Google Workspace
Four Workspace surfaces. One governed connection.
Forty-two tools for communication, scheduling, file operations, and people lookups with customer-owned Google OAuth.
Google Workspace is a Quilr-built MCP in the Library for Gmail, Google Calendar, Google Drive and Workspace directory lookups. There is no shared Quilr-owned Google client: each tenant connects with its own Google OAuth client.
Tools
42 tools are offered by default. One more, share_google_drive_file, is registered but disabled until a Quilr operator turns it on.
Gmail
Calendar
Drive
Directory
Directory tools use the People API and read only the signed-in user's own Workspace domain. They carry no administrator capability and do not use the Admin SDK. They return nothing useful for a consumer Gmail account.
Destructive tools
Seven destructive tools are enabled by default, each with the destructive annotation and tag, so you can hide them or require human approval as a class: send_gmail_message, trash_gmail_messages, delete_gmail_label, delete_gmail_draft, delete_google_calendar_event, delete_google_calendar, trash_google_drive_file.
Sending mail is irreversible. Trashing is recoverable until Google purges the item. Nothing in this MCP permanently deletes mail or files. share_google_drive_file is also destructive and is registered disabled; an operator must set GOOGLE_ENABLE_DRIVE_SHARING=true for your deployment to offer it. Even when Drive sharing is enabled, a grant to anyone is refused unless the call explicitly confirms it.
Setup
1. Create the Google OAuth client
- In the Google Cloud Console, create or select a project for the integration.
- In APIs & Services > Library, enable the Gmail API, Google Calendar API, Google Drive API and People API. Without the People API the directory tools fail.
- In APIs & Services > OAuth consent screen, choose Internal if every user is in your Workspace organization (no Google verification needed), or External for any Google account (restricted Gmail and Drive scopes then require Google OAuth verification, including the security assessment Google requires for restricted scopes, before the app can serve users outside its Test users list).
- Add the fifteen scopes below. The MCP accepts a token only if both
openidanduserinfo.emailwere granted; other tools returninsufficient_scopeif their product scope is missing. - In APIs & Services > Credentials, click Create Credentials > OAuth client ID and choose Web application. Other client types do not work with the gateway callback.
- Under Authorized redirect URIs, add the OAuth callback URL shown on the Google Workspace setup screen in QuilrAI. It must match exactly; use a separate client per environment with a different callback.
- Click Create and copy the Client ID and Client Secret.
Each scope is prefixed https://www.googleapis.com. Google's OAuth 2.0 scopes page is authoritative for the classification.
Earlier releases requested eight read-leaning scopes. The MCP now requests fifteen, including the restricted drive and gmail.modify scopes. A connection made with the old set keeps working for the tools its token covers and returns insufficient_scope for the rest until the user reconnects.
2. Install from the Library
- Go to Settings > AI Gateway > MCP Gateway, click Library and find Google Workspace.
- Click Set up, enter the OAuth client ID and OAuth client secret, and click Install.
- Connect OAuth once as an administrator. At Google's consent screen, grant every scope, including openid.
- Enable the tools you need in Tool visibility.
For an External app that is not yet verified, add users under Test users on the consent screen so they can authorize.
Troubleshooting
Tool failures return a JSON error with a code, the HTTP status, whether it is retryable, and a next_action.
References: Create an OAuth client ID, OAuth API verification FAQ, People API.
Compared with the official server
Choose official for product-native breadth
Use Google's separate preview endpoints when the agent needs first-party product depth or a Workspace surface this MCP does not cover, such as Chat.
- Provider-native endpoints
- Google Chat coverage
Choose one combined connection
Use Quilr when Gmail, Calendar, Drive, and directory lookups should share customer-owned OAuth, one gateway boundary, and forty-two consistent tools.
- Four surfaces, one connection
- Governed writes, sync, and destructive controls
Google's official Workspace MCPs are separate product endpoints in Developer Preview and also cover Google Chat. Quilr is the combined, gateway-managed option for Gmail, Calendar, Drive and directory lookups.