https://<product>mcp.googleapis.com/mcp/v1. There is nothing to self-host - you enable the MCP services in a Google Cloud project, create a single OAuth client, and register each product as a remote MCP server in TrueFoundry.
Each product is a separate MCP server, but all of them share one Google OAuth client. Outbound auth is OAuth2 Authorization Code with your own client, so every user authorizes their own Google account and only ever sees the Workspace data their Google permissions already allow.
Prerequisites
- A TrueFoundry account with permission to add MCP servers, and your TrueFoundry control plane base URL.
- A Google Cloud project where you can enable APIs and create OAuth credentials, enrolled in the Google Workspace Developer Preview Program. Enrollment is a hard blocker - see the note below.
- Google Workspace admin access if your organization restricts which OAuth apps users may authorize. With strict API controls, an admin must trust this client before users can connect - see Save and authorize.
The Workspace MCP servers are in limited release. Until the Google Cloud project behind your OAuth client is enrolled in the Developer Preview Program, every tool call fails with a
project not enrolled in the Google Workspace Developer Preview Program error, and the MCP services cannot be enabled on the project.Enrollment is tied to the Google Cloud project (along with the accounts registered with it), so enrolling the project once covers everyone who connects through that project’s shared OAuth client - individual users do not each apply. Anyone using a separate Cloud project of their own needs their own enrollment.To enroll: submit the application form with a Workspace-domain email - not a personal Gmail address or a service account - and your Google Cloud project number. Google then verifies your account, adds it to the program group, registers your project, and sends a confirmation email.After approval: the six MCP services become enable-able on the project. No TrueFoundry configuration changes are needed.The scopes below are the read-oriented defaults from Google’s Configure the Workspace MCP servers guide. Drop the products and scopes you do not need, and see Adding write access before enabling anything that mutates Workspace data.
Set up the Google Cloud project
Do this once. Every MCP server you register later reuses the same project, consent screen, and OAuth client.1
Select or create a Google Cloud project
In the Google Cloud Console, create a project or select an existing one and note the Project ID. See Create a Google Cloud project.
2
Enable the underlying Workspace APIs
Open this pre-filled Enable APIs link, pick your project, and click Enable. It enables the Gmail, Drive, Docs, Sheets, Slides, and Calendar APIs in one pass.You can also do it manually from APIs & Services > Library. See Enable Google Workspace APIs.
3
Enable the MCP services
Each product has a separate MCP API that must be enabled in addition to the product API above. This is the step most setups miss - a missing MCP service shows up later as
403 on every tool call.Open this pre-filled Enable APIs link and click Enable to turn on gmailmcp, drivemcp, docsmcp, sheetsmcp, slidesmcp, and calendarmcp.To enable them one at a time instead, open APIs & Services > Library, search for the service by name, and click Enable - or go straight to its page: gmailmcp, drivemcp, docsmcp, sheetsmcp, slidesmcp, and calendarmcp.4
Configure the OAuth consent screen
Go to Google Auth Platform > Branding (click Get Started if the project has no consent screen yet) and fill in:
Accept the policy and click Create. See Configure OAuth consent.
5
Add the OAuth scopes
Go to Google Auth Platform > Data Access > Add or Remove Scopes > Manually add scopes, paste the scopes for the products you are enabling, then click Add to Table > Update > Save.The scopes on the consent screen must cover the scopes you configure on each MCP server in TrueFoundry, otherwise consent fails with
access_denied.6
Create the OAuth client
Go to Google Auth Platform > Clients > Create Client and configure:
Click Create, then copy the Client ID and Client Secret. See Create access credentials.
Scope reference
All scopes are prefixed withhttps://www.googleapis.com/auth/.
Adding write access
Google’s defaults are read-oriented, with a few exceptions worth knowing:- Gmail’s
gmail.composealready covers creating and updating drafts. - Docs, Sheets, and Slides include the full
documents,spreadsheets, andpresentationsscopes, which allow edits to files the user can already edit. - Calendar is read-only by default. To let agents create, update, or delete events, also add
https://www.googleapis.com/auth/calendar.eventsto both the consent screen and the Calendar MCP server.
Register the servers in TrueFoundry
Repeat the steps below once per product. The OAuth endpoints and client credentials are identical every time - only the Name, URL, and Scopes change.1
Add a remote MCP server
In TrueFoundry, open MCP Servers, click Add MCP Server, and select Connect any Remote MCP Server.
2
Fill in the shared OAuth configuration
These values are the same for all six servers:
3
Fill in the per-product values
Enter scopes as fully qualified URLs, each prefixed with
https://www.googleapis.com/auth/.4
Add collaborators
Add the users or teams that should use the server. Assign MCP Server Manager to administrators and MCP Server User to consumers. See Access control.
5
Save and authorize
Click Add MCP Server. Each user then opens the server’s Tools tab and clicks Connect Now, signs in to their Google Account, and approves the requested scopes. The AI Gateway stores that user’s tokens and refreshes them automatically; access can be revoked from the same screen.
Verify the connection
After Connect Now succeeds, the server’s Tools tab lists the product’s tools. Click Try on any tool to run it and inspect the JSON response, then test end to end from the Agent Playground. For the tools each server exposes, see Google’s references for Gmail, Drive, Docs, Sheets, Slides, and Calendar. If a connection or tool call fails, see the MCP troubleshooting guide.Use Google Workspace safely with agents
- Keep per-user OAuth so Gmail, Drive, Docs, and Calendar access always follows each user’s own Google Workspace permissions.
- Prefer scoping individual data access over marking the app as broadly trusted in the Google Admin console. If your org uses Security > Access and data control > API controls, allowlist only the scopes listed above.
- Keep the client secret in TrueFoundry secrets and rotate it if it is ever exposed.
- Disable individual tools from the server’s Tools tab, or publish a Virtual MCP Server exposing only the tools an agent needs.
- Apply guardrails and tool approval to write-capable tools such as Gmail draft creation or Calendar event changes.
Google Chat (
https://chatmcp.googleapis.com/mcp/v1) and the People API (https://people.googleapis.com/mcp/v1) follow exactly the same pattern if you add them later, reusing the same OAuth client and consent screen. Chat additionally requires a Chat app configured in the Google Cloud Console.