Google Drive and Docs MCP: Official Options and Safe Setup

There are four ways to give an AI assistant your Google Drive today: Claude’s Google Workspace connectors, Google’s own Drive and Docs MCP servers, ChatGPT’s Google Drive app, and community servers. What each one can do, which OAuth scopes they ask for, what an admin controls, and how to prompt so nothing gets shared by accident.

8 min read

If you want an AI assistant to read and work with your Google Drive over MCP, you have four real options. Claude’s Google Drive connector is the shortest path: sign in with Google and it can search, read and, with your approval, share, move or trash files. Google now runs its own remote MCP servers for Drive, Docs, Sheets, Slides and more at addresses such as https://drivemcp.googleapis.com/mcp/v1, but you bring your own Google Cloud project and OAuth client. ChatGPT connects to Drive through its Google Drive app. And there are community servers, which work but deserve the checks any unofficial code gets. Whichever you pick, the assistant can reach every file your Google account can, so the scopes you grant and the prompts you write matter more than the setup.

Which route fits

  • You use Claude on the web, desktop or in Cowork: the built-in Google Drive connector. No URL, no Cloud project.
  • You want to control the OAuth client, the scopes and the Cloud project yourself, or use a host such as Antigravity: Google’s Drive MCP server.
  • You use ChatGPT: the Google Drive app, found under Plugins or Apps depending on your version.
  • You need something none of these does: a community server, after you have read its code and its scopes.

Claude’s Google Drive connector

Anthropic’s Google Workspace connector guide (opens in a new tab) describes what the Drive connector can do. It searches and retrieves Google Docs, and reads Sheets, Slides, PDFs, images and Microsoft Office files, taking the text only; embedded images are not processed. It can upload files, create folders, view a file’s permissions and recent changes, and share, move and trash files. Google Docs, Sheets and Slides editing is in beta: Claude can create files and edit them live in a pane beside the chat while you work in the same file.

By default Claude asks for your explicit approval before it shares, moves or trashes anything. On Team and Enterprise plans an Owner or Primary Owner has to enable the connector for the organisation first, and decides whether members may let those actions run without asking. On the Google side, a Workspace admin may need to allowlist Claude as a trusted OAuth app before anyone can sign in.

If you sign in to Claude Code with a claude.ai account, the connectors you added in claude.ai show up in Claude Code too, marked as coming from claude.ai in /mcp, according to the Claude Code MCP documentation (opens in a new tab). So one Drive sign-in can serve both. How directory connectors differ from custom ones is covered in Claude’s connectors explained.

Google’s own Drive and Docs MCP servers

Google now publishes remote MCP servers for Workspace. Its Workspace MCP setup guide (opens in a new tab) lists one per product: Gmail, Drive, Docs, Sheets, Slides, Calendar, Chat and the People API, each on its own googleapis.com address and each speaking streamable HTTP with OAuth 2.0. Google’s developer pages label them Developer Preview, so expect changes, and read the page before you rely on a tool name.

  • Drive, at https://drivemcp.googleapis.com/mcp/v1: search_files, list_recent_files, get_file_metadata, get_file_permissions, read_file_content, download_file_content, create_file and copy_file.
  • Docs, at https://docsmcp.googleapis.com/mcp/v1: read_doc and update_doc.
  • Sheets and Slides have their own servers at sheetsmcp and slidesmcp, with read and update tools of their own.

Notice what the Drive server does not have: no share, move or delete tool. Google’s own summary is that it reads data (search, metadata, content) and takes action by creating files and downloading content, while inheriting the user’s permissions and data governance controls. For an assistant whose job is to read, that is a smaller surface than a connector that can also share.

Setting it up for Claude

  1. Create or pick a Google Cloud project, and enable both the Google Drive API (drive.googleapis.com) and the Google Drive MCP API (drivemcp.googleapis.com).
  2. Configure the OAuth consent screen. Choose Internal as the audience if you are on Workspace, or External with named test users.
  3. Add the two scopes Google specifies: https://www.googleapis.com/auth/drive.readonly and https://www.googleapis.com/auth/drive.file.
  4. Create an OAuth client of type Web application with the redirect URI https://claude.ai/api/mcp/auth_callback.
  5. In Claude, add a custom connector under Settings, Connectors, with the server URL, and paste the client ID and secret under Advanced settings.

Claude Code has no fixed callback, so it takes pre-registered credentials differently: register http://localhost:8080/callback as a second redirect URI on the same client and pass the port with --callback-port. The --client-secret flag prompts for the secret rather than taking it on the command line.

Claude Code, with your own Google OAuth client
claude mcp add --transport http \
  --client-id YOUR_CLIENT_ID --client-secret --callback-port 8080 \
  google-drive https://drivemcp.googleapis.com/mcp/v1

Some files stay out of reach whatever you grant. Google’s Drive MCP file eligibility rules (opens in a new tab) exclude files with rights-management controls that block downloading, copying or printing, files encrypted with client-side encryption, items in the trash, and items marked as spam or malware, and they apply context-aware access policies. A search leaves ineligible files out rather than failing.

ChatGPT’s Google Drive app

In ChatGPT, Drive is an app rather than a server address. OpenAI’s help article on the Google Drive app says to open Plugins or Apps, find Google Drive, sign in and approve Google’s permission request. It works on files your Google account can already open. Docs, Sheets and Slides actions come through the same app, and anything that changes a file, such as creating, updating, moving, sharing or deleting it, needs the matching Google permission and has to be allowed in your workspace; ChatGPT may ask you to confirm first.

Eligible managed workspaces can also set up administrator-managed sync, which indexes chosen drives through a Google service account with domain-wide delegation while each member still sees only what Drive lets them open. Personal accounts get live access only; individual sync is no longer offered. The wider picture of apps and plugins in ChatGPT is in ChatGPT connectors and apps.

Community servers

The Google Drive server that once sat among the MCP project’s reference servers now lives in the archived servers repository (opens in a new tab), which states that the archived servers get no security updates or bug fixes. Many community servers cover Drive, Gmail and Calendar in one package. Some are good. Before you run one, check who publishes it and whether it is maintained, which scopes it requests (full drive access is very different from drive.file), where it stores your refresh token, and whether it can share or delete. The risks that apply to any unofficial server are in MCP security risks.

Scopes and the sharing risk

Two Google scopes come up again and again. drive.readonly lets an app view and download all your Drive files, including everything other people have shared with you. drive.file is narrow: it covers only files the app created, or files you opened or shared with it through a file picker. A read-only assistant with the first can still see a great deal; one with only the second sees almost nothing it did not make.

Sharing is the action to watch. A share cannot be taken back from someone who has already opened the file, and an assistant asked to “send the plan to the client” may reasonably decide that means sharing the folder. The other risk runs inward: a document anyone shares with you can carry text aimed at the assistant, the pattern described in indirect prompt injection, and share or send is how it would act on it. Google’s own guidance for its servers says to be cautious with untrusted inputs for this reason.

Admin controls

  • Claude Team and Enterprise: an Owner enables the connector, decides whether sharing, moving and trashing may run without approval, and can set each category of connector tool to always allow, needs approval or blocked.
  • Google Workspace: the Admin console’s API controls decide which third-party apps may use Workspace data and with which scopes. That is where Claude or ChatGPT is trusted, and where you find apps people connected on their own, as shadow AI agents explains.
  • ChatGPT workspaces: an admin chooses which Drive actions are available, while a Google Workspace admin separately approves the scopes those actions need. They may be different people.
  • Google’s MCP servers: Google recommends screening prompts and responses with Model Armor or an equivalent before you expose a model to Workspace data.

Prompts that keep it safe

  • Name the place. “In the Q4 Planning folder, find the latest budget sheet” beats “find the budget”, and keeps the assistant out of the rest of your Drive.
  • Say read-only out loud. “Read these three documents and summarise the open decisions. Do not share, move, rename or delete anything.”
  • Write into a new file. “Put the summary in a new document in my Drafts folder” leaves the originals untouched.
  • Ask for sources. “List the files you used, with links” lets you check it read the right version.
  • Never approve a share you did not ask for. If a share or move prompt appears mid-task, stop and ask why.

From a document to a task list

Drive is where decisions get written down, not where the work that follows is tracked. A useful pattern is to connect Drive and a task board to the same assistant: “Read the meeting notes from Tuesday and file each action as a task, with the owner in the note and a link to the document.” fenbs fits that second half. The assistant connects to https://fenbs.ai/api/mcp with OAuth and the scopes you tick, files each action as a feature, enhancement or bug, and every task it creates is recorded under its name. The setup is on the MCP docs page.

Related

What a sign-in grants and how it ends: how MCP sign-in works. Examples of Drive and Gmail in everyday work: Claude Cowork examples. Habits for any connection: MCP security best practices.

Questions people ask.

Is there an official Google Drive MCP server?

Yes. Google publishes a remote Drive MCP server at https://drivemcp.googleapis.com/mcp/v1, alongside servers for Docs, Sheets, Slides, Gmail, Calendar and Chat. Google labels them Developer Preview, and you need your own Google Cloud project and OAuth client to use them.

Can Claude read and edit Google Docs?

Yes. Claude’s Google Drive connector reads Docs, Sheets, Slides, PDFs and Office files, and Google Docs, Sheets and Slides editing is in beta, in a live pane beside the chat. Claude asks before it shares, moves or trashes a file unless an admin has changed that.

Which OAuth scopes does Google’s Drive MCP server need?

Google’s setup guide adds drive.readonly and drive.file to the consent screen. drive.readonly can view and download every file the account can open, so treat the connection as reaching all of your Drive.

Can the assistant see files that were shared with me?

Yes, if the scope allows it. All of these routes work with what your Google account can open, which includes files other people shared with you. Files protected by rights management or client-side encryption are excluded by Google’s MCP server.

Start with one thing.

There is nothing to set up first. Write one line and you’ve started.