/mcp"
}
}
}
Your MCP client will prompt for Google sign-in on first connection. See Remote Deployment for details.
What Can It Do?
Tools across Google Docs, Sheets, and Drive:
Google Docs
Google Sheets
Google Sheets Tables
Google Drive
Gmail
Google Calendar
Apps Script
Automate the automation: create and edit the Apps Script behind a Doc or Sheet — onEdit triggers, custom menus, scheduled jobs — instead of telling the user to paste code into the editor by hand.
Requires two things beyond the usual setup:
- The Apps Script API must be enabled per Google account at https://script.google.com/home/usersettings — it is off by default, and a 403 with "Apps Script API" in the message means this step was missed.
- The
script.projects scope, which is included in SCOPES. Existing installs must re-authorize once to pick it up.
Usage Examples
Google Docs
"Read document ABC123 as markdown"
"Append 'Meeting notes for today' to document ABC123"
"Make the text 'Important' bold and red in document ABC123"
"Replace the entire document with this markdown: # Title\n\nNew content here"
"Insert a 3x4 table at index 50 in document ABC123"
Google Sheets
"Read range A1:D10 from spreadsheet XYZ789"
"Write [[Name, Score], [Alice, 95], [Bob, 87]] to range A1 in spreadsheet XYZ789"
"Create a new spreadsheet titled 'Q1 Report'"
"Format row 1 as bold with a light blue background in spreadsheet XYZ789"
"Freeze the first row in spreadsheet XYZ789"
"Add a dropdown with options [Open, In Progress, Done] to range C2:C100"
"Create a table named 'Tasks' in range A1:D10 with columns: Task (TEXT), Status (DROPDOWN: 'Not Started','In Progress','Done'), Priority (NUMBER)"
"Add a medium solid border around A1:D10 in spreadsheet XYZ789"
"Protect the header row so collaborators can't accidentally edit it"
"Auto-fit row heights for rows 2–50 after wrapping text"
Google Drive
"List my 10 most recent Google Docs"
"Search for documents containing 'project proposal'"
"Create a folder called 'Meeting Notes' and move document ABC123 into it"
Gmail
"Show me my 20 most recent unread emails"
"Search Gmail for messages from [email protected] in the last 7 days"
"Read the full body of message ID 18c3f4a2b1d9"
"Send an email to [email protected] with the subject 'Weekly update' and this body..."
"Reply to message 18c3f4a2b1d9 with 'Thanks, confirmed.'"
"Star message 18c3f4a2b1d9 and archive it"
"Move message 18c3f4a2b1d9 to Trash"
"List all my Gmail labels"
"Draft a reply to that email but don't send it yet — let me review first"
"Show me my drafts, then send the one to bob@"
"Triage my unread inbox: tell me which 20 emails need attention and which are noise"
Google Calendar
"What's on my calendar this week?"
"Create an event titled 'Project review' tomorrow from 2pm to 3pm Pacific time"
"Quick add: lunch with Alex Friday 12:30"
"Reschedule event abc123 to next Monday at 10am"
"Delete the 'Standup' event tomorrow"
"List all events on my calendar between April 15 and April 22"
"Schedule a 30-minute meeting with [email protected] next Wednesday at 11am with a Google Meet link"
Markdown Workflow
The server supports a full round-trip markdown workflow:
- Read a document as markdown:
readDocument with format='markdown'
- Edit the markdown locally
- Push changes back:
replaceDocumentWithMarkdown
Supported: headings, bold, italic, strikethrough, links, bullet/numbered lists, horizontal rules.
Live Docs Verification
The repository includes an opt-in live integration test for cloneTable against the real Google Docs API. It is skipped by default.
Requirements:
- valid
GOOGLE_CLIENT_ID and GOOGLE_CLIENT_SECRET
- an authorized token already stored via
npx -y @a-bonus/google-docs-mcp auth
Run it with:
GOOGLE_DOCS_LIVE_TESTS=1 npm run test:live:docs
This test creates temporary source/target Google Docs, verifies cloneTable, and then deletes the test files.
Remote Deployment
Deploy the server centrally on Google Cloud Run (or any container host) so your team can use it without local installs. The server uses MCP OAuth 2.1 with FastMCP's built-in GoogleProvider -- MCP clients handle the auth flow automatically.
Visit the server root URL (/) for setup instructions and a ready-to-copy client config.
Environment Variables
Setup
- Create a GCP project and enable Docs, Sheets, and Drive APIs
- Create an OAuth client (Web application type, not Desktop)
- Set the authorized redirect URI to
{BASE_URL}/oauth/callback
- Deploy to Cloud Run:
gcloud run deploy google-docs-mcp \
--source . \
--region europe-west3 \
--port 8080 \
--allow-unauthenticated \
--set-env-vars "^|^MCP_TRANSPORT=httpStream|BASE_URL=https://your-service.run.app|ALLOWED_DOMAINS=yourdomain.com|GOOGLE_CLIENT_ID=...|GOOGLE_CLIENT_SECRET=...|TOKEN_STORE=firestore|JWT_SIGNING_KEY=your-secret-key"
Note: The ^|^ prefix changes the env var delimiter from , to | because ALLOWED_DOMAINS contains commas.
How It Works
- By default, OAuth sessions are stored in memory and lost on restart
- For production, set
TOKEN_STORE=firestore and JWT_SIGNING_KEY for persistent auth across deploys and cold starts
- On serverless platforms (Cloud Run, etc.), set
MCP_STATELESS=true — MCP sessions are held in memory, so scale-to-zero wipes them. Stateless mode disables session tracking entirely; each request authenticates independently via the JWT/Firestore token flow
ALLOWED_DOMAINS restricts access to specific Google Workspace domains
- Access tokens refresh automatically; inactive sessions expire after 30 days
- Users can revoke access at any time via Google Account permissions
Updating Your Deployment
Merging changes to main does not automatically update your Cloud Run service. Each deployment is independent — you need to redeploy manually when you want new features or fixes.
To update:
Pull the latest code:
git pull origin main
Redeploy to Cloud Run:
gcloud run deploy your-service-name --source . --region your-region
Your existing environment variables are preserved — no need to pass --set-env-vars again.
When to redeploy:
- Bug fixes and security patches — redeploy as soon as possible
- New features — redeploy at your convenience
- Breaking changes — check the release notes before redeploying
You can check your current version against the latest release on the releases page.
Authentication Options
OAuth (Default)
Pass your Google Cloud OAuth client credentials as environment variables:
Service Account (Enterprise)
For Google Workspace with domain-wide delegation:
{
"mcpServers": {
"google-docs": {
"command": "npx",
"args": ["-y", "@a-bonus/google-docs-mcp"],
"env": {
"SERVICE_ACCOUNT_PATH": "/path/to/service-account-key.json",
"GOOGLE_IMPERSONATE_USER": "[email protected]"
}
}
}
}
Token Storage
OAuth refresh tokens are stored in ~/.config/google-docs-mcp/token.json (respects XDG_CONFIG_HOME). OAuth client IDs and client secrets are not stored in the token file. To re-authorize, run the auth command again or delete the token file.
Multiple Google Accounts
Set GOOGLE_MCP_PROFILE to store tokens in a profile-specific subdirectory. This allows using different Google accounts for different projects:
{
"mcpServers": {
"google-docs": {
"command": "npx",
"args": ["-y", "@a-bonus/google-docs-mcp"],
"env": {
"GOOGLE_CLIENT_ID": "...",
"GOOGLE_CLIENT_SECRET": "...",
"GOOGLE_MCP_PROFILE": "work"
}
}
}
}
Tokens are stored per profile:
~/.config/google-docs-mcp/
├── token.json # default (no profile)
├── work/token.json # GOOGLE_MCP_PROFILE=work
├── personal/token.json # GOOGLE_MCP_PROFILE=personal
Without GOOGLE_MCP_PROFILE, behavior is unchanged.
Known Limitations
- Comment anchoring: Programmatically created comments appear in the comment list but aren't visibly anchored to text in the Google Docs UI. This is a Google Drive API limitation.
- Sheets comment anchoring: API-created spreadsheet comments can store anchor metadata, but Google Workspace editors treat Drive API anchors as unanchored comments. Use
createSheetsComment with includeCellLink=true for a clickable link to the target cell, or createSheetsCellNote when the review text must be attached to the cell itself.
- Comment resolution: Resolved status may not persist in the Google Docs UI.
- Converted documents: Docs converted from Word may not support all API operations.
- Markdown images: Not yet supported in the markdown-to-Docs conversion.
- Deeply nested lists: Lists with 3+ nesting levels may have formatting quirks.
- Gmail hard delete:
trashMessage moves messages to Trash (reversible). Permanent deletion requires the broader https://mail.google.com/ scope and is not exposed in v0.1.
- Gmail attachments:
getMessage returns attachment metadata but does not download attachment bytes yet.
- Gmail HTML email send:
sendEmail sends plain-text only. For HTML bodies, paste HTML into the body field — it will be delivered as text, not rendered.
- Calendar scope:
calendar.events permits event CRUD on existing calendars but cannot create or delete entire calendars themselves.
- Apps Script API is off by default: every account must enable it once at https://script.google.com/home/usersettings. The tools cannot turn it on for you.
- Apps Script deployments: the tools edit project source. Creating versions, deployments and installable triggers is not exposed yet — simple triggers such as
onEdit and onOpen work without any of that.
- Calendar recurring events:
updateEvent and deleteEvent modify the entire recurring series unless you target a specific instance ID returned by listEvents with singleEvents=true.
Troubleshooting
- Server won't start:
- Verify
GOOGLE_CLIENT_ID and GOOGLE_CLIENT_SECRET are set in the env block of your MCP config.
- Try running manually:
npx @a-bonus/google-docs-mcp and check stderr for errors.
- Authorization errors:
- Ensure Docs, Sheets, Drive, Gmail, and Calendar APIs are enabled in Google Cloud Console.
- Confirm your email is listed as a Test User on the OAuth consent screen and that all required scopes (Docs, Sheets, Drive,
gmail.modify, calendar.events) are added to the consent screen.
- Re-authorize:
npx @a-bonus/google-docs-mcp auth
- Delete
~/.config/google-docs-mcp/token.json and re-authorize if upgrading — Gmail and Calendar scopes were added in later versions, so existing tokens must be refreshed.
- Remote (Cloud Run) users must sign out and sign back in from their MCP client so Google reissues consent with the new scope list.
- Tab errors:
- Use
listTabs to see available tab IDs.
- Omit
tabId for single-tab documents.
- "Page not found" on claude.ai during OAuth sign-in (remote deployments):
- Symptom: clicking Connect on a custom MCP connector lands on the Claude "Page not found" page instead of the Google sign-in screen.
- Cause: Cloud Run cold start. The first request to an idle service times out before the container finishes spinning up, and Claude routes the failed redirect to its 404 page.
- Workaround: hard-refresh the page (
Cmd+Shift+R on macOS, Ctrl+Shift+R on Windows/Linux). The second request hits a now-warm instance and the OAuth flow proceeds normally.
- Permanent fix: set
--min-instances=1 on your Cloud Run service to keep one instance always warm (gcloud run services update <service> --region <region> --min-instances=1). Costs ~$2–3/month for the memory reservation.
- Re-authenticated unexpectedly after a redeploy (remote deployments):
- Cause:
JWT_SIGNING_KEY is auto-generated on each container start, so redeploys invalidate all previously issued sessions.
- Fix: set a stable
JWT_SIGNING_KEY env var on the Cloud Run service so it survives restarts: gcloud run services update <service> --region <region> --update-env-vars JWT_SIGNING_KEY=$(openssl rand -hex 32). Sessions minted after this change will survive future redeploys.
- High CPU with multiple MCP sessions: Some clients call
tools/list very often. FastMCP otherwise recomputes JSON Schema for every tool on every request, which can pin a CPU core per process. This server precomputes the payload once before stdio starts and replaces the tools/list handler with a cached snapshot. If you still see sustained load, capture a few seconds with sample <pid> 1 10 (macOS) or node --cpu-prof and report it.
Google Cloud Setup Details
Step-by-step Google Cloud Console instructions
For remote deployment, create an OAuth client of type Web application (not Desktop app). Use Desktop app only for local stdio usage.
- Go to Google Cloud Console: Open console.cloud.google.com
- Create or Select a Project: Click the project dropdown > "NEW PROJECT". Name it (e.g., "MCP Docs Server") and click "CREATE".
- Enable APIs:
- Navigate to "APIs & Services" > "Library"
- Search for and enable: Google Docs API, Google Sheets API, Google Drive API, Gmail API, Google Calendar API
- Configure OAuth Consent Screen:
- Go to "APIs & Services" > "OAuth consent screen"
- Choose "External" and click "CREATE"
- Fill in: App name, User support email, Developer contact email
- Click "SAVE AND CONTINUE"
- Add scopes:
documents, spreadsheets, drive, gmail.modify, calendar.events
- Click "SAVE AND CONTINUE"
- Add your Google email as a Test User
- Click "SAVE AND CONTINUE"
- Create Credentials:
- Go to "APIs & Services" > "Credentials"
- Click "+ CREATE CREDENTIALS" > "OAuth client ID"
- Application type: "Desktop app"
- Click "CREATE"
- Copy the Client ID and Client Secret
Contributing
Contributions are welcome! See CONTRIBUTING.md for development setup, architecture overview, and guidelines.
License
MIT -- see LICENSE for details.