{"slug": "mcp-configuration-for-google-workspace-with-claude-code", "title": "MCP Configuration for Google Workspace with Claude Code", "summary": "A developer published a Claude Code skill and plugin that automates connecting Google Workspace's eight remote MCP servers — Gmail, Drive, Docs, Sheets, Slides, Calendar, Chat and People — to Claude Code, enabling the required APIs, registering the servers, handling OAuth sign-in and testing each one. All eight servers passed a read-only test, though the setup is limited by roughly one-hour sign-in sessions and a People sign-in that revokes previously issued tokens, so People must be authenticated first.", "body_md": "This article provides a step by step configuration guide for the Google Workspace remote MCP servers with Claude Code. The setup is packaged as a Claude Code skill and plugin, so Claude Code can enable the APIs, register the servers, sign in, and test all eight of them.\n\n[https://github.com/xbill9/workspace-mcp-claude](https://github.com/xbill9/workspace-mcp-claude)\n\n**All eight Workspace servers pass a read-only test from Claude Code. Two sign-in limits shape how you use them: each sign-in lasts about an hour, and signing People in again revokes every token issued before it, so People always goes first.**\n\nYes! The first two versions of this setup used Gemini CLI and Antigravity CLI:\n\n[MCP Configuration for Google Workspace with Gemini CLI](https://medium.com/google-cloud/mcp-configuration-for-google-workspace-with-gemini-cli-ead9ebdc5903)\n\n[MCP Configuration for Google Workspace with Antigravity CLI](https://dev.to/gde/mcp-configuration-for-google-workspace-with-antigravity-cli-3f34)\n\nThis version moves the same Google Cloud project to Claude Code, brings in the three newer servers (Docs, Sheets and Slides) and Chat, which the earlier config files left out, and packages it all as a Claude Code skill.\n\nGoogle hosts one remote MCP server per Workspace product. Getting Claude Code connected takes a Google Cloud project with the right APIs, an OAuth web client, a few console settings, the servers registered in Claude Code, and a browser sign-in per server.\n\nThe repository turns that into scripts and a skill. The scripts do everything that has an API. The skill tells Claude Code how to check what is already done, run the scripts, walk through the console steps, and test the result.\n\nGoogle Workspace is Google's subscription productivity suite: Gmail, Drive, Docs, Sheets, Slides, Calendar, Chat and Meet on a custom domain, with admin controls and shared storage.\n\n[Google Workspace: Secure Online Productivity & Collaboration Tools](https://workspace.google.com/)\n\nWorkspace MCP support is in Developer Preview. Sign up here before starting:\n\n[Google Workspace Developer Preview Program](https://developers.google.com/workspace/preview)\n\n`gcloud`), signed in.\n\n```\ncd ~\ngit clone https://github.com/xbill9/workspace-mcp-claude\ncd workspace-mcp-claude\n```\n\n| Server | URL | Tools | \n|---|---|---|\n| gmail | `https://gmailmcp.googleapis.com/mcp/v1` | 23 | \n| drive | `https://drivemcp.googleapis.com/mcp/v1` | 8 | \n| docs | `https://docsmcp.googleapis.com/mcp/v1` | 2 | \n| sheets | `https://sheetsmcp.googleapis.com/mcp/v1` | 6 | \n| slides | `https://slidesmcp.googleapis.com/mcp/v1` | 4 | \n| calendar | `https://calendarmcp.googleapis.com/mcp/v1` | 9 | \n| chat | `https://chatmcp.googleapis.com/mcp/v1` | 4 | \n| people | `https://people.googleapis.com/mcp/v1` | 3 | \n\nA ninth server, `workspace-developer` at `https://workspace-developer.goog/mcp`, searches the Workspace developer docs and needs no sign-in. The tool counts come from `mcp_probe.sh`, shown later.\n\nEach product needs its API and its MCP service. People serves MCP from `people.googleapis.com`, so the total is 15 services. `bootstrap.sh` enables them with gcloud:\n\n```\n./bootstrap.sh\nUpdated property [core/project].\nEnabling Workspace APIs and MCP services on comglitn\nOperation \"operations/acat.p2-<project-number>-d46329d0-40b5-4232-a430-c43e10731dc2\" finished successfully.\n```\n\nWhen gcloud cannot sign in from the current shell, one console URL enables all 15 at once:\n\n```\nhttps://console.cloud.google.com/flows/enableapi?apiid=gmail.googleapis.com,drive.googleapis.com,docs.googleapis.com,sheets.googleapis.com,slides.googleapis.com,calendar-json.googleapis.com,chat.googleapis.com,people.googleapis.com,gmailmcp.googleapis.com,drivemcp.googleapis.com,docsmcp.googleapis.com,sheetsmcp.googleapis.com,slidesmcp.googleapis.com,calendarmcp.googleapis.com,chatmcp.googleapis.com&project=PROJECT_ID\n```\n\nIn the Google Cloud console, open **Google Auth Platform → Branding** and click **Get Started** if it is not configured. Name the app `Workspace MCP Servers`, pick **Internal** for the audience, and add a contact email.\n\nThen **Data Access → Add or remove scopes → Manually add scopes**, and paste the scopes for the servers you want. Prefix each with `https://www.googleapis.com/auth/`:\n\n| Server | Scopes | \n|---|---|\n| gmail | `gmail.readonly` ,`gmail.compose` | \n| drive | `drive.readonly` ,`drive.file` | \n| docs | drive scopes, `documents.readonly` ,`documents` | \n| sheets | drive scopes, `spreadsheets.readonly` ,`spreadsheets` | \n| slides | drive scopes, `presentations.readonly` ,`presentations` | \n| calendar | `calendar.calendarlist.readonly` ,`calendar.events.freebusy` ,`calendar.events.readonly` | \n| chat | `chat.spaces.readonly` ,`chat.memberships.readonly` ,`chat.messages.readonly` ,`chat.messages.create` ,`chat.users.readstate` | \n| people | `directory.readonly` ,`userinfo.profile` ,`contacts.readonly` | \n\nThat is 21 distinct scopes. The sensitive-scopes table on the Data Access page shows 10 rows per page, so three of them land on page 2.\n\n**Google Auth Platform → Clients → Create Client**. Pick **Web application** and add two authorized redirect URIs:\n\n`http://localhost:8765/callback` for Claude Code. The port matches `CALLBACK_PORT` in the scripts.`https://claude.ai/api/mcp/auth_callback` for claude.ai and Claude Desktop custom connectors.\nLeave \"This client will be used by an AI-powered agent\" unticked. Google's guide leaves it off.\n\nThe Chat server needs a Chat app in the project. Open **Google Chat API → Manage → Configuration** and set:\n\n`Chat MCP`\n`https://developers.google.com/chat/images/quickstart-app-avatar.png`\n`Chat MCP server`\nLeave \"Build this Chat app as a Workspace add-on\" as it is. Clearing it cannot be undone.\n\nThe console shows a client secret once, when it is created. On a later visit the client page says viewing and downloading secrets is no longer available, and **Add secret** creates a new one with a download button.\n\nThe download lands in `~/Downloads` as `client_secret_<client-id>.json` or `client_secret_<n>_<client-id>.json`. `bootstrap.sh` picks up the newest one.\n\n`bootstrap.sh` installs the client from the downloaded JSON into `~/client_id.txt` and `~/client_secret.txt` (mode 600, never printed), then registers the servers with `claude mcp add-json`:\n\n```\n./bootstrap.sh --no-apis --no-login\nInstalling OAuth client from /home/xbill/Downloads/client_secret_2_<project-number>-<client>.apps.googleusercontent.com.json\nSaved client <project-number>-… to ~/client_id.txt and ~/client_secret.txt\nAdding Workspace MCP servers to Claude Code (scope: local)\nRedirect URI required on the OAuth client: http://localhost:8765/callback\n\ngmail: https://gmailmcp.googleapis.com/mcp/v1 (HTTP) - ✔ Connected\ndrive: https://drivemcp.googleapis.com/mcp/v1 (HTTP) - ✔ Connected\ndocs: https://docsmcp.googleapis.com/mcp/v1 (HTTP) - ✔ Connected\nsheets: https://sheetsmcp.googleapis.com/mcp/v1 (HTTP) - ✔ Connected\nslides: https://slidesmcp.googleapis.com/mcp/v1 (HTTP) - ✔ Connected\ncalendar: https://calendarmcp.googleapis.com/mcp/v1 (HTTP) - ✔ Connected\nchat: https://chatmcp.googleapis.com/mcp/v1 (HTTP) - ✔ Connected\npeople: https://people.googleapis.com/mcp/v1 (HTTP) - ! Needs authentication\nworkspace-developer: https://workspace-developer.goog/mcp (HTTP) - ✔ Connected\n```\n\nEach server gets its scopes pinned in `oauth.scopes` and the fixed callback port. Claude Code keeps the client secret in its own credential store, so nothing secret reaches `.mcp.json` or `~/.claude.json`.\n\n`MCP_SCOPE` picks where the servers live: `user` (the default, every project), `local` (this directory only) or `project` (a shared `.mcp.json`).\n\nSign in People before the other seven. A repeat People sign-in revokes every token issued before it, so the order matters every time you sign in again. The known issues below have the measurements.\n\nFrom your own terminal, in the repository directory:\n\n```\nfor s in people gmail drive docs sheets slides calendar chat; do claude mcp login $s; done\n```\n\nOr run `/mcp` inside Claude Code and pick **Authenticate** on each server, People first.\n\nClaude Code can also do it for you through the Chrome extension. `claude mcp login` needs a terminal, so `mcp_login.sh` runs it under a pseudo-terminal and prints the Google sign-in URL for Claude to open. `check` confirms once **Allow** has been clicked:\n\n```\n./mcp_login.sh start people\n./mcp_login.sh check people\nhttps://accounts.google.com/o/oauth2/v2/auth?response_type=code&client_id=<id>&code_challenge=<…>&code_challenge_method=S256&redirect_uri=http%3A%2F%2Flocalhost%3A8765%2Fcallback&state=<…>&scope=https%3A%2F%2Fwww.googleapis.com%2Fauth%2Fdirectory.readonly+https%3A%2F%2Fwww.googleapis.com%2Fauth%2Fuserinfo.profile+https%3A%2F%2Fwww.googleapis.com%2Fauth%2Fcontacts.readonly&resource=https%3A%2F%2Fpeople.googleapis.com%2Fmcp\nSigned in: people\n```\n\nThe consent page is a grant of access to your mail, files and calendar. Check the permissions it lists against the scope table before clicking **Allow**.\n\n`mcp_status.sh` lists each server's sign-in. `--verify` asks Google whether each token is still accepted, printing only valid or invalid:\n\n```\n./mcp_status.sh --verify\nserver    registered  token    min left  refresh\ngmail     yes         valid          50  no\ndrive     yes         valid          51  no\ndocs      yes         valid          52  no\nsheets    yes         valid          53  no\nslides    yes         valid          54  no\ncalendar  yes         valid          54  no\nchat      yes         valid          55  no\npeople    yes         valid          49  no\n\n8 of 8 servers hold a token Google accepts.\nTokens without refresh expire after about an hour; sign in again with /mcp or mcp_login.sh when they do.\n```\n\n`mcp_test.sh` runs one headless Claude Code session allowed only read-only tools, asks it to make one call per server, and grades each server from the tool results in the session's event stream. The model's own summary plays no part in the grade:\n\n```\n./mcp_test.sh\nTesting: gmail drive docs sheets slides calendar chat people\n\nserver    result            ok  err  tools\ngmail     PASS               1    0  list_labels\ndrive     PASS               4    0  list_recent_files, search_files\ndocs      PASS               1    0  read_doc\nsheets    PASS               1    0  get_spreadsheet\nslides    PASS               1    0  read_presentation\ncalendar  PASS               1    0  list_calendars\nchat      PASS               1    0  search_conversations\npeople    PASS               1    0  get_user_profile\n\n8 of 8 servers passed.\nexit=0\n```\n\nDrive shows four calls because its file search also finds the Doc, Sheet and Slides deck the next three checks read. `./mcp_test.sh slides` tests one server.\n\nWith the servers signed in, restart Claude Code in the repository directory so their tools load, and ask in plain language. Each demo below shows the prompt, the tools Claude Code called, and its answer. They come from `docs/article/run-demo.sh`, which runs a prompt through a headless session limited to the tools named after it.\n\n```\ndocs/article/run-demo.sh \"According to my Google profile, what is my name?\" \"mcp__people__get_user_profile\"\n> According to my Google profile, what is my name?\n\n  ✅ mcp__people__get_user_profile\n\nYour Google profile name is **xbill work** (account xbill@glitnir.com).\n```\n\nTwo servers work together here: Drive finds the newest presentation and Slides reads it.\n\n```\ndocs/article/run-demo.sh \"Find my most recent Google Slides presentation and give me its title, its slide count, and a three-bullet summary of what it covers.\" \"mcp__drive__search_files,mcp__slides__read_presentation\"\n> Find my most recent Google Slides presentation and give me its title, its slide count, and a three-bullet summary of what it covers.\n\n  ✅ mcp__drive__search_files\n  ✅ mcp__drive__search_files\n  ✅ mcp__slides__read_presentation\n  ✅ Bash  echo \"30_37 12_0 30_0 30_8 30_13 30_19 30_25 30_43 30_51 30_57 30_63 30_68 30_73 30_78 30_83 30_92 30_88 30_97 30_102 30_107 30_113 30_118 30_136 30_142 30_162 5_0 30_153 30_158 32_0\" | wc -w\n\nYour most recent presentation is **Gemma4 Local**. It was last modified 2026-10-01 and you last opened it today. A Drive search for presentations modified after that date returned only this deck, so nothing newer exists.\n\n- **Title:** Gemma4 Local. The subtitle is \"Deploying next-generation open-weights models on local hardware environments.\"\n- **Slide count:** 29. I counted the slide IDs the Slides API returned with `wc`. Eight of the 29 slides have no text, so they're probably images or screenshots. The summary below comes from the text on the other slides.\n\n**What it covers:**\n- **The Gemma 4 model family.** It explains what Gemma is: open weights under the Apache license, and a separate model from Gemini. It then goes through the sizes: E2B and E4B for edge devices, the 26B A4B mixture-of-experts model, and the 31B dense model. It also includes two newer additions: the 12B mid-size model and quantization-aware training (QAT) to shrink the weights for low-end hardware.\n- **Ways to access and host it.** Options include AI Studio, Model Garden, local hosting (Ollama, vLLM, Docker, Edge Gallery on mobile) and Google Cloud. On Google Cloud that means TPUs (v5e, v5p, v6e, Ironwood), Cloud Run with L4 or 96 GB GPUs, VMs with attached GPUs, and GKE.\n- **Live demos and next steps.** The demos are a self-contained Tesla T4 VM on Google Cloud and a 4 GB laptop GPU running a QAT model, plus others in the repo across Cloud Run, GKE, TPU, AWS and Azure. The \"Future\" slide lists a vLLM QAT TPU pull request, a v5e deep dive, a v6e comparison, QAT and GGUF repacks, JAX on AWS Inf2, and a \"lite\" GKE demo.\n\nThe deck opens with your speaker slides (bio, where to find you, recent articles). [link to the deck removed]\n```\n\nClaude counted the slides with `wc` over the IDs Slides returned, so the 29 comes from the tool output.\n\nAsk for the count Gmail's own search returns, so the number comes from Gmail:\n\n```\ndocs/article/run-demo.sh \"How many unread threads are in my Gmail inbox? Use the count the Gmail search returns rather than counting results yourself. Reply with the number and the query you used, and nothing about the individual emails.\" \"mcp__gmail__search_threads\"\n> How many unread threads are in my Gmail inbox? Use the count the Gmail search returns rather than counting results yourself. Reply with the number and the query you used, and nothing about the individual emails.\n\n  ✅ mcp__gmail__search_threads\n\nGmail's search returned **2** unread threads in your inbox.\n\n- **Query:** `in:inbox is:unread`\n- **Count:** `resultCountEstimate: \"2\"`. That's the number Gmail reported, and it's labelled an estimate.\n\nOne of the two threads that came back no longer has the `UNREAD` label, so it was probably read recently and the search index hasn't caught up. The live number may be 1.\n```\n\nCalendar's `suggest_time` searches for free time. The pinned Calendar scopes are read-only, so nothing can be booked:\n\n```\ndocs/article/run-demo.sh \"Suggest a free 30-minute slot for a meeting tomorrow afternoon on my primary calendar. Read only, do not create anything.\" \"mcp__calendar__list_calendars,mcp__calendar__suggest_time\"\n> Suggest a free 30-minute slot for a meeting tomorrow afternoon on my primary calendar. Read only, do not create anything.\n\n  ✅ mcp__calendar__list_calendars\n  ✅ mcp__calendar__list_events\n  ✅ mcp__calendar__suggest_time\n\nI suggest **Monday, October 5, 2:00–2:30 PM Eastern**.\n\nYour primary calendar (xbill@glitnir.com, Eastern time) has one event tomorrow afternoon: **[TPU] Office Hours, 1:30–2:00 PM**. I asked Calendar's free-time search for openings between noon and 5 PM, and it returned two:\n\n- 🟢 **12:00–1:30 PM** (90 minutes)\n- 🟢 **2:00–5:00 PM** (3 hours)\n\nI picked 2:00 PM because it starts the longest open stretch, so the meeting can run over without a conflict. 12:00–12:30 is also free if you'd rather go before the office hours.\n\n⚠️ You haven't responded to the TPU Office Hours invite yet, but Calendar still counts it as busy. If you skip it, 12:00–5:00 is open, apart from that one half-hour.\n\nThis only read your calendar. I didn't create or change anything.\n```\n\nThe 2026-07-28 MCP specification makes the protocol stateless: a `server/discover` request replaces the `initialize` handshake. `mcp_probe.sh` checks each server with no credentials:\n\n```\n./mcp_probe.sh\nserver    2026-07-28  legacy init  tools\ngmail     yes         2025-11-25   23\ndrive     yes         2025-11-25   8\ndocs      yes         2025-11-25   2\nsheets    yes         2025-11-25   6\nslides    yes         2025-11-25   4\ncalendar  yes         2025-11-25   9\nchat      yes         2025-11-25   4\npeople    no          2025-11-25   3\n\n7 of 8 servers advertise 2026-07-28; 59 tools in total.\n```\n\nSeven servers advertise 2026-07-28 and Claude Code connects to those at that version. People answers only the 2025-11-25 handshake. All eight accept 2025-11-25, so any current MCP client connects.\n\nThe repository is also a Claude Code plugin marketplace. Install the `google-workspace-mcp` skill from inside Claude Code:\n\n```\n/plugin marketplace add xbill9/workspace-mcp-claude\n/plugin install google-workspace-mcp@workspace-mcp-claude\n```\n\nTo try it from a clone without installing, start Claude Code with `claude --plugin-dir ~/workspace-mcp-claude/plugin`. The skill finds its scripts relative to its own directory either way. The manifests and the skill validate:\n\n```\nclaude plugin validate .\nclaude plugin validate plugin\nclaude plugin validate plugin/skills\nValidating marketplace manifest: /home/xbill/workspace-mcp-claude/.claude-plugin/marketplace.json\n\n✔ Validation passed\nValidating plugin manifest: /home/xbill/workspace-mcp-claude/plugin/.claude-plugin/plugin.json\n\n✔ Validation passed\nValidating components in: /home/xbill/workspace-mcp-claude/plugin/skills\n\n✔ Validation passed\n```\n\nThe skill loads when a request is about connecting, signing in to, testing or fixing the Workspace servers, even when it never says \"MCP\":\n\n| Ask | What the skill does | \n|---|---|\n| \"Connect my Gmail and Drive to Claude Code\" | checks what exists, then walks the missing steps in order | \n| \"Is my Google Workspace MCP setup working?\" | runs `mcp_status.sh --verify` and`mcp_test.sh` | \n| \"My Gmail tools disappeared\" | checks for revoked or expired tokens and says which servers to sign in again | \n| \"Sign my Workspace servers back in\" | People first, then the other seven | \n| \"Gmail says insufficient_scope\" | names the scope to add in `claude_setup.sh` and on the consent screen | \n\nIt always starts by finding out what is already done, because setup is usually half finished: a project with the APIs on, a client from an earlier tool, servers registered for another directory.\n\nAsked from the home directory, with no setup files in sight, the skill loads, finds the servers registered for the repository directory, and checks them without changing anything. Trimmed:\n\n```\n> Is my Google Workspace MCP setup for Claude Code working? Check it, but do not sign anything in or change anything.\n\n  ✅ Skill  google-workspace-mcp:google-workspace-mcp\n  ✅ Bash  \"/home/xbill/workspace-mcp-claude/plugin/skills/google-workspace-mcp/scripts/mcp_status.sh\" --verify; …\n  ✅ Bash  claude mcp list 2>&1 | head -40; …\n  ✅ Bash  cd /home/xbill/workspace-mcp-claude && \"/home/xbill/workspace-mcp-claude/plugin/skills/google-workspace-mcp/scripts/mcp_test.sh\"; …\n\nYes, it works. All eight Workspace servers answered a real read-only call, and Google accepts all eight sign-ins. I didn't sign in or change anything.\n\n**Sign-ins** (`mcp_status.sh --verify`): all 8 servers are registered and Google accepts all 8 tokens. They have about 38–43 minutes left (People and Gmail run out first), with no refresh token. After that they show \"Needs authentication\", and you'll need to sign in again with `/mcp`. Sign in to People first, because a repeat People sign-in makes Google revoke the tokens of the other servers.\n\n- **The servers only exist in `~/workspace-mcp-claude`.** They're registered with `local` scope, so from any other directory (including `~`, where I started) `claude mcp list` doesn't show them and their tools aren't available. If you want Gmail and Drive everywhere, re-register them with `MCP_SCOPE=user`.\n```\n\nMoving the servers to `user` scope drops their sign-ins and their client secret, because both are stored per server name. Remove the `local` copies, run `MCP_SCOPE=user ./claude_setup.sh` once more, then sign in to all eight again, People first.\n\n| File | Purpose | \n|---|---|\n| `SKILL.md` | the workflow: check first, then APIs, console, secret, register, sign in, test | \n| `scripts/bootstrap.sh` | APIs, client install, registration, sign-in (People first) | \n| `scripts/claude_setup.sh` | registers the eight servers plus `workspace-developer` with pinned scopes | \n| `scripts/mcp_login.sh` | sign-in without a terminal: prints the Google URL, then confirms | \n| `scripts/mcp_status.sh` | sign-in state per server; `--verify` asks Google | \n| `scripts/mcp_test.sh` | one read-only call per server, graded from the tool results | \n| `scripts/mcp_probe.sh` | MCP versions and tool lists, no credentials needed | \n| `references/console-setup.md` | the console steps, with the exact URLs and settings | \n| `references/servers.md` | server URLs, the 21 scopes, tool lists | \n| `references/known-issues.md` | the two sign-in limits, with the measurements | \n| `references/quirks.md` | every other quirk seen during setup | \n\nThe scripts at the repository root are wrappers around these, so a plain clone works the same way.\n\nThe skill stops at three points, each for a reason:\n\nGoogle issues these sign-ins without a refresh token, so Claude Code cannot renew them. Every Workspace entry in Claude Code's credential store has an access token and an expiry one hour after sign-in, and no refresh token.\n\nThe authorization URL Claude Code builds carries `response_type`, `client_id`, PKCE, `redirect_uri`, `state`, `scope` and `resource`. Google issues a refresh token only when the request also asks for offline access (`access_type=offline`), and Claude Code's `oauth` settings (`clientId`, `callbackPort`, `scopes`, `authServerMetadataUrl`) have no field that adds it.\n\nPlan for a fresh sign-in each working hour. `mcp_status.sh` shows the minutes left.\n\nSigning People in again makes Google revoke the token of every server signed in before it, while those tokens still have most of their hour left. Sign-ins for the other seven revoke nothing. Each row below was checked with Google's token-info endpoint:\n\n| Sign-in order | Tokens Google accepts afterwards | \n|---|---|\n| All eight, People last, first sign-in for each | 8 of 8 ✅ | \n| People again | People only ❌ | \n| All eight again, People last | 7 valid until People, then People only ❌ | \n| People first, then the other seven | 8 of 8 ✅ | \n\nPeople's repeat sign-in shows one extra step: a \"Sign in to Workspace MCP Servers\" page with your name and profile picture, and a `profile` scope added to the grant. Why Google revokes the other tokens is unconfirmed.\n\nA revoked server is hard to spot. `claude mcp list` still shows it `✔ Connected`, the stored expiry still shows minutes left, and in a session its tools are simply missing. Claude Code's debug log has the reason:\n\n```\n[DEBUG] MCP server \"slides\": Connection error: Unauthorized\n[ERROR] MCP server \"slides\" Failed to fetch tools: Unauthorized\n```\n\n`mcp_status.sh --verify` reports such a token as `revoked`. `bootstrap.sh` and the skill sign People in first.\n\nAll eight servers list their tools without any token, and seven of them accept Claude Code's connection without one too. So `claude mcp list` shows those seven `✔ Connected` before you sign in and after a token is revoked. People asks Claude Code for a sign-in and shows `! Needs authentication`.\n\nUse `mcp_status.sh --verify` for sign-in state and `mcp_test.sh` for working tools.\n\nEach server publishes the scopes it accepts. Gmail's list has 11, starting with `https://mail.google.com/`, full mailbox access. Without pinned scopes, Claude Code requests what the server's metadata or a `401` response suggests.\n\n`claude_setup.sh` pins the scopes from Google's guide for every server. Gmail exposes 23 tools against the 10 the guide lists, and the extra trash, spam and label-editing tools need scopes outside the pinned set. They fail with `insufficient_scope` until you widen that server's entry and sign it in again.\n\nWhen Claude drives the sign-in through Chrome, Google's \"Choose an account\" page often stays put after the first click on the account. Click the account and press Enter, and repeat once if the chooser is still showing.\n\nChat's consent page lists five permissions and puts **Allow** below the fold, so scroll first. The skill's `references/quirks.md` lists every quirk seen during setup.\n\nClaude Code's auto mode refuses to read the client secret from the console or from its downloaded file, and refuses to click **Add secret**. Allowing the tool in `/permissions` leaves that check in place.\n\nSo the secret takes one human step: you download it, and `bootstrap.sh` copies it into `~/client_secret.txt` without printing it. Delete the downloaded JSON afterwards.\n\n|  | Gemini CLI | Antigravity CLI | Claude Code | \n|---|---|---|---|\n| Server config | `.gemini/settings.json` ,`httpUrl` | `mcp_config.json` ,`serverUrl` | `claude mcp add-json` ,`type: http` | \n| Client secret | `${CLIENT_SECRET}` from the environment | written into the config file (no variable substitution) | Claude Code's credential store | \n| Redirect URI | see the Gemini CLI article | `https://antigravity.google/oauth-callback` | `http://localhost:8765/callback` | \n| Scopes | listed per server | listed per server | pinned per server in `oauth.scopes` | \n| Sign-in | `/mcp auth <server>` | `/mcp` → Authenticate | `/mcp` ,`claude mcp login` , or`mcp_login.sh` | \n\nclaude.ai and Claude Desktop take the same eight URLs as custom connectors (**Settings → Connectors → Add custom connector**), with the OAuth client ID and secret under **Advanced settings** and `https://claude.ai/api/mcp/auth_callback` as the redirect URI.\n\nFor terminal work in Claude Code, the `google-workspace-mcp` skill. It registers all eight servers with pinned scopes, keeps the secret out of config files, signs People in first, and proves the result with a read-only test.\n\nPlan around the hourly sign-in. `mcp_status.sh --verify` at the start of a session tells you which servers need it, and People first keeps one sign-in from undoing the others.\n\nThe goal of this article was to connect Claude Code to Google's eight remote Workspace MCP servers and package the setup as a Claude Code skill. The key to the solution was scripting every step that has an API, documenting the console steps that do not, and grading the result from tool calls. The results were:\n\nScope: one Google Workspace account in the Developer Preview, one Google Cloud project with an Internal consent screen and one Web application OAuth client shared by all eight servers, Claude Code 2.1.289 on Linux, checked on 2026-10-04 and 2026-10-05. The revocation was reproduced twice with Google's token-info endpoint; its cause on Google's side is unconfirmed. Separate OAuth clients per server and claude.ai connectors were not tested.\n\nThe strategy for using MCP with Google Workspace from Claude Code was validated with an incremental step by step approach.", "url": "https://wpnews.pro/news/mcp-configuration-for-google-workspace-with-claude-code", "canonical_source": "https://dev.to/gde/mcp-configuration-for-google-workspace-with-claude-code-11om", "published_at": "2026-10-05 13:42:33+00:00", "updated_at": "2026-10-05 13:48:41.601358+00:00", "lang": "en", "topics": ["ai-agents", "agent-protocols", "ai-tools", "developer-tools"], "entities": ["Google Workspace", "Claude Code", "Anthropic", "Google", "Gmail", "Google Drive", "Google Docs", "Google Cloud"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/mcp-configuration-for-google-workspace-with-claude-code", "markdown": "https://wpnews.pro/news/mcp-configuration-for-google-workspace-with-claude-code.md", "text": "https://wpnews.pro/news/mcp-configuration-for-google-workspace-with-claude-code.txt", "jsonld": "https://wpnews.pro/news/mcp-configuration-for-google-workspace-with-claude-code.jsonld"}}