worksmobile-mcp
Provides admin tools for LINE WORKS Drive, including shared-drive governance, permission management, folder inheritance controls, share creation, file upload/download, and search via service-account delegation.
Provides admin tools for NAVER WORKS Drive, including shared-drive governance, permission management, folder inheritance controls, share creation, file upload/download, and search via service-account delegation.
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@worksmobile-mcpshow permissions for drive @2001000000xxxxxx"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
worksmobile-mcp
Unofficial NAVER WORKS (LINE WORKS) Drive admin CLI + MCP server, built on the
Developer API's service-account delegation (JWT delegated_user).
Existing WORKS MCP servers focus on the end-user plane (your own mail/calendar/files via User OAuth). This project covers the admin plane that they don't:
act as any member of your tenant via delegation (like Google domain-wide delegation)
shared-drive governance: list drives, inspect
accessibleRange/permissionType, grant/revoke drive- and folder-level permissions, toggle folder inheritance (enable/disable)share-create ("shared with me" shortcuts), My Drive scaffolding, upload/download, search
Not affiliated with NAVER / WORKS MOBILE Corp. "NAVER WORKS", "LINE WORKS" and worksmobile.com are their trademarks/properties. Official API docs: https://developers.worksmobile.com/
Safety design
WORKS Drive permission APIs have sharp edges. This tool encodes them:
Every mutating operation requires explicit confirmation — CLI:
--yes(non-interactive runs refuse without it); MCP:confirm=trueparameter. Agents are expected to ask the human before setting it.Bulk permission delete ("all-delete") is not exposed at all — its semantics flipped between WORKS versions (masters-only vs open to everyone).
Destructive semantics are spelled out in tool docs: drive
accessibleRangePATCH transitions wipe granted permissions; folderenablebreaks inheritance;disabledrops folder grants.
Related MCP server: synology-office-mcp
Setup
In the Developer Console, create an app with service-account delegation, note Client ID/Secret, create the service account, and download the private key. Grant OAuth scopes (
file,user.read).Configure credentials:
pip install worksmobile-mcp # or: uv tool install worksmobile-mcp
mkdir -p ~/.config/worksmobile
cp .env.example ~/.config/worksmobile/.env # then fill in valuesConfig resolution: process env (WORKS_*) > $WORKS_ENV_FILE > ./.env >
~/.config/worksmobile/.env.
CLI
worksmobile drives # list shared drives
worksmobile drive @2001000000xxxxxx # accessibleRange / permissionType
worksmobile ls --sd @2001000000xxxxxx # list files
worksmobile perms @2001000000xxxxxx --folder FID
worksmobile grant @2001000000xxxxxx --target pm@corp.com --type WRITE --folder FID --yes
worksmobile share FID --owner host@corp.com --to pm@corp.com --type WRITE --yes
worksmobile download FID --sd @2001000000xxxxxx -o report.hwp
worksmobile call GET /users/me/drive/files # raw API escape hatchAll read commands accept --user someone@corp.com to act as that member.
MCP server
stdio (local agents — Claude Code, Codex, Cursor, Gemini CLI):
claude mcp add worksmobile -- worksmobile-mcp{ "mcpServers": { "worksmobile": { "command": "worksmobile-mcp" } } }Streamable HTTP (remote / chat surfaces):
worksmobile-mcp --transport streamable-http --port 8123⚠️ The delegated service account can act as any member. If you expose the HTTP transport beyond localhost, put real authentication in front of it, or don't.
Tools
Tool | Mutating | Description |
| shared drives & settings | |
| files of a shared drive or a member's My Drive | |
| drive/folder permissions | |
| ⚠ | grant / delete one permission |
| ⚠ | folder inheritance gate |
| storage-redirect download / 2-step upload | |
| My Drive folder | |
| ⚠ | "shared with me" shortcuts (My Drive only) |
| a member's received shares | |
| drive search | |
| ⚠ | raw API escape hatch |
⚠ = requires confirm=true.
API notes (hard-won)
accessibleRangeis 3-valued:TENANT/DOMAIN/MEMBER. New drives default to DOMAIN+WRITE. PATCH transitions are destructive (MEMBER→DOMAIN deletes all grants; →MEMBER fails while folder-level grants exist).Folder-level permissions accept individual users only (no org units); the target must already be a drive member (undocumented, observed).
Folder
enable= masters-only until you grant;disable= grants dropped, inheritance back.share-create works on My Drive folders only — team-drive folders can't produce "shared with me" shortcuts.
A pure service-account token has no My Drive (403); hosting requires delegation to a real account.
Upload is 2-step (metadata POST →
uploadUrlPUT); download is a 302 whose storage location also requires the Bearer token.GET /sharedrivesresponds{"sharedrives": [...]}(docs imply a bare array).
License
MIT
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- AlicenseAqualityDmaintenanceNAVER WORKS CLI + MCP server. 26 tools for messages, calendar, drive, mail, tasks, and boards. AI agents can manage NAVER WORKS directly.Last updated265024Apache 2.0
- AlicenseAqualityCmaintenanceSelf-hosted MCP server that exposes Synology Drive, Spreadsheet, MailPlus, and Calendar as structured tools for AI agents, enabling file, spreadsheet, email, and calendar management via natural language.Last updated3979MIT
- AlicenseAqualityDmaintenanceMCP server for Google Workspace APIs - Docs, Sheets, Drive, Gmail, and Calendar. Enables reading, creating, and editing Google Docs and Sheets, managing comments, reading emails, and viewing calendar events.Last updated2344416MIT
- AlicenseBqualityCmaintenanceProduction-ready MCP server for Google Workspace providing broad coverage across Gmail, Drive, Calendar, Docs, Sheets, and more, with safe-by-default write operations and markdown-to-Google-Docs support.Last updated100MIT
Related MCP Connectors
The official MCP Server from Mia-Platform to interact with Mia-Platform Console
MCP (Model Context Protocol) server for Appwrite
MCP server for interacting with the Supabase platform
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/z0nam/worksmobile-mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server