Google Drive

Live

OAUTH 2.0

FILE STORAGE

Files & Documents

Every file, folder, and shared drive your team manages lives in Google Drive. Google Drive MCP gives your agent authenticated access to file storage scoped to the user who authorized it.

  • Acts as the user: Access and write actions stay tied to the Google Drive account that authorized the agent.
  • Credentials stay vaulted: AES-256, resolved at request time, never in LLM context.
  • Scoped before every call: User permissions enforced. 90-day audit trail.
Google Drive
agent · Acme Q3
Run
Find all PDFs shared with me this month and list the owners.
S
gdrive_files_search
77ms
Document agent
11 PDFs shared this month. Top 5: contract-acme.pdf (Sarah, Oct 29), proposal-globex.pdf (James, Oct 28), sow-initech.pdf (Maria, Oct 26), deck-umbrella.pdf (David, Oct 24), brief-stark.pdf (Lisa, Oct 22).
Sources: 11 PDFs, shared this month
googledrivemcp
11 files
18:29
Message Claude...

Tools your document agent reaches for on Google Drive, scoped per user.

CALL ANY TOOL
List, get, download, create, share, and search files and folders in Google Drive.
googledrive_list_changes
List changes
List changes (files created, modified, moved, deleted, or shared) since a given page token, for efficiently keeping an external system in sync with Google Drive without re-scanning everything. Get an initial token from Get Changes Start Page Token.
Parameters
Name
Type
Required
Description
page_token
string
Required
The token for continuing a previous list request, or the startPageToken from Get Changes Start Page Token for a first call.
drive_id
string
Optional
The shared drive to list changes for. Omit to list changes for the user's My Drive.
include_items_from_all_drives
boolean
Optional
Whether both My Drive and shared drive items should be included in results.
include_removed
boolean
Optional
Whether to include changes indicating items removed from the change list, such as deleted files or those the user lost access to.
page_size
integer
Optional
Maximum number of changes to return per page (1-1000, default 100).
restrict_to_my_drive
boolean
Optional
Whether to restrict results to changes inside the My Drive hierarchy, excluding shared items.
supports_all_drives
boolean
Optional
Whether the requesting app supports both My Drive and shared drives.
googledrive_search_files
Search files
googledrive_list_replies
List replies
googledrive_search_content
Search content
googledrive_list_comments
List comments
googledrive_get_about
Get about
googledrive_list_revisions
List revisions
googledrive_get_reply
Get reply
googledrive_list_permissions
List permissions
googledrive_get_comment
Get comment
googledrive_list_shared_drives
List shared drives
googledrive_get_revision
Get revision
googledrive_list_folder_contents
List folder contents
googledrive_get_permission
Get permission
googledrive_list_access_proposals
List access proposals
googledrive_get_shared_drive
Get shared drive
googledrive_create_file
Create file
googledrive_get_file_metadata
Get file metadata
googledrive_create_reply
Create reply
googledrive_get_access_proposal
Get access proposal
googledrive_update_reply
Update reply
googledrive_get_start_page_token
Get start page token
googledrive_create_folder
Create folder
googledrive_update_comment
Update comment
googledrive_create_comment
Create comment
googledrive_update_revision
Update revision
googledrive_create_shared_drive
Create shared drive
googledrive_update_permission
Update permission
googledrive_copy_file
Copy file
googledrive_update_shared_drive
Update shared drive
Build your Agent
Drop the toolkit in, point it at the user, and your document agent can use Google Drive from the first run.
Python · LlamaIndex
import { ScalekitClient } from "@scalekit-sdk/node";
import { DynamicStructuredTool } from "@langchain/core/tools";
import { createReactAgent } from "@langchain/langgraph/prebuilt";
import { z } from "zod";

const sk = new ScalekitClient(envUrl, clientId, clientSecret);

const { tools } = await sk.tools.listScopedTools("user_123", {
filter: { connectionNames: ["googledrive"], toolNames: ["gdrive_files_list", "gdrive_file_get", "gdrive_file_download"] },
pageSize: 100,
});

const lcTools = tools.map((t) => new DynamicStructuredTool({
name: t.tool.definition.name,
description: t.tool.definition.description,
schema: z.object({}).passthrough(),
func: async (args) => {
const { data } = await sk.tools.executeTool({
toolName: t.tool.definition.name,
identifier: "user_123",
params: args,
});
return JSON.stringify(data);
},
}));

const agent = createReactAgent({ llm, tools: lcTools });
import { ScalekitClient } from "@scalekit-sdk/node";
import OpenAI from "openai";

const sk = new ScalekitClient(envUrl, clientId, clientSecret);
const openai = new OpenAI();

const { tools } = await sk.tools.listScopedTools("user_123", {
filter: { connectionNames: ["googledrive"], toolNames: ["gdrive_files_list", "gdrive_file_get", "gdrive_file_download"] },
pageSize: 100,
});

const llmTools = tools.map((t) => ({
type: "function",
function: {
name: t.tool.definition.name,
description: t.tool.definition.description,
parameters: t.tool.definition.input_schema,
},
}));

const resp = await openai.responses.create({
model: "gpt-4o", input: prompt, tools: llmTools,
});
import { ScalekitClient } from "@scalekit-sdk/node";
import Anthropic from "@anthropic-ai/sdk";

const sk = new ScalekitClient(envUrl, clientId, clientSecret);
const anthropic = new Anthropic();

const { tools } = await sk.tools.listScopedTools("user_123", {
filter: { connectionNames: ["googledrive"], toolNames: ["gdrive_files_list", "gdrive_file_get", "gdrive_file_download"] },
pageSize: 100,
});

const llmTools = tools.map((t) => ({
name: t.tool.definition.name,
description: t.tool.definition.description,
input_schema: t.tool.definition.input_schema,
}));

const msg = await anthropic.messages.create({
model: "claude-sonnet-4-6", max_tokens: 1024,
tools: llmTools,
messages: [{ role: "user", content: prompt }],
});
import { Agent } from "@google/adk/agents";
import {
MCPToolset, StreamableHTTPConnectionParams,
} from "@google/adk/tools/mcp";

const toolset = new MCPToolset({
connectionParams: new StreamableHTTPConnectionParams({
url: "https://mcp.scalekit.com/googledrive",
headers: { Authorization: `Bearer ${userScopedToken}` },
}),
});

const agent = new Agent({
name: "agent", model: "gemini-2.0-flash",
tools: await toolset.getTools(),
});
Try these prompts
Paste any prompt into your agent to start using Google Drive.
Search & recall
Copy the prompt
Copied
Find all PDFs shared with me this week.
Copy the prompt
Copied
List files in folder [folder name].
Copy the prompt
Copied
Get the owner of [file name].
Copy the prompt
Copied
Search Drive for [keyword].
Action & sharing
Copy the prompt
Copied
Create a folder named [folder name] in [parent].
Copy the prompt
Copied
Share [file] with [email] as editor.
Copy the prompt
Copied
Download [file name] as PDF.
Copy the prompt
Copied
Move [file] to [folder].
Audits & reporting
Copy the prompt
Copied
Which files were modified today?
Copy the prompt
Copied
List all files owned by [email].
Copy the prompt
Copied
Find files larger than 100MB in [folder].
Copy the prompt
Copied
Show all files shared with anyone outside the domain.
SEE HOW AUTH WORKS
Users authorize Google Drive once. Their credentials stay vaulted, every call is checked, and every action is logged.
1
Authorize
Your user connects
Google Drive
once. We tie it to their identity and the meetings they approved — no shared bot account, no org-wide access
Who:
user ‘A’
when:
Once per user
access:
Limited to user
2
Store
Their
Google Drive
token lives in a vault scoped to them. User A's meetings are never reachable by an agent acting for user B, even on the same connection
vault:
encrypted
scope:
per-user
tokens:
auto-refreshed
3
Resolve
When your agent calls a
Google Drive
tool, we fetch the right token server-side. It never touches your agent, never appears in the LLM context, never shows up in your logs
speed:
~40ms
check:
before every call
seen by:
nobody
4
Audit
Every
Google Drive
tool call is logged — who triggered it, which meeting was fetched, what came back. 90 days of history, tied to the user who authorized it
history:
90 days
export:
SIEM-ready
logged:
every call
Test other agents
Same per-user auth pattern across other document agents and MCP connectors. Working code, live demos, fork what fits.
GTM and RevOps Teams
Deal room sync
Pulls opportunity context from Salesforce, captures key decisions from Slack, and syncs a running summary to the deal room doc in Google Drive, but only when the deal actually changed.
GTM and RevOps Teams
Revenue forecast commentary
Pulls open pipeline from Salesforce and HubSpot, calculates coverage against quota, flags at-risk stages, posts commentary to Slack, and logs every snapshot to Google Sheets.
People Ops and HR teams
Performance review collector
Collects review feedback from Airtable and Google Forms scoped to each manager's direct reports, writes per-employee summaries to Notion, and DMs the manager a Slack digest.
People Ops and HR teams
Offer letter routing agent
Drafts the offer in PandaDoc, blocks on the hiring manager's approval in Slack, then emails the candidate their e-signature link. Every call runs as the recruiter who triggered it, never a shared HR bot.
Test other agents
Same per-user auth pattern across other document agents and MCP connectors. Working code, live demos, fork what fits.
GTM
Deal room sync agent
Pull opportunity context from Salesforce, capture decisions from Slack, and keep the Google Drive deal room doc current.
GTM
Revenue forecast agent
Score pipeline coverage against quota across Salesforce and HubSpot, post forecast commentary to Slack, log snapshots to Sheets.
PEOPLE OPS
Performance review collector agent
Collect review feedback from Airtable and Google Forms per manager, summarise each report in Notion, and DM the digest in Slack.
PEOPLE OPS
Offer letter routing agent
Draft the offer in PandaDoc, gate it on hiring manager approval in Slack, then email the candidate their signature link.
Why Scalekit
Secure your agent's access. Connectors ship in minutes
01.
Shared tokens break per-user analytics
A shared token looks fine in a demo. In production every call looks like a service account. Scalekit resolves the real user credential so attribution, audit, and scope stay accurate.
// shared token
 audit → bot_service_account
 user_filter → broken

 // scalekit
 audit → user_abc
 scope → enforced ✓
02.
Authentication is not authorization
03.
Multi-tenancy is architectural
04.
Google Drive today. Others tomorrow.
“Our agents act across Salesforce, Gong, Google Drive, and more, on behalf of every customer. Scalekit behind the scenes meant we can keep adding tools without ever rebuilding how credentials or tool calling work.”
Venu Madhav Kattagoni
Head of Engineering / Von
FAQs
Frequently Asked Questions
Does the agent access Google Drive as the user or as a shared key?
As the user. Each workspace member authorizes once and Scalekit resolves their credential at request time. Audit logs attribute every action to that user, not a shared service account.
Where is the Google Drive oauth 2.0 stored?
In Scalekit's managed AES-256 token vault, namespaced per tenant. Refresh is automatic. Revocation is a single dashboard action. Tokens never appear in prompts, logs, or LLM context.
Can I limit what the agent is allowed to do in Google Drive?
Yes. Pass a tool name filter to listScopedTools so the document agent only sees the subset you authorize. Pre-API-call scope checks block out-of-policy actions before the request reaches Google Drive.
What happens when a user revokes Google Drive access?
The connection is invalidated on the next tool call. Subsequent requests for that user fail closed with a clear error. Other users in the tenant remain unaffected. The event is logged for audit.
Can the agent reach shared drives the user is not a member of?
No. Access resolves the authorizing user's current Drive permissions. Shared drives the user hasn't joined and files with download restrictions are all blocked at the Google layer.
Start in your coding agent
Up and running in one command
Install the Scalekit skill in your editor of choice. Connector, auth, tools, prompt, all wired up
Claude Code REPL
/plugin marketplace add scalekit-inc/claude-code-authstack
/plugin install agentkit@scalekit-auth-stack
Cursor Code REPL
# ~/.cursor/mcp.json
{
""mcpServers"": {
""googledrive"": {
""url"": ""https://mcp.scalekit.com/googledrive"",
""headers"": { ""Authorization"": ""Bearer $SCALEKIT_TOKEN"" }
}
}
}
Codex Code REPL
# ~/.codex/config.toml
[mcp_servers.googledrive]
url = ""https://mcp.scalekit.com/googledrive""
auth_env = ""SCALEKIT_TOKEN""
Copilot Code REPL
# .vscode/mcp.json
{
""servers"": {
""googledrive"": {
""url"": ""https://mcp.scalekit.com/googledrive"",
""type"": ""http""
}
}
}