Skip to main content

Google Workspace

GMAIL + CALENDAR + DRIVE + DIRECTORY

Four Workspace surfaces. One governed connection.

Forty-two tools for communication, scheduling, file operations, and people lookups with customer-owned Google OAuth.

Google Workspace is a Quilr-built MCP in the Library for Gmail, Google Calendar, Google Drive and Workspace directory lookups. There is no shared Quilr-owned Google client: each tenant connects with its own Google OAuth client.

Tools​

42 tools are offered by default. One more, share_google_drive_file, is registered but disabled until a Quilr operator turns it on.

Gmail​

CapabilityToolsAccess
Search and read messagessearch_gmail_messages, get_gmail_messages, get_gmail_threadRead only
Read attachmentsread_gmail_attachmentRead only
List and inspect draftslist_gmail_drafts, get_gmail_draftRead only
List labelslist_gmail_labelsRead only
Track changes incrementallysync_gmail_messagesRead only
Create and update draftssave_gmail_draftWrite
Create and rename labelssave_gmail_labelWrite
Apply and remove labels in bulkupdate_gmail_messagesWrite
Send mailsend_gmail_messageDestructive, cannot be revoked
Move messages to trashtrash_gmail_messagesDestructive
Delete a label or a draftdelete_gmail_label, delete_gmail_draftDestructive

Calendar​

CapabilityToolsAccess
List calendarslist_google_calendarsRead only
Read eventslist_google_calendar_events, get_google_calendar_event, list_google_calendar_event_instancesRead only
Check availabilityget_google_calendar_availabilityRead only
Track changes incrementallysync_google_calendar_eventsRead only
Create and update eventssave_google_calendar_eventWrite
Create and rename calendarssave_google_calendarWrite
RSVP to an invitationrespond_to_google_calendar_eventWrite
Delete an eventdelete_google_calendar_eventDestructive
Delete a calendardelete_google_calendarDestructive

Drive​

CapabilityToolsAccess
Find files and shared driveslist_google_drive_files, get_google_drive_file, list_google_shared_drivesRead only
Read and export file contentread_google_drive_file, export_google_drive_fileRead only
Read comments and revisionslist_google_drive_comments, list_google_drive_revisionsRead only
See who a file is shared withlist_google_drive_permissionsRead only
Track changes incrementallysync_google_drive_changesRead only
Create files and folderscreate_google_drive_fileWrite
Update metadata, copy and movesave_google_drive_fileWrite
Add a commentcreate_google_drive_commentWrite
Move a file to trashtrash_google_drive_fileDestructive
Change who can reach a fileshare_google_drive_fileDestructive, disabled by default

Directory​

CapabilityToolsAccess
Read the connected user's profileget_google_user_profileRead only
Look up people in your Workspace domainsearch_google_directory, list_google_directory_peopleRead only

Directory tools use the People API and read only the signed-in user's own Workspace domain. They carry no administrator capability and do not use the Admin SDK. They return nothing useful for a consumer Gmail account.

Destructive tools​

Seven destructive tools are enabled by default, each with the destructive annotation and tag, so you can hide them or require human approval as a class: send_gmail_message, trash_gmail_messages, delete_gmail_label, delete_gmail_draft, delete_google_calendar_event, delete_google_calendar, trash_google_drive_file.

Sending mail is irreversible. Trashing is recoverable until Google purges the item. Nothing in this MCP permanently deletes mail or files. share_google_drive_file is also destructive and is registered disabled; an operator must set GOOGLE_ENABLE_DRIVE_SHARING=true for your deployment to offer it. Even when Drive sharing is enabled, a grant to anyone is refused unless the call explicitly confirms it.

Setup​

1. Create the Google OAuth client​

  1. In the Google Cloud Console, create or select a project for the integration.
  2. In APIs & Services > Library, enable the Gmail API, Google Calendar API, Google Drive API and People API. Without the People API the directory tools fail.
  3. In APIs & Services > OAuth consent screen, choose Internal if every user is in your Workspace organization (no Google verification needed), or External for any Google account (restricted Gmail and Drive scopes then require Google OAuth verification, including the security assessment Google requires for restricted scopes, before the app can serve users outside its Test users list).
  4. Add the fifteen scopes below. The MCP accepts a token only if both openid and userinfo.email were granted; other tools return insufficient_scope if their product scope is missing.
  5. In APIs & Services > Credentials, click Create Credentials > OAuth client ID and choose Web application. Other client types do not work with the gateway callback.
  6. Under Authorized redirect URIs, add the OAuth callback URL shown on the Google Workspace setup screen in QuilrAI. It must match exactly; use a separate client per environment with a different callback.
  7. Click Create and copy the Client ID and Client Secret.
ScopeWhy it is neededGoogle class
openidMandatory. Without it Google returns no user identifier (sub) and the MCP rejects the token.Basic
.../auth/userinfo.emailMandatory. Identify the connected user.Basic
.../auth/userinfo.profileRead the user's own name and photo.Basic
.../auth/gmail.readonlySearch and read messages, threads and attachments.Restricted
.../auth/gmail.composeCreate and update drafts, and send mail.Restricted
.../auth/gmail.modifyApply and remove labels on messages, and trash them.Restricted
.../auth/gmail.labelsCreate, rename and delete labels.Sensitive
.../auth/calendar.calendarlist.readonlyList the user's calendars.Sensitive
.../auth/calendar.eventsRead, create, update and delete events, and RSVP.Sensitive
.../auth/calendar.freebusyCheck availability.Sensitive
.../auth/calendar.calendarsCreate, rename and delete calendars.Sensitive
.../auth/drive.metadata.readonlyRead file and shared-drive metadata.Restricted
.../auth/drive.readonlyRead and export file content.Restricted
.../auth/driveCreate, update, copy, move, trash and comment on files, and read permissions.Restricted
.../auth/directory.readonlyLook up people in the user's own Workspace domain.Sensitive

Each scope is prefixed https://www.googleapis.com. Google's OAuth 2.0 scopes page is authoritative for the classification.

Scope footprint grew

Earlier releases requested eight read-leaning scopes. The MCP now requests fifteen, including the restricted drive and gmail.modify scopes. A connection made with the old set keeps working for the tools its token covers and returns insufficient_scope for the rest until the user reconnects.

2. Install from the Library​

  1. Go to Settings > AI Gateway > MCP Gateway, click Library and find Google Workspace.
  2. Click Set up, enter the OAuth client ID and OAuth client secret, and click Install.
  3. Connect OAuth once as an administrator. At Google's consent screen, grant every scope, including openid.
  4. Enable the tools you need in Tool visibility.

For an External app that is not yet verified, add users under Test users on the consent screen so they can authorize.

Troubleshooting​

Tool failures return a JSON error with a code, the HTTP status, whether it is retryable, and a next_action.

ErrorLikely causeFix
redirect_uri_mismatchThe redirect URI in Google Cloud differs from the QuilrAI callback URL.Add the exact callback URL under Authorized redirect URIs and retry.
invalid_clientWrong client ID or secret, or a deleted secret.Copy both values again and update QuilrAI.
Access blocked: app has not been verifiedAn External app uses restricted scopes before verification.Add the user as a test user, complete verification, or use an Internal app.
Consent succeeds but every call returns 401openid was not granted.Reconnect and grant all scopes.
insufficient_scope from one productA scope is missing from the consent screen, or the connection predates it.Add the scope named in the error and reconnect.
insufficient_scope on every directory toolPeople API not enabled, or directory.readonly not granted.Enable the API, confirm the scope and reconnect.
not_found on a directory searchThe account is not in a Workspace domain.Directory lookups need a Workspace account.
sync_expired from a sync_* toolThe sync marker is older than Google's retention window.Start a fresh sync without a marker.
invalid_cursor when pagingThe cursor was altered, reused by another user, or the deployment lost its cursor signing secret.Re-run the query without a cursor.
share_google_drive_file is not listedThe tool is disabled by default.Ask Quilr to set GOOGLE_ENABLE_DRIVE_SHARING=true for your deployment.

References: Create an OAuth client ID, OAuth API verification FAQ, People API.

Compared with the official server​

Provider-native

Choose official for product-native breadth

Use Google's separate preview endpoints when the agent needs first-party product depth or a Workspace surface this MCP does not cover, such as Chat.

  • Provider-native endpoints
  • Google Chat coverage
Quilr-managed

Choose one combined connection

Use Quilr when Gmail, Calendar, Drive, and directory lookups should share customer-owned OAuth, one gateway boundary, and forty-two consistent tools.

  • Four surfaces, one connection
  • Governed writes, sync, and destructive controls
Decision signalOfficial endpoints reach Chat; Quilr minimizes connection and policy sprawl across the four surfaces agents use most.
CapabilityGmailCalendarDriveDirectory
Search and read✅✅✅✅
Multi-item and thread reads✅✅✅✅
Attachment and file-content reads✅-✅-
Incremental sync✅✅✅-
CreateDrafts, labelsEvents, calendarsFiles, folders, comments-
UpdateMessage labels, draftsEvents, calendars, RSVPMetadata, copy, move-
Availability lookup-✅--
Permission visibility--✅-
Move to trash, recoverable✅-✅-
Permanent deleteLabels, draftsEvents, calendars--
Irreversible sendSend email---
Change who can reach a file--Opt-in-

Google's official Workspace MCPs are separate product endpoints in Developer Preview and also cover Google Chat. Quilr is the combined, gateway-managed option for Gmail, Calendar, Drive and directory lookups.