Managing Google Workspace
taylorwilsdon/google_workspace_mcp
Manages Google Workspace operations across 12 services (Gmail, Drive, Calendar, Docs, Sheets, Slides, Forms, Tasks, Contacts, Chat, Apps Script, Custom Search).
Verify Google Workspace MCP authentication at the start of any session that needs Google APIs (Docs, Slides, Drive).
$ npx skills add ai-analyst-lab/ai-analyst --skill auth-preflight -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install ai-analyst-lab/ai-analyst auth-preflight --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/ai-analyst-lab/ai-analyst.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/auth-preflight .claude/skills/auth-preflight && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "auth-preflight" agent skill from https://github.com/ai-analyst-lab/ai-analyst/tree/main/.claude/skills/auth-preflight into .claude/skills/auth-preflight/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "auth-preflight", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/ai-analyst-lab/ai-analyst/tree/main/.claude/skills/auth-preflightType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add ai-analyst-lab/ai-analyst --skill auth-preflight -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install ai-analyst-lab/ai-analyst auth-preflight --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ai-analyst-lab/ai-analyst.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/auth-preflight .agents/skills/auth-preflight && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "auth-preflight" agent skill from https://github.com/ai-analyst-lab/ai-analyst/tree/main/.claude/skills/auth-preflight into .agents/skills/auth-preflight/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "auth-preflight", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ai-analyst-lab/ai-analyst --skill auth-preflight -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install ai-analyst-lab/ai-analyst auth-preflight --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ai-analyst-lab/ai-analyst.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/auth-preflight .cursor/skills/auth-preflight && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "auth-preflight" agent skill from https://github.com/ai-analyst-lab/ai-analyst/tree/main/.claude/skills/auth-preflight into .cursor/skills/auth-preflight/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "auth-preflight", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/ai-analyst-lab/ai-analyst.git --path .claude/skills/auth-preflight--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add ai-analyst-lab/ai-analyst --skill auth-preflight -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install ai-analyst-lab/ai-analyst auth-preflight --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ai-analyst-lab/ai-analyst.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/auth-preflight .gemini/skills/auth-preflight && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "auth-preflight" agent skill from https://github.com/ai-analyst-lab/ai-analyst/tree/main/.claude/skills/auth-preflight into .gemini/skills/auth-preflight/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "auth-preflight", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install ai-analyst-lab/ai-analyst auth-preflightInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add ai-analyst-lab/ai-analyst --skill auth-preflight -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/ai-analyst-lab/ai-analyst.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/auth-preflight .github/skills/auth-preflight && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "auth-preflight" agent skill from https://github.com/ai-analyst-lab/ai-analyst/tree/main/.claude/skills/auth-preflight into .github/skills/auth-preflight/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "auth-preflight", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ai-analyst-lab/ai-analyst --skill auth-preflight -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install ai-analyst-lab/ai-analyst auth-preflight --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ai-analyst-lab/ai-analyst.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/auth-preflight .opencode/skills/auth-preflight && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "auth-preflight" agent skill from https://github.com/ai-analyst-lab/ai-analyst/tree/main/.claude/skills/auth-preflight into .opencode/skills/auth-preflight/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "auth-preflight", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
auth-preflightVerify Google Workspace MCP authentication at the start of any session that needs Google APIs (Docs, Slides, Drive).
Auth Preflight is an agent skill from ai-analyst-lab/ai-analyst. Verify Google Workspace MCP authentication at the start of any session that needs Google APIs (Docs, Slides, Drive). This skill prevents auth failures mid-workflow by testing credentials upfront. Use this skill automatically at session start when the task involves Google Docs, Google Slides, Drive uploads, or any MCP Google Workspace tool. Also trigger when users mention "Google Doc", "Google Slides", "upload to Drive", "export to Google", "share on Drive", or any Google-related output format. Apply before…
Its SKILL.md is about 3.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Documents & Office, covering Cloud office suites. It works with Model Context Protocol, Google Docs, Google Slides and Google Workspace. The repository describes itself as: AI Product Analyst — Claude Code-powered data analysis toolkit. The licence is MIT.
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 52c0744. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are bash).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Auth Preflight loads about 3.1k tokens when it runs. Until then it costs about 243 tokens; SKILL.md has 1,177 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from ai-analyst-lab/ai-analyst at commit 52c0744, republished under its MIT licence (© ai-analyst-lab). 1,177 words, ~3,099 tokens.
.claude/skills/auth-preflight/SKILL.md (or your agent's skills folder).Verify Google Workspace MCP authentication BEFORE beginning any Google-dependent work. Catches auth issues in <30 seconds instead of discovering them after 5-10 minutes of chart generation, narrative writing, or deck building.
Core principle: Fail fast with clear guidance, not slow with cryptic errors mid-workflow.
Trigger this skill immediately when:
mcp__google-* tool will be calledCritical timing: Run auth preflight as your FIRST action, before exploring data, generating charts, parsing narratives, or any other substantive work.
Read .mcp.json to discover which Google MCP server(s) are configured:
cat .mcp.json | grep -A3 googleLook for entries like:
google-docs → Google Docs + Drive MCP server (most common)google-workspace → Full workspace MCP (Docs, Slides, Drive)google-slides → Slides-specific MCP serverExtract:
Why this matters: Different MCP implementations store credentials in different locations. Detecting configuration first ensures you check the right paths.
If no Google MCP found: Report:
Auth: FAILED — No Google MCP server configured in .mcp.json
To use Google Docs/Slides, add a Google MCP server to .mcp.jsonBased on MCP type from Step 1, check credentials in ALL possible locations (some setups use non-standard paths):
# For google-docs MCP
ls ~/.claude/mcp-servers/google-docs-mcp-server/
# For google-workspace MCP
ls ~/.google_workspace_mcp/credentials/
# For google-slides MCP
ls ~/.claude/mcp-servers/google-slides-mcp-server/# Some custom MCP installs use these
ls ~/.config/google-docs-mcp-server/
ls ~/.google_mcp/credentials/Look for:
token.json (current access/refresh token)credentials.json (OAuth client credentials){email}.json filesIf no credentials found anywhere:
If credentials found:
user@gmail.com.json → use exactly user@gmail.com in all API calls)cat {token_path} | grep expiryMake a simple API call to verify the token works. Always use CREATE operations, not READ operations to avoid permission errors on specific documents.
Why create, not read? Reading a specific document can fail with 403 "Permission denied" even when auth is valid (if that doc isn't shared with the user). Creating a new document only requires valid auth, not document-specific permissions.
If google-docs MCP:
mcp__google-docs__create_document(title="Auth Preflight Test - Delete Me")If google-workspace MCP:
mcp__google-workspace__create_doc(
user_google_email="{email_from_credentials_filename}",
title="Auth Preflight Test"
)Critical: Use the EXACT email string from the credential filename. Gmail treats dots as equivalent (a.b@gmail.com = ab@gmail.com) but MCP stores tokens by exact string match.
If google-slides MCP:
mcp__google-slides__create_presentation(title="Auth Preflight Test")Interpreting results:
| Result | Meaning | Action |
|---|---|---|
| Success (doc/presentation created) | Auth is valid | Report "Auth: OK", clean up test resource, proceed |
| 401 Unauthorized | Token expired/invalid | Proceed to Step 4 (re-auth) |
| 403 Forbidden (when creating) | Quota exceeded or API disabled | Report API configuration issue |
| "Tool not found" | MCP not loaded | Recommend restarting Claude Code |
| "Address already in use" | OAuth server already running | Try actual API call (ignore this error) |
If successful:
Auth: OK ({server_type})
Token verified via create_document at {timestamp}
Ready to proceed with Google API operationsIf auth error: Proceed to Step 4.
If credentials missing or token invalid, guide user through re-authentication.
For google-docs MCP:
mcp__google-docs__authorize_google_docs()For google-workspace MCP:
mcp__google-workspace__authorize()For google-slides MCP:
mcp__google-slides__authorize()When authorization URL appears:
Copy-paste the URL into your browser
Select your Google account when prompted
If you see "Access blocked: This app isn't verified":
If authorization fails with "Address already in use":
After you see "Authentication successful" in browser, tell me "done" and I'll verify
After user confirms auth completed, repeat Step 3 (create test document/presentation).
If successful:
Auth: OK ({server_type})
Re-authentication successful
Proceeding with {original_task}If still failing: Check diagnostics:
# Verify new credentials appeared
ls ~/.claude/mcp-servers/google-docs-mcp-server/
# Check if token was actually written
ls -lh ~/.claude/mcp-servers/google-docs-mcp-server/token.json
# If token is 0 bytes or very old (unchanged timestamp), auth didn't completeIf credentials still missing/invalid:
Auth: FAILED — Re-authentication did not create valid credentials
Diagnostic findings:
- Credential location: {path_checked}
- Token file: {exists/missing}
- Token size: {bytes} (should be >200 bytes)
- Last modified: {timestamp}
Recommended action:
1. Restart Claude Code (closes all MCP servers cleanly)
2. Check for auth URL in Claude Code startup logs
3. Complete OAuth flow in browser
4. Verify you added your email as a test user in Google Cloud Console
5. If still failing, check Google Cloud Console → APIs & Services → Enabled APIs
- Required: Google Docs API, Google Drive API (and Google Slides API if needed)If you created a test document/presentation in Step 3 and it's still accessible, optionally clean it up:
# For test documents
mcp__google-docs__delete_document(document_id="{test_doc_id}")
# (if delete tool exists)
# Or just leave it - user can delete manually from DriveThis is non-critical; the test resource causes no harm.
| Issue | Symptom | Root Cause | Fix |
|---|---|---|---|
| Email mismatch (workspace-mcp) | Auth succeeds but all API calls fail with "Invalid grant" | Email parameter doesn't match credential filename exactly | Extract email from credential filename, use exact string (including/excluding dots) |
| Token expired | "Authentication needed" on every call | Token hasn't been refreshed, or refresh token invalid | Re-auth via Step 4 |
| App not verified | "Access blocked" screen after selecting Google account | User not added as test user for OAuth app | Add user's email in Google Cloud Console → OAuth consent screen → Test users |
| URL corruption | Auth URL gives 400 error | Terminal cmd-click appended control characters | Copy-paste URL manually, don't click |
| MCP server not found | "Tool not found" errors on all MCP calls | Server didn't start with Claude Code session | Restart Claude Code (MCP servers auto-start) |
| Port conflict | "Address already in use" during authorize() | OAuth callback server already bound to port | Restart Claude Code to reset server state |
| Stale token in memory | Credentials valid on disk but API calls fail | MCP server has cached invalid token | Restart Claude Code to reload credentials from disk |
| Credentials in wrong location | Token.json exists but skill can't find it | Custom MCP installation path | Check .mcp.json command/args to infer storage location |
General troubleshooting principle: When in doubt, restart Claude Code. This cleanly reloads all MCP servers with fresh credentials from disk.
~/.google_workspace_mcp/credentials/{email}.jsonuser_google_email parameterjohn.doe@gmail.com ≠ johndoe@gmail.com)create_doc() with email + titlemcp__google-workspace__authorize()~/.claude/mcp-servers/google-docs-mcp-server/token.jsoncreate_document(title="...") — no email parammcp__google-docs__authorize_google_docs()token, refresh_token, expiry, scopes~/.claude/mcp-servers/google-slides-mcp-server/token.jsoncreate_presentation(title="...")mcp__google-slides__authorize()Adaptation rule: Always detect actual config from .mcp.json and ls results rather than assuming a specific pattern. Support all three patterns in the same skill.
Always use CREATE for test calls, never READ. Creating a resource only requires valid auth. Reading requires auth + permissions on that specific resource.
Extract email from credential filename for workspace-mcp. Don't ask the user for their email. The exact string in the filename is what must be passed to API calls.
One auth attempt, then clear explanation. If re-auth fails, provide diagnostics and actionable next steps. Don't retry repeatedly.
© ai-analyst-lab, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .claude/skills/auth-preflight of ai-analyst-lab/ai-analyst.
Open the folder on GitHubat commit 52c0744
Auth Preflight next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Auth Preflight this skillai-analyst-lab/ai-analyst | 304 | — | ~3.1k | Automated safety check: Pass | MIT | |
| Managing Google Workspacetaylorwilsdon/google_workspace_mcp | 3.3k | — | ~2.9k | Automated safety check: Pass | MIT | |
| Google Workspaceespennilsen/pi | 122 | — | ~3.4k | Automated safety check: Pass | MIT | |
| Google Docssanjay3290/ai-skills | 431 | — | ~636 | Automated safety check: Pass | Apache-2.0 | |
| Gwskv0906/pm-kit | 138 | — | ~1.6k | Automated safety check: Pass | MIT | |
| Google Docs, Sheets and Slides Editingasgeirtj/system_prompts_leaks | 69k | — | ~3.5k | Automated safety check: Warn | CC0-1.0 |
taylorwilsdon/google_workspace_mcp
Manages Google Workspace operations across 12 services (Gmail, Drive, Calendar, Docs, Sheets, Slides, Forms, Tasks, Contacts, Chat, Apps Script, Custom Search).
espennilsen/pi
Manage Google Workspace via the gws CLI — Drive, Gmail, Sheets, Docs, Slides, People, Chat, Meet, Forms, and cross-service workflows.
sanjay3290/ai-skills
Interact with Google Docs - create documents, search by title, read content, and edit text.
kv0906/pm-kit
This skill should be used when the user asks to "set up gws", "install Google Workspace CLI", "connect Gmail to Claude", "manage Google Drive from terminal", "send email from CLI", "check my…
asgeirtj/system_prompts_leaks
Guidance for creating and editing Google Docs, Sheets and Slides through connectors, with per-app API rules and helper scripts for positions, ranges and slide layout.
mitsuhiko/agent-stuff
Access Google Workspace APIs (Drive, Docs, Calendar, Gmail, Sheets, Slides, Chat, People) via local helper scripts without MCP.
ai-analyst-lab/ai-analyst
Never present a metric or number in isolation; anchor every number to a comparison (prior period, benchmark, or another segment) or state that none is available.
ai-analyst-lab/ai-analyst
Retrieve proven SQL patterns, table cheatsheets, and join patterns from .knowledge/query-archaeology/ so past work gets reused.
ai-analyst-lab/ai-analyst
Save completed analyses to the knowledge system's analysis archive for future reference.
ai-analyst-lab/ai-analyst
Causal inference toolkit for when experiments are not possible: estimate treatment effects from observational data with assumption checks and mandatory caveats.
ai-analyst-lab/ai-analyst
Standardized workflow for uploading local chart PNGs to Google Drive and making them available for insertion into Google Docs and Slides.
ai-analyst-lab/ai-analyst
Independently validate the current analysis with a second model (OpenAI Codex).
Categories
Verify Google Workspace MCP authentication at the start of any session that needs Google APIs (Docs, Slides, Drive). Auth Preflight is an agent skill from ai-analyst-lab/ai-analyst. Verify Google Workspace MCP authentication at the start of any session that needs Google APIs (Docs, Slides, Drive).
Auth Preflight fits situations like: users mention Google Doc; upload to Drive; export to Google; any Google-related output format.
Run `npx skills add ai-analyst-lab/ai-analyst --skill auth-preflight -a claude-code`. Or copy the skill folder (.claude/skills/auth-preflight in ai-analyst-lab/ai-analyst) into .claude/skills/auth-preflight in your project. Claude Code loads it when a task matches its description.
Run `npx skills add ai-analyst-lab/ai-analyst --skill auth-preflight -a codex`. Or copy the skill folder (.claude/skills/auth-preflight in ai-analyst-lab/ai-analyst) into .agents/skills/auth-preflight in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ai-analyst-lab/ai-analyst --skill auth-preflight -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/auth-preflight, .gemini/skills/auth-preflight, .github/skills/auth-preflight and .opencode/skills/auth-preflight in your project.
SKILL.md names no scripts, command-line tools or credentials: Auth Preflight is instructions for the agent only. Our summary lists: Python 3.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Auth Preflight is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.1k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Auth Preflight: Managing Google Workspace (taylorwilsdon/google_workspace_mcp, 3.3k stars), Google Workspace (espennilsen/pi, 122 stars), Google Docs (sanjay3290/ai-skills, 431 stars) and Gws (kv0906/pm-kit, 138 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
ai-analyst-lab (a GitHub organization) maintains it in ai-analyst-lab/ai-analyst, which has 304 GitHub stars. The repository holds 43 skills in this directory. The repository was last updated on September 30, 2026.
Source: ai-analyst-lab/ai-analyst on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.