gdrive-mcp
The gdrive-mcp server provides a read/write interface for Google Drive, Docs, and Sheets, with safety guardrails like bounded reads, confirm-gated destructive operations, and a local file sandbox. Core capabilities include:
Discovery & Navigation: Resolve Drive/Docs/Sheets URLs or IDs; search files by name, content, MIME type, or parent folder; list folder contents; and retrieve file metadata (owner, timestamps, size, parents, sharing).
Google Docs:
Read documents in markdown/text with paginated bounded chunks, outline, revision ID, and optional colored text.
Extract embedded images in document order.
Create documents with optional initial markdown content.
Append or insert text (supports markdown and colored text) at specific locations using indices or locators.
Insert tables from row grids.
Delete or replace text/sections (with explicit confirmation and dry-run option).
List and add comments.
Google Sheets:
Preview sheets with a bounded 5×5 grid or a specified A1 range.
Read full tabs to local CSV files, returning path and dimensions.
Write rows starting at a cell (confirm-gated when overwriting, dry-run, supports RAW or USER_ENTERED input).
Append rows non-destructively (dry-run supported).
Format cells (bold/italic/underline) within an A1 range (dry-run).
Create spreadsheets with optional named tabs; add tabs to existing ones.
Clear ranges or delete rows (confirm-gated, dry-run).
File Management:
Read any file as text in bounded chunks (including Google-native exports and PDF text).
Download binary files (inline base64 or to sandbox).
Upload new files or replace existing content (confirm-gated for replacement).
Move and rename files (both confirm-gated).
Export Google-native files to PDF, DOCX, XLSX, PPTX, CSV, TXT, MD, HTML.
Safety & Security:
Destructive operations require explicit
confirm=true; many support a dry-run to preview changes.Local file I/O is sandboxed to a configurable directory, rejecting path traversal.
Verification gate can require per-call approval for certain models or universally.
All tool calls are audit-logged (user, tool, target, outcome, without content).
Reads are bounded to prevent context flooding.
Markdown formatting and color support for rich text creation/editing in Docs.
Provides tools for interacting with Google Drive, including reading and writing Google Docs and Google Sheets, searching files, managing folders, and more.
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@gdrive-mcpshow me files named 'report' in my Drive"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
gdrive-mcp
A read/write MCP for Google Drive, Docs & Sheets that fixes what trips agents on naive Drive servers — whole-document context floods, unguarded destructive writes, and inconsistent argument names — with bounded/paged reads, spill-to-disk for full data, confirm-gated mutations, and one consistent item argument.
Conventions: every tool takes its target as
item(a URL or ID); unknown args are rejected; destructive tools (ᶜ) return an impact preview unless called withconfirm=true.Dry-run (edit-only): the edit tools for existing files —
append_text,insert_text,insert_table,delete_text,replace_text,write_sheet,append_rows,format_cells,clear_range,delete_rows— acceptdry_run=true, returning a predicted before/after without writing (client-side;write_sheetshows formula cells literally, so Google's recalculation isn't simulated, and Docsinsert_textreports the insertion point rather than a merged string). Dry-runs are still subject to the verification gate.Editing a Doc by content, not by offset:
delete_text/replace_text(andinsert_text/insert_table'safter/before) locate their target with a locator —match(a literal, case-sensitive substring lying within one paragraph) orsection(a heading's exact text, covering that heading and everything under it up to the next heading of the same or higher level). Character offsets intoread_document's content are not valid Docs indexes: that content is rendered markdown (heading prefixes, synthesized table delimiter rows, escaped pipes) and does not align with the document's UTF-16 index space. The server resolves locators against the API's own element offsets instead, so anchors are always valid — and for block content they land on a paragraph boundary by construction. Eachread_documentoutlineentry also carries realstart/endoffsets, plus arevision_id; locator writes pin that revision, so a concurrent edit makes the write fail rather than land on shifted text.Colored text (opt-in):
append_text/insert_texttake an optionalcolor(hex, e.g.#3366CC) applied only when explicitly passed — unset = plain text.read_document(include_colors=true)returnscolored_runs(spans with an explicit foreground color).Formatted writes (opt-in):
append_text/insert_text/create_documentacceptmarkdown=true, rendering a small dialect —#…######headings,-/*bullets,1.numbered lists (nest with two spaces or a tab per level),**bold**,*italic*,<u>underline</u>, and GFM pipe tables (a header row immediately followed by a| --- | --- |delimiter row — a lone| a | b |line with no delimiter stays literal text). The only escape is\|for a literal pipe inside a table cell; otherwise text that looks like markup gets styled (leavemarkdownunset to store text verbatim). Table round-trip preserves structure and plain cell text — cell emphasis and multi-paragraph cells are not preserved on read. In Sheets,format_cellssets bold/italic/underline on a cell range without touching values.Local-file sandbox: all local file I/O is confined to
GDRIVE_MCP_FILES_DIR(default a private0700dir under the config dir) —download_file/export_file/read_full_sheetwrite there (relativedest_path; absolute paths and..rejected, files0600), andupload_file(source_path)reads only from there. This stops a prompt-injected agent from writing to~/.sshor exfiltrating arbitrary local files to Drive. Fetched Doc images are pulled only from Google hosts (the OAuth token is never sent elsewhere).Spilled-file retention + audit: files spilled to the sandbox are swept on server start once older than
GDRIVE_MCP_FILES_TTL_HOURS(default 24;0disables) — for a long-lived server, restart to dispose, or lower the TTL. The sweep is ownership-gated: it only runs in a sandbox gdrive-mcp itself created (tracked by a.gdrive-mcp-sandboxmarker file), so pointingGDRIVE_MCP_FILES_DIRat a pre-existing directory never deletes the files already there — a startup warning notes the skipped sweep, and creating the marker file yourself opts the directory in. Every tool call is appended to an audit log (GDRIVE_MCP_AUDIT_LOG, defaultaudit.login the config dir) recording user, tool, target id, and outcome — never the content read or written.Verification gate: set
GDRIVE_MCP_VERIFICATION_MODEL_PATTERNSto comma-separated, case-insensitive model-name substrings when selected model families should require per-call user approval via MCP elicitation. A match from either the operator pinGDRIVE_MCP_CALLING_MODELor the request's self-reported_meta.modelturns the gate on; a nonmatching request model cannot turn off an operator-pin match. SetGDRIVE_MCP_REQUIRE_VERIFICATION=alwaysto gate every call regardless of model. Gated calls fail closed on decline or when the client cannot prompt. Because request metadata is advisory, enforce mandatory policy with deployment-controlled environment variables and credential boundaries.
Tools
Discovery
resolve_link— resolve any Drive/Docs/Sheets URL or ID into its id, kind, name, and link.search_files— find files by name, full-text content, MIME type, and/or parent folder.list_folder— list a folder's direct children.get_metadata— full metadata for a file: owner, timestamps, size, parents, sharing.
Docs
read_document— read a Doc as markdown/text in bounded ~8k-char chunks (paginated, with anoutlinecarrying each heading'sstart/endoffsets, plusrevision_id); reads all tabs by default or a specifictab.extract_images— pull embedded images (inline and positioned/floating) out as viewable images, in document order (tab-aware).create_document— create a new Doc, optionally with initial content (markdown=truefor formatted).append_text— append text to the end of a Doc, targeting a chosen tab (markdown=truefor headings/lists/bold/italic/underline).insert_text— insert textafter/beforea matched substring (or at a rawindex), targeting a chosen tab (markdown=trueas above).insert_table— insert a table filled from arowsgrid (append, orafter/beforea match, or at anindex;header=truebolds the first row).**
delete_text**ᶜ — delete a matched substring or a whole headingsection.**
replace_text**ᶜ — replace a matched substring or a wholesection(markdown=truefor formatted replacements; useinsert_tablefor tables).read_comments— list a doc/file's comments and replies.add_comment— add an (unanchored) comment.
Sheets
read_sheet— a bounded 5×5 preview of each tab (configurablemax_rows/max_cols; passa1_rangefor an exact range;values=FORMULAfor formulas).read_full_sheet— read a whole tab, save it to a local CSV, and return the path + exacttotal_rows/total_cols+ the 5×5 preview.**
write_sheet**ᶜ — write rows starting at a cell; gated when it would overwrite non-empty cells.append_rows— append rows after the last row (non-destructive).format_cells— set bold/italic/underline on a bounded A1 range (tri-state flags; values untouched).create_spreadsheet— create a new spreadsheet with optional named tabs.add_tab— add a tab to an existing spreadsheet.**
clear_range**ᶜ — clear the values in an A1 range.**
delete_rows**ᶜ — delete N rows from a tab.
Files
read_file_as_text— a file's content as text in bounded chunks (Google-native exported; PDFs text-extracted).download_file— download a binary file (base64 if small, else written to disk).**
upload_file**ᶜ — create a new file, or replace an existing file's content (replace is gated).**
move_file**ᶜ — move a file into aparentfolder.**
rename_file**ᶜ — rename a file.export_file— export a Google-native file to pdf / docx / xlsx / pptx / csv / txt / md / html.
Related MCP server: google-mcp
Quick install
Requires uv, the Claude Code CLI (claude), and your own Google OAuth client (see Setup). Then:
git clone https://github.com/shivankj11/gdrive-mcp.git && cd gdrive-mcp && bash setup.shsetup.sh is idempotent — re-run it any time. It installs uv (if missing), runs the one-time Google browser consent, and registers the server with Claude Code. It looks for the Desktop-app OAuth client JSON in this order: an existing ~/.config/gdrive-mcp/oauth_client.json; a GDRIVE_MCP_OAUTH_CLIENT_CMD that prints the JSON; or a plaintext oauth_client.json at the repo root. If none is found it tells you how to create one.
Setup (one-time, per Google account)
In a Google Cloud project you control, create an OAuth client (Application type Desktop app) and configure its consent screen. The
drivescope is restricted, so follow Google's verification requirements (for personal use, add yourself as a test user).Enable the Drive, Docs, and Sheets APIs (all three are authorized by the single
drivescope, but each must be enabled once).Save the client JSON to
~/.config/gdrive-mcp/oauth_client.json(or setGDRIVE_MCP_OAUTH_CLIENT), then:
uv run gdrive-mcp auth # one-time loopback-OAuth browser consent; caches a token
uv run gdrive-mcp whoami # verifyYou authenticate as yourself, so the server can only reach what your own Google account already can.
Register with an MCP client
claude mcp add gdrive -- uv run --directory /path/to/gdrive-mcp gdrive-mcp serveRust implementation (rust/)
rust/ holds a second, self-contained implementation of the same server — same 29 tools, same
argument names, same result shapes, same confirm/dry-run/locator/gate semantics — as a single
static binary with no Python runtime. The two are interchangeable: they read the same
~/.config/gdrive-mcp/oauth_client.json and write the same token.json (byte-compatible with
google-auth's format), so authenticating with one authenticates the other, and every
GDRIVE_MCP_* variable in Configuration means the same thing to both.
cargo install --path rust # or: cargo build --release --manifest-path rust/Cargo.toml
gdrive-mcp auth # one-time browser consent (skip if the Python side already ran it)
gdrive-mcp whoami # verify
claude mcp add gdrive -- gdrive-mcp serveNotable differences, all internal:
Google APIs are called directly over REST (
reqwest) instead of through a discovery document, behind aGoogleApitrait so the tool tests run against a recording fake.MCP is served by
rmcp, the official Rust SDK; the verification gate prompts through its elicitation support, andtests/server_integration.rsdrives the registered path with a real in-memory MCP client (annotations, strict schemas, and every accept/decline/no-prompt branch).Argument handling reproduces both of FastMCP's layers, not just the strict one: unknown arguments are rejected (
extra="forbid"), and a list sent as a JSON string or a boolean sent as"true"is coerced the way pydantic's lax mode did, because MCP clients really send those.PDF text extraction uses
pdf-extractrather thanpypdf, so extracted text may differ in whitespace for unusual PDFs.The markdown dialect's inline rules need lookaround, which Rust's default
regexengine does not support, somd.rsusesfancy-regexfor exactly those two patterns — with\wand\sspelled out, since the two engines define them differently.
Known behavioural divergences, both confined to how a spilled filename is spelled: A1 cells accept
only ASCII digits (Python's \d also matched other Unicode digits), and localfs's filename
sanitiser keeps Unicode combining marks where Python replaced them with _. Neither affects
containment or content.
cargo test --manifest-path rust/Cargo.toml # unit + integration tests, no credentials needed
python3 scripts/diff_tool_surface.py # both servers advertise an identical tool surfaceSee VERIFICATION.md for what each implementation's tests actually pin, and for
the live credentialed runs.
Configuration
Env var | Default | Purpose |
|
| Desktop-app OAuth client JSON |
|
| Cached per-user token |
|
| Sandbox for local file I/O — download/export/CSV writes and upload sources are confined here (absolute/ |
|
| Age (hours) after which spilled sandbox files are swept on server start; |
|
| Base config dir |
| (unset) | Operator-controlled caller-model pin; used when the client does not send |
| (unset) | Comma-separated model-name substrings that require per-call verification |
| (unset) | Set to |
Credential files are git-ignored and must never be committed.
Development
uv sync # install deps (incl. dev group)
uv run pytest # run the test suiteLicense
MIT — see LICENSE.
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- AlicenseAqualityDmaintenanceMCP server for Google Workspace APIs - Docs, Sheets, Drive, Gmail, and Calendar. Enables reading, creating, and editing Google Docs and Sheets, managing comments, reading emails, and viewing calendar events.345216MIT
- Alicense-qualityBmaintenanceMCP server for Google Drive, Docs, and Sheets — built for Claude Code. Gives Claude Code direct read/write access to Google Sheets (cell-level edits, formatting, structure), Google Docs (insert, replace, append), and Drive (search).721MIT
- Flicense-qualityCmaintenanceA read-only Google Drive MCP server that allows searching files, reading file content (with auto-export for Google Docs, Sheets, Slides), and retrieving file metadata via OAuth authentication.132
- AlicenseBqualityCmaintenanceProduction-ready MCP server for Google Workspace providing broad coverage across Gmail, Drive, Calendar, Docs, Sheets, and more, with safe-by-default write operations and markdown-to-Google-Docs support.100MIT
Related MCP Connectors
Streamable HTTP MCP server for Google Calendar and Sheets with OAuth login.
Google Docs MCP Pack — read, create, and edit Google Docs via OAuth.
Read-only MCP server for ClassQuill, a tutoring-business-management platform.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/shivankj11/gdrive-mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server