Skip to main content
Google publishes official managed remote MCP servers for Gmail, Drive, Docs, Sheets, Slides, and Calendar at https://<product>mcp.googleapis.com/mcp/v1. There is nothing to self-host - you enable the MCP services in a Google Cloud project, create a single OAuth client, and register each product as a remote MCP server in TrueFoundry. Each product is a separate MCP server, but all of them share one Google OAuth client. Outbound auth is OAuth2 Authorization Code with your own client, so every user authorizes their own Google account and only ever sees the Workspace data their Google permissions already allow.

Prerequisites

  • A TrueFoundry account with permission to add MCP servers, and your TrueFoundry control plane base URL.
  • A Google Cloud project where you can enable APIs and create OAuth credentials, enrolled in the Google Workspace Developer Preview Program. Enrollment is a hard blocker - see the note below.
  • Google Workspace admin access if your organization restricts which OAuth apps users may authorize. With strict API controls, an admin must trust this client before users can connect - see Save and authorize.
The Workspace MCP servers are in limited release. Until the Google Cloud project behind your OAuth client is enrolled in the Developer Preview Program, every tool call fails with a project not enrolled in the Google Workspace Developer Preview Program error, and the MCP services cannot be enabled on the project.Enrollment is tied to the Google Cloud project (along with the accounts registered with it), so enrolling the project once covers everyone who connects through that project’s shared OAuth client - individual users do not each apply. Anyone using a separate Cloud project of their own needs their own enrollment.To enroll: submit the application form with a Workspace-domain email - not a personal Gmail address or a service account - and your Google Cloud project number. Google then verifies your account, adds it to the program group, registers your project, and sends a confirmation email.After approval: the six MCP services become enable-able on the project. No TrueFoundry configuration changes are needed.
The scopes below are the read-oriented defaults from Google’s Configure the Workspace MCP servers guide. Drop the products and scopes you do not need, and see Adding write access before enabling anything that mutates Workspace data.

Set up the Google Cloud project

Do this once. Every MCP server you register later reuses the same project, consent screen, and OAuth client.
1

Select or create a Google Cloud project

In the Google Cloud Console, create a project or select an existing one and note the Project ID. See Create a Google Cloud project.
2

Enable the underlying Workspace APIs

Open this pre-filled Enable APIs link, pick your project, and click Enable. It enables the Gmail, Drive, Docs, Sheets, Slides, and Calendar APIs in one pass.You can also do it manually from APIs & Services > Library. See Enable Google Workspace APIs.
3

Enable the MCP services

Each product has a separate MCP API that must be enabled in addition to the product API above. This is the step most setups miss - a missing MCP service shows up later as 403 on every tool call.Open this pre-filled Enable APIs link and click Enable to turn on gmailmcp, drivemcp, docsmcp, sheetsmcp, slidesmcp, and calendarmcp.To enable them one at a time instead, open APIs & Services > Library, search for the service by name, and click Enable - or go straight to its page: gmailmcp, drivemcp, docsmcp, sheetsmcp, slidesmcp, and calendarmcp.
4

Configure the OAuth consent screen

Go to Google Auth Platform > Branding (click Get Started if the project has no consent screen yet) and fill in:Accept the policy and click Create. See Configure OAuth consent.
An External app left in Testing status has its refresh tokens expired by Google after roughly seven days, which forces every user to reconnect weekly. Use Internal, or publish the app, before rolling out to a team.
5

Add the OAuth scopes

Go to Google Auth Platform > Data Access > Add or Remove Scopes > Manually add scopes, paste the scopes for the products you are enabling, then click Add to Table > Update > Save.The scopes on the consent screen must cover the scopes you configure on each MCP server in TrueFoundry, otherwise consent fails with access_denied.
6

Create the OAuth client

Go to Google Auth Platform > Clients > Create Client and configure:Click Create, then copy the Client ID and Client Secret. See Create access credentials.
A wrong redirect URI is the most common cause of OAuth failures. Match your control plane host exactly - correct scheme, no trailing slash, no path changes. Create one client and reuse it for all six servers; do not create one client per product.

Scope reference

All scopes are prefixed with https://www.googleapis.com/auth/.

Adding write access

Google’s defaults are read-oriented, with a few exceptions worth knowing:
  • Gmail’s gmail.compose already covers creating and updating drafts.
  • Docs, Sheets, and Slides include the full documents, spreadsheets, and presentations scopes, which allow edits to files the user can already edit.
  • Calendar is read-only by default. To let agents create, update, or delete events, also add https://www.googleapis.com/auth/calendar.events to both the consent screen and the Calendar MCP server.
For a broad rollout, register the read-only scopes first and publish write-capable variants as separate Virtual MCP Servers scoped to trusted teams.

Register the servers in TrueFoundry

Repeat the steps below once per product. The OAuth endpoints and client credentials are identical every time - only the Name, URL, and Scopes change.
1

Add a remote MCP server

In TrueFoundry, open MCP Servers, click Add MCP Server, and select Connect any Remote MCP Server.
2

Fill in the shared OAuth configuration

These values are the same for all six servers:
Store the client secret as a TrueFoundry secret and reference it by its tfy-secret:// FQN instead of pasting the raw value into each of the six servers.
3

Fill in the per-product values

Enter scopes as fully qualified URLs, each prefixed with https://www.googleapis.com/auth/.
4

Add collaborators

Add the users or teams that should use the server. Assign MCP Server Manager to administrators and MCP Server User to consumers. See Access control.
5

Save and authorize

Click Add MCP Server. Each user then opens the server’s Tools tab and clicks Connect Now, signs in to their Google Account, and approves the requested scopes. The AI Gateway stores that user’s tokens and refreshes them automatically; access can be revoked from the same screen.
Strict org API controls can block authorization. If your organization restricts which apps may access Workspace data (Admin console > Security > Access and data control > API controls), users clicking Connect Now may hit Error 400: admin_policy_enforced. A Google Workspace super admin must either enable Trust internal, domain-owned apps, or open App Access Control > Manage Third-Party App Access, find this OAuth client by its Client ID, and set its access to Trusted. A regular user cannot resolve this themselves. See Control which apps access Workspace data. (This is distinct from org_internal, which means a user outside your domain is trying to authorize an Internal app - a consent-screen audience issue, not an API-controls one.)
If your TrueFoundry version discovers OAuth metadata from the remote MCP server, keep the discovered authorization and token URLs and supply only the Google client credentials and scopes.

Verify the connection

After Connect Now succeeds, the server’s Tools tab lists the product’s tools. Click Try on any tool to run it and inspect the JSON response, then test end to end from the Agent Playground. For the tools each server exposes, see Google’s references for Gmail, Drive, Docs, Sheets, Slides, and Calendar. If a connection or tool call fails, see the MCP troubleshooting guide.

Use Google Workspace safely with agents

  • Keep per-user OAuth so Gmail, Drive, Docs, and Calendar access always follows each user’s own Google Workspace permissions.
  • Prefer scoping individual data access over marking the app as broadly trusted in the Google Admin console. If your org uses Security > Access and data control > API controls, allowlist only the scopes listed above.
  • Keep the client secret in TrueFoundry secrets and rotate it if it is ever exposed.
  • Disable individual tools from the server’s Tools tab, or publish a Virtual MCP Server exposing only the tools an agent needs.
  • Apply guardrails and tool approval to write-capable tools such as Gmail draft creation or Calendar event changes.
Google Chat (https://chatmcp.googleapis.com/mcp/v1) and the People API (https://people.googleapis.com/mcp/v1) follow exactly the same pattern if you add them later, reusing the same OAuth client and consent screen. Chat additionally requires a Chat app configured in the Google Cloud Console.