fgac
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@fgacsummarize the latest email from Sarah about the contract"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
FGAC.ai
Fine-grain access control for AI agents on Gmail, Google Sheets and Google Docs.
Product: https://fgac.ai · Docs: https://fgac.ai/docs · Privacy: https://fgac.ai/privacy
FGAC.ai is a hosted MCP server and API proxy that sits between your AI agents and your Google accounts. Connect one or many Gmail accounts — work, school, personal, and inboxes teammates delegate to you — plus the specific Google Sheets and Docs you choose, and every request passes through deny-by-default access rules you control before it touches Google. Nothing to install, no Google Cloud project needed: sign in with Google and the agent can read that account's mail immediately; sending, editing, and other inboxes are granted from your dashboard or from a one-click approval link the agent hands you when it is denied.
Add FGAC to your agent
Client | How |
Claude.ai / Claude Desktop | Search FGAC in the connectors directory, or add a custom connector with the URL below |
Claude Code |
|
VS Code / Copilot, Cursor, Windsurf, Cline | Add a remote MCP server: |
Smithery | |
Any Google SDK | Point the client's endpoint override at |
MCP endpoint: https://fgac.ai/api/mcp (Streamable HTTP; OAuth 2.1 with
dynamic client registration and PKCE; discovery at
/.well-known/oauth-protected-resource/mcp).
Related MCP server: VaultAssist
What you get
Multiple Gmail accounts — connect several accounts, and let teammates delegate their inboxes to your agent from their own dashboard. Every delegation keeps its own rules and is revocable in one click. No password sharing.
Editable Google Sheets and Docs — expose individual files read-only or read & write; agents can update cells, append rows, and edit documents there and nowhere else. The rest of your Drive does not exist to them.
Guardrails — read rules hide sensitive mail (2FA codes, password resets, financial alerts) by label or content pattern; send whitelists limit outbound mail to recipients you approve; permanent deletion is never possible.
One-click approvals — when an agent needs more (a new recipient, a new sheet), it asks; you approve exactly that grant from a single-use link.
Nineteen tools — typed Gmail, Sheets, Docs, and comments tools with safety annotations, plus a rule-checked raw Google API escape hatch covering the full Gmail, Sheets, and Docs API surface.
A request log — every call your agent makes, with what was allowed and what was blocked and why.
Your data is never stored or used for training. See the Terms for service terms.
Licensing
Two different things, two different terms:
The hosted service at https://fgac.ai is open to anyone — individuals, teams, companies, and schools — under its Terms of Service and Privacy Policy. Connecting an agent through fgac.ai does not involve this repository's license at all.
This source code is licensed for personal use only: an independent individual may self-host it to manage their own Gmail or Google Workspace accounts. Use by or on behalf of a company, government agency, or educational institution, and offering the code as a hosted or multi-tenant service, are prohibited without a separate license from the author. See
LICENSEfor the exact terms and liability limitations.
Developing
This is a Next.js app deployed on Vercel, with Clerk for authentication and Neon Postgres via Drizzle. There is exactly one supported way to run it locally, and it depends on access to the project's Vercel environment:
npx vercel link --yes --project fine-grain-access-control # once per clone
npx vercel env pull .env.local --environment=development # dev Clerk + Neon creds
npm run db:branch # isolated Neon branch
npm run devNode 20.9+ is required. npm run env:check diagnoses environment problems.
Contributor rules, QA workflow, and database safety guards are documented in
CLAUDE.md and docs/.
This server cannot be installed
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Connectors
Permissioned access to Gmail, Drive and Calendar via the user's own Google account
Authenticated email gateway for AI agents — per-agent inboxes, HITL approval, SPF/DKIM verified.
Authenticated email gateway for AI agents — per-agent inboxes, HITL approval, SPF/DKIM verified.
Security gateway for AI agents: policy, approval, and audited execution, no secrets shared.
Related MCP Servers
- -licenseNot gradedqualityNot gradedmaintenanceEnables AI assistants to securely manage Google Workspace services (Gmail, Calendar, Drive, Sheets, Contacts) with persistent multi-account OAuth. Uses OS keychain for credential storage with health monitoring and granular business rules for enterprise security.-
- AlicenseNot gradedqualityDmaintenanceEnables natural language control over Google Workspace (Gmail, Drive, Calendar, Sheets, Slides, Tasks) through secure OAuth 2.1 authentication, with vault-level security and multi-user isolation.1527-
- AlicenseNot gradedqualityDmaintenanceEnables AI tools to append content to Google Docs and create Gmail drafts with human-in-the-loop approval.Apache 2.0
- AlicenseNot gradedqualityCmaintenanceEnables AI agents to read, triage, respond to, and calendar-manage Gmail with a production-grade MCP control plane and human-in-the-loop safety.3MIT