mcp-google-multi
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| MASTER_KEY | Yes | Base64-encoded 32-byte key to encrypt token store (e.g. openssl rand -base64 32) | |
| GOOGLE_PROFILE | No | Write policy: read-only (default), safe-writes, or full-writes | read-only |
| GOOGLE_ACCOUNTS | Yes | Comma-separated alias:email pairs, e.g. work:you@co.com,personal:you@gmail.com | |
| GOOGLE_CLIENT_ID | Yes | OAuth Desktop client ID from Google Cloud | |
| GOOGLE_READ_ONLY | No | Set to 'true' to hard-disable all writes | |
| TOKEN_STORE_PATH | No | Override path for encrypted token directory (default: ~/.config/mcp-google-multi/tokens) | |
| GOOGLE_WRITE_DENY | No | Glob overrides to deny specific write tools, e.g. '*:delete*' | |
| GOOGLE_WRITE_ALLOW | No | Glob overrides to allow specific write tools, e.g. 'calendar:*, sheets:update*' | |
| GOOGLE_CLIENT_SECRET | Yes | OAuth Desktop client secret from Google Cloud | |
| GOOGLE_ADMIN_ACCOUNTS | No | Aliases granted Workspace admin scopes | |
| GOOGLE_OPTIONAL_SCOPES | No | Extra scope bundles: 'forms', 'chat', or comma-separated |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": true
} |
| prompts | {
"listChanged": true
} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| discover_allA | Reveal ALL curated Google tools at once (instead of per-service discovery). Use when starting substantial Google work; prefer these over google_api_call. Pair with discover_reset. |
| discover_resetA | Collapse the tool surface back to the configured default, reclaiming context budget after heavy Google work. All tools remain callable by name after collapsing. |
| gmail_discoverA | Discover gmail: lists the catalog and reveals its hidden tools; call first, then call the tool by name. Ops: search, read, read_thread, read_batch, send, download_attachment, create_draft, modify_labels, trash, delete +12 more; 58 generated ops: users. |
| drive_discoverA | Discover drive: lists the catalog and reveals its hidden tools; call first, then call the tool by name. Ops: search, read, list, upload, download, export, create_folder, update, delete, trash +26 more; 35 generated ops: approvals, files, drives, teamdrives, changes, apps +6 areas. |
| calendar_discoverA | Discover calendar: lists the catalog and reveals its hidden tools; call first, then call the tool by name. Ops: list_calendars, list_events, get_event, create_event, update_event, delete_event, quick_add, move_event, list_instances, get_freebusy +1 more; 27 generated ops: acl, calendar, calendars, events, settings, channels +1 areas. |
| sheets_discoverA | Discover sheets: lists the catalog and reveals its hidden tools; call first, then call the tool by name. Ops: create, get, read_range, write_range, append_rows, clear_range, batch_read, batch_write, add_sheet, delete_sheet +19 more; 7 generated ops: spreadsheets. |
| docs_discoverA | Discover docs: lists the catalog and reveals its hidden tools; call first, then call the tool by name. Ops: create, get, read, insert_text, replace_text, delete_range, update_style, insert_table, create_named_range, delete_named_range +17 more. |
| contacts_discoverA | Discover contacts: lists the catalog and reveals its hidden tools; call first, then call the tool by name. Ops: search, resolve, get, list, create, update, delete, groups_list, group_members, group_create; 14 generated ops: people, contact, other. |
| searchconsole_discoverA | Discover searchconsole: lists the catalog and reveals its hidden tools; call first, then call the tool by name. Ops: sites_list, sites_get, sites_add, sites_delete, sitemaps_list, sitemaps_get, sitemaps_submit, sitemaps_delete, searchanalytics_query, url_inspect; 1 generated ops: url. |
| tasks_discoverA | Discover tasks: lists the catalog and reveals its hidden tools; call first, then call the tool by name. Ops: lists_list, list_get, list_insert, list_update, list_delete, list, get, insert, update, delete +2 more; 2 generated ops: tasklists, tasks. |
| meet_discoverA | Discover meet: lists the catalog and reveals its hidden tools; call first, then call the tool by name. Ops: conference_records_list, conference_record_get, recordings_list, transcripts_list, transcript_entries_list; 13 generated ops: conference, spaces. |
| workspaceevents_discoverA | Discover workspaceevents: lists the catalog and reveals its hidden tools; call first, then call the tool by name. Ops: 15 generated ops: tasks, subscriptions, message, operations. |
| google_api_searchA | Search the Google API Discovery index for any Workspace REST method, including ones with no dedicated tool here. Returns method ids + parameters to invoke via google_api_call. APIs: gmail, drive, calendar, sheets, docs, slides, forms, people, searchconsole, tasks, chat, meet, driveactivity, drivelabels, admin_directory, admin_reports, admin_datatransfer, groupssettings, analyticsadmin, analyticsdata, appsmarket, classroom, cloudidentity, cloudsearch, groupsmigration, keep, licensing, postmaster, reseller, script, vault, workspaceevents. |
| google_api_callA | Invoke any Google Workspace REST method by Discovery id (escape hatch for operations without a dedicated tool). Find methods with google_api_search first. Subject to the same write-control policy as named tools. On reads, pass a |
| account_listA | List the configured Google accounts: alias, email, admin flag, token health (ok / expired_refreshable / needs_reauth / missing / decrypt_error), and granted vs configured scopes. Use this to see which account aliases are available and healthy. |
| diagnoseA | Health report for this server: runtime, config, keys, per-account token status, scope grants, and API enablement. Read-only; returns copy-pasteable fixes for anything wrong. Call this to diagnose auth/config failures. |
| account_addA | Add a new Google account: pass alias + email directly (plus optional bundles/allBundles/admin), or pass nothing for an interactive form where the client supports elicitation. Writes the registry and runs Google consent in the browser. No file editing or restart needed to use the account (tools of a service it newly enables register at the next restart). Requires GOOGLE_CLIENT_ID/SECRET (run the |
| account_reauthA | Re-authenticate an existing Google account (recover a dead refresh token, or grant scopes after a profile change). Runs Google consent in the browser. Pass the account alias. |
| account_write_configA | Register this server with your MCP client (Claude Code / Claude Desktop / Cursor) so you don't hand-edit JSON. Default: returns the exact snippet/command to add. Pass write:true to write detected file-based configs in place (backs up first, never clobbers a malformed file). Secrets are never inlined. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
| setup | Guided Google Cloud Console prelude: project, APIs, consent screen, OAuth client, and credentials. The one-time browser setup that has no API. |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 19 tools
Each discover tool targets a distinct Google service, and the search/call/account tools have clearly separate roles. There is minor overlap between account_list and diagnose, which both surface token-health information, but their overall scopes differ enough for an agent to select correctly.
The tool names are consistently snake_case and use recognizable prefixes for accounts and raw API access. The discovery naming is slightly uneven: per-service tools use service_discover while the aggregate helpers use discover_all and discover_reset, but the pattern remains readable.
With 19 visible tools, the surface falls into the heavy range even though each service discover tool has a clear purpose. A multi-service Google server can justify some breadth, but the count is above the typical 3-15 sweet spot and could be reduced with more generic discovery.
The server covers major Google Workspace services and provides an escape hatch for any missing REST method, plus account add/list/reauth/config and diagnostics. Minor gaps exist around account removal or disablement, but most lifecycle and API-access needs are addressed.