Google Workspace MCP
by adamcfield
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| MCP_READONLY | No | Set to "true" to register only read tools (no writes, sends, deletes). | false |
| TOOL_SURFACE | No | Which tools tools/list advertises: "full" (default) or "compact". | full |
| ALLOWED_EMAILS | No | Comma-separated emails / @domains allowed to sign in. Fail closed: empty = nobody (unless ALLOW_ANY_GOOGLE_ACCOUNT). | |
| MCP_AUTH_TOKEN | No | Shared secret MCP clients send; also unlocks /google/auth. Required for the bearer worker (>=32 random chars recommended). | |
| GOOGLE_CLIENT_ID | No | The GCP OAuth 2.0 Web application client ID. | |
| TOOL_SURFACE_ADD | No | Comma/space-separated extra tool names to advertise on top of a compact surface. | |
| ENABLED_TOOL_GROUPS | No | Least privilege: comma-separated product groups or profile shorthands to enable. Only enabled groups' tools are registered and only their Google scopes are requested. | |
| DISABLED_TOOL_GROUPS | No | Comma-separated product groups to disable. | |
| GOOGLE_CLIENT_SECRET | No | The GCP OAuth 2.0 Web application client secret. | |
| GOOGLE_HOSTED_DOMAIN | No | Optional Workspace domain pre-selected on Google's account chooser (hd). Enforcement is still ALLOWED_EMAILS. | |
| GOOGLE_REFRESH_TOKEN | No | Optional: refresh token minted elsewhere (skips /google/auth). Used by the bearer worker. | |
| TOOL_RATE_LIMIT_PER_MIN | No | Tool calls per minute per MCP session (default 120; 0 = unlimited). | 120 |
| ALLOW_ANY_GOOGLE_ACCOUNT | No | Set to "true" to allow an empty allow-list to admit any Google account that passes your consent screen. Opt-in for public deployments only. | false |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Server capabilities have not been inspected yet.
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
No tools | |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
This server cannot be deployed
Maintenance
ActivityMaintained
ResponsivenessNo issues