How to Connect Google Workspace (Drive, Gmail, Calendar) to AI Agents Securely

Last updated ·Read as Markdown
Answer

Connect Google Drive, Gmail, and Calendar to AI agents through an MCP gateway, one integration per service, with read-only tools and narrow OAuth scopes. Use your own OAuth credentials so you choose the scopes, set the app's access in the Google Admin console, allow each integration for a group, and have each person authorize with their own Google account. In Metorial, each person then adds one Magic MCP URL to their assistant, and every call is logged with their identity.

Google Workspace holds the documents, mail, and calendars a company runs on, which is why people want agents there and why the permissions matter. The safe version has three parts: narrow scopes, an admin who has approved the app, and each person signing in as themselves.

If agents should
Start with
Find and summarize documents
Google Drive, read tools, narrowest scope that works
Triage and summarize email
Gmail, read and search tools only
Check availability and schedule
Google Calendar, read first, then event creation
Operate under security review
Your own OAuth credentials plus Admin console API controls

What do you need before starting?

  • A Google Workspace admin who can configure API controls.
  • An OAuth app in your own Google project, if you want to choose the scopes.
  • A Metorial account. The Dev plan is free.
  • A decision on which of the three services to start with. Gmail is the one to be slowest with.

How do you connect Drive, Gmail, and Calendar?

1. Choose the services. In Metorial, Gmail, Google Calendar, and Google Drive are separate integrations. Set up only the ones a team needs, so each gets its own tools and its own access rules.

2. Create custom OAuth credentials. In the dashboard, select Settings, then Organization Settings, then Provider Auth under Integrations and MCP, and select Create Auth Credentials. Copy the Redirect URI into your Google OAuth app, then enter a Name, Client ID, and Client Secret. Review the scopes and keep only what the integration needs. In Google's console, you can set the app's user type to Internal, which limits authorization requests to members of your organization.

3. Create each integration. Open Integrations, select Create Integration, choose the Google service, and under Auth Method select the credentials you just made. In Tool Filters, reject the tools that send, create, change, or delete.

4. Configure the app in the Admin console. A Workspace admin opens Security, Access and data control, API controls and sets the app's access. The options are Trusted, Limited, Specific Google data, and Blocked. Specific Google data lets the admin name the exact scopes.

5. Allow it for a group. In Workforce, under Access, add the integration, then in its Access section select Add Group, set it to Allow, and save. Publish it in a portal as a user-configured listing.

6. Each person connects and adds the URL. People open the portal, authorize Google with their own account, and paste their Magic MCP URL into Claude, Cursor, or another assistant.

7. Check the first call. Ask for something narrow, such as "list the files shared with me this week". Then open Integrations, Connection Logs, Tool Calls and confirm the row names the tool, the arguments, and the right person.

Which Google scopes should you grant?

Google classifies scopes, and the classification is a good guide to risk. In Drive, drive.file is non-sensitive and covers only files a person selects or shares with the app. The broader drive and drive.readonly scopes are restricted. In Gmail, gmail.readonly and gmail.modify are restricted, and gmail.send is sensitive. Calendar offers narrow options such as calendar.events.readonly, which covers viewing events without editing them.

Pick the narrowest scope that supports the use case, and match it to the tools you leave enabled. A read-only scope paired with write tools rejected in Metorial fails safe from both sides.

What does the Admin console add?

It lets the organization decide, not each employee. Under Manage Google Services, an admin can mark a service as Restricted so that only Trusted apps or apps with Specific Google data can use it. For Gmail, Drive, Docs, and Chat, admins can also restrict high-risk scopes separately. For example, Gmail restrictions include scopes for sending mail or modifying messages.

What if the admin blocks the app?

In the Admin console's Settings for API controls, admins choose what happens when people use apps nobody has configured. They can allow all third-party apps, allow only basic sign-in requests, or block unconfigured apps entirely. If your organization blocks them, an unconfigured connection may fail until an admin sets the app to Trusted or Specific Google data. Configure the app first, then invite people.

What does per-person sign-in change?

Each agent reaches the files, messages, and calendars that person's Google account already reaches, and the call record names the person. A shared service credential does neither. See How to control which AI tools each team can use for how groups decide who gets each integration.

Frequently asked questions

Is Google Workspace one connection or several?

Several. Metorial lists Gmail, Google Calendar, and Google Drive as separate integrations, so you can set up only the services a team needs and give each its own tool filters and group access.

Which Google scopes are the riskiest for an agent?

Broad Gmail and Drive scopes. Google classes gmail.readonly, gmail.modify, drive, and drive.readonly as restricted scopes, and gmail.send as sensitive. The drive.file scope, which covers only files a user shares with the app, is non-sensitive.

Can a Google Workspace admin control which apps reach company data?

Yes. In the Admin console, under Security, then Access and data control, then API controls, admins can mark an app as Trusted, Limited, Specific Google data, or Blocked, and can restrict high-risk scopes for Gmail, Drive, Docs, and Chat separately.

Should the agent be able to send email?

Not at first. Reading and searching mail covers most triage and summary use cases. Sending is the action that reaches people outside the company, so enable it for a small group after reviewing the call records.

Do we need our own OAuth credentials?

It is the way to control scopes yourself. Metorial lets you create custom OAuth credentials from your own OAuth app, review the scopes, and grant only what the integration needs. Without them, the integration uses the permissions its default sign-in requests.

Sources

  1. Metorial documentation: Create custom OAuth credentials
  2. Google Workspace Admin: Control which apps access Google Workspace data
  3. Google Drive API: Choose Google Drive API scopes
  4. Gmail API: Choose Gmail API scopes

Ready to build with Metorial?

Connect any AI agent to any tool or data source. Govern every action.