Gmail and Google Calendar MCP: Email and Scheduling From an Agent
There are three ways to give an AI assistant your Gmail and Google Calendar: Claude’s built-in connectors, Google’s own Gmail and Calendar MCP servers, and ChatGPT’s Google apps. What each can read and change, which OAuth scopes they ask for, how to set them up, and which actions should always wait for you.
8 min read
Yes, there is an official Gmail MCP server, and a Google Calendar one beside it. Google runs both as remote servers at https://gmailmcp.googleapis.com/mcp/v1 and https://calendarmcp.googleapis.com/mcp/v1, in Developer Preview, and you connect them with your own Google Cloud project and OAuth client. The Gmail server can search, read, label and draft, but it has no send or delete tool. The shorter path for most people is Claude’s built-in Gmail and Google Calendar connectors: sign in with Google and Claude can search mail, draft, and, after you approve each one, send, reply and forward. ChatGPT reaches the same data through its Gmail and Google Calendar apps. Whichever you choose, every email the assistant reads was written by someone else, so reading is the safe half and sending is the half you keep for yourself.
Which route fits
- You use Claude on the web or desktop and want it working today: the built-in Gmail and Google Calendar connectors. No server address, no Cloud project.
- You want an assistant that cannot send mail at all, or you want to own the OAuth client and its scopes: Google’s Gmail and Calendar MCP servers, added as custom connectors.
- You use ChatGPT: its Gmail and Google Calendar apps.
- You need something none of these offers: a community server, after the checks further down.
Claude’s Gmail and Google Calendar connectors
Anthropic’s guide to Google Workspace connectors (opens in a new tab) says Gmail, Google Calendar and Google Drive connectors are available to all users on Claude and Claude Desktop. In Gmail, Claude can search and read mail, draft messages, list saved drafts, manage labels and threads, and see attachment metadata but not attachment content. It can also send, reply and forward. By default it asks for your approval before each of those three, and on Team and Enterprise plans an Owner decides whether members may let them run without asking.
In Calendar it can view your events and shared calendars you can open, create, update and delete events, find a time that works for several attendees, manage attendee lists, accept or decline invitations, and set up recurring meetings. The Drive half of the same family is covered in Google Drive and Docs MCP.
- Google’s consent screen will mention sending email. That is expected: the connector can send, and the approval prompt is what stands between a draft and a sent message.
- On Team and Enterprise plans, an Owner or Primary Owner enables the connectors for the organization before anyone can sign in.
- On Google Workspace, an admin may need to mark Claude as a trusted app under Security, Access and data control, API controls, before anyone can connect.
- Retrieved mail is stored with the chat it was used in, so deleting the chat deletes it.
Google’s Gmail and Calendar MCP servers
Google’s guide to configuring the Google Workspace MCP servers (opens in a new tab) lists one remote server per product, each speaking streamable HTTP with OAuth 2.0. They are labeled Developer Preview, and the prerequisites include membership in the Google Workspace Developer Preview Program, so treat tool names as subject to change.
- Gmail:
search_threads,get_thread,get_message,create_draft,list_drafts,list_labels, and tools to label and unlabel messages and threads. There is no send tool and no delete tool; Google’s own example drafts an email “allowing you to review and send it from Gmail.” - Calendar:
list_calendars,list_events,search_events,get_event,suggest_time,create_event,update_event,delete_eventandrespond_to_event.
The two servers differ in a way worth noticing. The Gmail server is built to stop at a draft. The Calendar server can create, change and delete events, and changes to a shared meeting reach other people’s calendars. The setup guide lists only three read-level Calendar scopes for the consent screen, even though the server has those write tools, so look at what the consent screen actually asks for when you connect.
Setup, in outline
- In a Google Cloud project, enable the Gmail API and Google Calendar API, and the Gmail MCP API and Google Calendar MCP API (
gmailmcp.googleapis.comandcalendarmcp.googleapis.com). - Configure the OAuth consent screen: Internal if you are on Workspace, or External with named test users.
- Add the scopes Google lists. For Gmail:
gmail.readonlyandgmail.compose. For Calendar:calendar.calendarlist.readonly,calendar.events.freebusyandcalendar.events.readonly. - Create an OAuth client of type Web application with the redirect URI
https://claude.ai/api/mcp/auth_callback. - In Claude, add a custom connector under Customize, Connectors (Team and Enterprise owners use Organization settings, Connectors; Free plans allow one custom connector), with the server URL, and paste the client ID and secret under Advanced settings. Repeat for the second server.
Claude Code takes the same client through its pre-registered OAuth flags. Add http://localhost:8080/callback as a second redirect URI on the client first; --client-secret then prompts for the secret instead of taking it on the command line.
claude mcp add --transport http \ --client-id YOUR_CLIENT_ID --client-secret --callback-port 8080 \ gmail https://gmailmcp.googleapis.com/mcp/v1 claude mcp add --transport http \ --client-id YOUR_CLIENT_ID --client-secret --callback-port 8080 \ google-calendar https://calendarmcp.googleapis.com/mcp/v1
One requirement is easy to miss. Google’s page on security for Workspace MCP servers (opens in a new tab) says you must screen prompts and responses for malicious content or prompt injection, with Google’s Model Armor or a solution of your own that you document. Mail is exactly the untrusted input that rule is written for.
ChatGPT’s Gmail and Google Calendar apps
In ChatGPT, Gmail and Google Calendar are apps you connect in settings rather than server addresses. OpenAI’s help center describes drafting email from a conversation and sending it once you choose to, and setting up meetings through the calendar apps. In a managed workspace, write actions for these apps stay off until an admin turns them on per app. How apps work in ChatGPT generally is in ChatGPT connectors and apps.
OAuth scopes: read vs send
The scope decides what a leaked or misused token can do, whatever the assistant was asked. Google’s Gmail API scopes page (opens in a new tab) tells developers to choose the most narrowly focused scope possible, and the differences are large:
gmail.metadata: labels and headers, not the body. Enough for “who wrote to me about the contract this week?”gmail.readonly: view your messages and settings. Restricted, because it is the whole mailbox.gmail.compose: manage drafts and send email. Note the second half: the Google server offers no send tool, but the scope it asks for would allow sending through the API.gmail.send: send email on your behalf, and nothing else.gmail.modify: read, compose and send, without permanent deletion.https://mail.google.com/: read, compose, send and permanently delete all your email. Google says to request it only for immediate, permanent deletion.
Calendar follows the same pattern. The Calendar API scopes (opens in a new tab) run from calendar.freebusy, which only shows availability, through calendar.events.readonly, to calendar.events to edit events and the full calendar scope, which can also share and permanently delete calendars. For scheduling suggestions, free/busy is often all an assistant needs.
Community servers
Many open-source Gmail and Calendar MCP servers exist, often bundled with Drive. None is recommended here. Before you run one, check who publishes it and whether it is maintained, which scopes it requests (a server asking for https://mail.google.com/ can delete mail permanently), where it stores your refresh token, and whether it has a send or delete tool you do not need. Pin the version you read. The wider checklist is in MCP security risks.
Safe uses, and what waits for you
An inbox is the textbook channel for indirect prompt injection: anyone can write to you, and an assistant that reads the message reads their instructions too. The safe jobs are the ones where following a planted instruction would do little harm:
- Triage. “Summarize unread mail from the last two days, grouped by who needs a reply from me. Do not reply, forward, label or delete anything.”
- Drafting. “Draft a reply to the vendor’s last message declining the new terms. Leave it in Drafts.” You read it and press Send yourself.
- Scheduling suggestions. “Find three 30-minute slots next week when Dana and I are both free. Do not create or change any events.”
- Meeting prep. “List tomorrow’s meetings with the latest email thread for each.”
Send, forward and delete are the actions a person approves, one at a time, after reading the full message, not the assistant’s summary of it. Add accepting or declining on your behalf and creating events with outside attendees, since both reach other people. Keep the approval prompt on in Claude, and never approve a send you did not ask for in that turn. When to ask and when not to is covered in human in the loop for AI agents.
Turning email requests into tasks
Much of an inbox is work other people are asking for, and it gets lost because mail is not a task list. Connect a board to the same assistant and the requests can leave the inbox. fenbs is one such board: the assistant connects to https://fenbs.ai/api/mcp with OAuth and the scopes you tick, files each request as a feature, enhancement or bug, and every task it creates is recorded in the history under its name.
Read my unread mail from the past week that asks me to do something. For each request, create a fenbs task in To Do: a short title, the kind (feature, enhancement or bug), and a note that says who asked, what they asked for, and the email subject. Do not reply to, forward, label or delete any email. List the tasks you created at the end.
Two honest limits. fenbs has no due dates and no assignee field, so a deadline or an owner from the email goes in the title or the first line of the note. And the assistant should never copy the email body wholesale: summarize the request, and leave personal details out of the note. If you would rather review first, ask for the list as plain lines and paste it into Add many yourself.
Related
Setting up the board side: the MCP docs page and Claude integration. What a sign-in grants and how it ends: how MCP sign-in works. The Microsoft side of the same question: Outlook MCP server.