Agent skill

Gws Setup

by jezweb in jezweb/claude-skills

Set up the Google Workspace CLI (gws) from scratch. An agent skill from jezweb/claude-skills.

MITAuto-check passedDocuments & Office

Install Gws Setup

skills CLI
$ npx skills add jezweb/claude-skills --skill gws-setup -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jezweb/claude-skills gws-setup --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jezweb/claude-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/integrations/skills/gws-setup .claude/skills/gws-setup && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
gws-setup
GitHub stars
1.1k
Token cost
~2.3k tokens
SKILL.md length
994 words
Files
1
Skills in repo
52
Repo updated
First seen
Licence
MIT

At a glance

Set up the Google Workspace CLI (gws) from scratch. An agent skill from jezweb/claude-skills.

  • Works in 8 steps: Pre-flight Checks → Install the CLI → Create a GCP Project and OAuth Credentials → …
  • The user wants to set up gws for the first time
  • SKILL.md covers Prerequisites, Workflow, Critical Patterns and See Also
  • Calls npm and npx; reaches console.cloud.google.com and accounts.google.com; needs GOOGLE_WORKSPACE_CLI_CLIENT_SECRET

What it does

Gws Setup is an agent skill from jezweb/claude-skills. Set up the Google Workspace CLI (gws) from scratch. Guides through GCP project creation, OAuth credentials, authentication, and installing 90+ agent skills for Claude Code. Use whenever the user wants to set up gws for the first time, configure Google Workspace API access, install the Google Workspace CLI, or troubleshoot gws auth issues.

Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts. Compatibility notes: claude-code-only

It sits in Documents & Office, covering Cloud office suites and OAuth and OpenID Connect. It works with Google Workspace and Google Cloud. The repository describes itself as: Skills for Claude Code CLI such as full stack dev Cloudflare, React, Tailwind v4, and AI integrations. The licence is MIT.

When your agent uses it

  • The user wants to set up gws for the first time
  • Configure Google Workspace API access
  • Install the Google Workspace CLI
  • Troubleshoot gws auth issues

Example prompts

  • “/gws-setup”

Requirements

  • Node.js
  • A credential in GOOGLE_WORKSPACE_CLI_CLIENT_SECRET
  • Compatibility (from SKILL.md): claude-code-only

Workflow steps

8 steps, taken from the step headings in SKILL.md.

  1. Pre-flight Checks
  2. Install the CLI
  3. Create a GCP Project and OAuth Credentials
  4. Choose Scopes
  5. Authenticate
  6. Install Agent Skills
  7. Save Credentials for Other Machines
  8. Verify Everything Works

What it can do on your machine

Read from SKILL.md and the folder at commit 64965d9. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm
    • npx

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • console.cloud.google.com
    • accounts.google.com
    • oauth2.googleapis.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • GOOGLE_WORKSPACE_CLI_CLIENT_SECRET

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    claude-code-only

    From compatibility in the SKILL.md frontmatter.

Context cost

Gws Setup loads about 2.3k tokens when it runs. Until then it costs about 88 tokens; SKILL.md has 994 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~88
When it runs · the whole SKILL.md, loaded when a task matches
~2.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from jezweb/claude-skills at commit 64965d9, republished under its MIT licence (© jezweb). 994 words, ~2,291 tokens.

Download SKILL.mdSave it as .claude/skills/gws-setup/SKILL.md (or your agent's skills folder).
name
gws-setup
description
Set up the Google Workspace CLI (gws) from scratch. Guides through GCP project creation, OAuth credentials, authentication, and installing 90+ agent skills for Claude Code. Use whenever the user wants to set up gws for the first time, configure Google Workspace API access, install the Google Workspace CLI, or troubleshoot gws auth issues.
compatibility
claude-code-only

Google Workspace CLI — First-Time Setup

Set up the gws CLI (@googleworkspace/cli) with OAuth credentials and 90+ agent skills for Claude Code. Produces a fully authenticated CLI with skills for Gmail, Drive, Calendar, Sheets, Docs, Chat, Tasks, and more.

Prerequisites

  • Node.js 18+
  • A Google account (personal or Workspace)
  • Access to Google Cloud Console (console.cloud.google.com)

Workflow

Step 1: Pre-flight Checks

Check what's already done and skip completed steps:

bash
# Check if gws is installed
which gws && gws --version

# Check if client_secret.json exists
ls ~/.config/gws/client_secret.json

# Check if already authenticated
gws auth status

If gws auth status shows "status": "success" with scopes, skip to Step 6 (Install Skills).

Step 2: Install the CLI
bash
npm install -g @googleworkspace/cli
gws --version
Step 3: Create a GCP Project and OAuth Credentials

The user needs to create OAuth Desktop App credentials in Google Cloud Console. Walk them through each step.

3a. Create or select a GCP project:

Direct the user to: https://console.cloud.google.com/projectcreate

Or use an existing project. Ask the user which they prefer.

3b. Enable Google Workspace APIs:

Direct the user to the API Library for their project: https://console.cloud.google.com/apis/library?project=PROJECT_ID

Enable these APIs (search for each):

  • Gmail API
  • Google Drive API
  • Google Calendar API
  • Google Sheets API
  • Google Docs API
  • Google Chat API (requires extra Chat App config — see below)
  • Tasks API
  • People API
  • Google Slides API
  • Google Forms API
  • Admin SDK API (optional — for Workspace admin features)

3c. Configure Google Chat App (required for Chat API):

Enabling the Chat API alone isn't enough — Google requires a Chat App configuration even for user-context OAuth access. Without this, all Chat API calls return errors.

Direct the user to: https://console.cloud.google.com/apis/api/chat.googleapis.com/hangouts-chat?project=PROJECT_ID

  1. Click the Configuration tab
  2. Fill in app details (name, avatar, description — values don't matter for CLI use)
  3. Under "Functionality", check Spaces and group conversations
  4. Under "Connection settings", select Apps Script or HTTP endpoint (pick any — we just need the config to exist)
  5. Save

This creates the app identity that the Chat API requires. Messages sent via gws still appear as coming from the authenticated user (OAuth user context), not from a bot.

3e. Configure OAuth consent screen:

Direct the user to: https://console.cloud.google.com/apis/credentials/consent?project=PROJECT_ID

Settings:

  • User Type: External (works for any Google account)
  • App name: gws CLI (or any name)
  • User support email: their email
  • Developer contact: their email
  • Leave scopes blank (gws requests scopes at login time)
  • Add their Google account as a test user (required while app is in "Testing" status)
  • Save and continue through all screens

3f. Create OAuth client ID:

Direct the user to: https://console.cloud.google.com/apis/credentials?project=PROJECT_ID

  1. Click Create Credentials → OAuth client ID
  2. Application type: Desktop app
  3. Name: gws CLI
  4. Click Create
  5. Copy the JSON or download the client_secret_*.json file

3g. Save the credentials:

Ask the user to provide the client_secret.json content (paste the JSON or provide the downloaded file path).

bash
mkdir -p ~/.config/gws

Write the JSON to ~/.config/gws/client_secret.json. The expected format:

json
{
  "installed": {
    "client_id": "...",
    "project_id": "...",
    "auth_uri": "https://accounts.google.com/o/oauth2/auth",
    "token_uri": "https://oauth2.googleapis.com/token",
    "client_secret": "...",
    "redirect_uris": ["http://localhost"]
  }
}
Step 4: Choose Scopes

Ask the user what level of access they want:

OptionCommandWhat it grants
Full access (recommended)gws auth login --fullAll Workspace scopes including admin, pubsub, cloud-platform
Core servicesgws auth login -s gmail,drive,calendar,sheets,docs,chat,tasksMost-used services only
Minimalgws auth login -s gmail,calendarJust email and calendar

Recommend full access for power users. The OAuth consent screen shows all requested scopes so the user can review before granting.

Note: If the GCP app is in "Testing" status, scope selection is limited to ~25 scopes. Use -s service1,service2 to request targeted scopes, or publish the app (Publish → In Production) for broader scope access.

Show full SKILL.md (438 more words)Show less
Step 5: Authenticate

IMPORTANT: This step prints a very long OAuth URL (30+ scopes) that the user must open in their browser. The URL is too long to copy from terminal output — it wraps across lines and breaks. Always extract it to a file and open it programmatically.

  1. Run the login command and capture the output:
bash
gws auth login --full 2>&1 | tee /tmp/gws-auth-output.txt
# Or with specific services:
# gws auth login -s gmail,drive,calendar,sheets,docs,chat,tasks 2>&1 | tee /tmp/gws-auth-output.txt

Running as a background task is fine — it will complete once the user approves in browser.

  1. Extract and open the URL (run separately after output appears):
bash
grep -o 'https://accounts.google.com[^ ]*' /tmp/gws-auth-output.txt > /tmp/gws-auth-url.txt
cat /tmp/gws-auth-url.txt | xargs open

If open doesn't work, tell the user: "The auth URL is saved at /tmp/gws-auth-url.txt — open that file and copy the URL."

  1. Wait for the user to approve in their browser.

After browser approval, gws stores encrypted credentials at ~/.config/gws/credentials.enc.

Verify:

bash
gws auth status

Should show "status": "success" with the authenticated account and granted scopes.

Step 6: Install Agent Skills

Install the 90+ gws agent skills globally for Claude Code:

bash
npx skills add googleworkspace/cli -g --agent claude-code --all

Verify skills are installed:

bash
ls ~/.claude/skills/gws-* | wc -l

Should show 30+ gws skill directories.

Step 7: Save Credentials for Other Machines

If the user has other machines to set up, suggest exporting the client credentials:

bash
gws auth export

This prints decrypted credentials (including refresh token) to stdout. The client_secret.json file is the portable part — the same OAuth client can be used on any machine, with gws auth login generating fresh user tokens per machine.

Tell the user to save the client_secret.json content somewhere secure (password manager, encrypted note) for use with the gws-install skill on other machines.

Step 8: Verify Everything Works

Run a few commands to confirm:

bash
# Check auth
gws auth status

# Check calendar
gws calendar +agenda --today

# Check email
gws gmail +triage

If any command fails with auth errors, re-run gws auth login with the needed scopes.


Critical Patterns

Testing vs Production OAuth Apps

GCP OAuth apps start in "Testing" status with a 7-day token expiry and ~25 scope limit. For long-term use:

  • Push the app to Production in the OAuth consent screen settings
  • Production apps have no token expiry limit
  • For personal/internal use, Google does not require verification
Scope Reference
Service flagWhat it enables
gmailSend, read, manage email, labels, filters
driveFiles, folders, shared drives
calendarEvents, calendars, free/busy
sheetsRead and write spreadsheets
docsRead and write documents
chatSpaces, messages
tasksTask lists and tasks
slidesPresentations
formsForms and responses
peopleContacts and profiles
adminWorkspace admin (directory, devices, groups)
Environment Variable Alternative

Instead of client_secret.json, credentials can be provided via environment variables:

bash
export GOOGLE_WORKSPACE_CLI_CLIENT_ID="your-client-id"
export GOOGLE_WORKSPACE_CLI_CLIENT_SECRET="your-client-secret"
gws auth login
Config Directory

All gws config lives in ~/.config/gws/:

FilePurpose
client_secret.jsonOAuth client credentials (portable)
credentials.encEncrypted user tokens (per-machine)
token_cache.jsonToken refresh cache
cache/API discovery schema cache

See Also

  • gws-install — Quick setup on additional machines with existing credentials
  • gws-shared — Auth patterns and global flags for gws commands

© jezweb, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in plugins/integrations/skills/gws-setup of jezweb/claude-skills.

Open the folder on GitHubat commit 64965d9

Compare with similar skills

Gws Setup next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Gws Setup compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Gws Setup this skilljezweb/claude-skills1.1k—~2.3kAutomated safety check: PassMIT
Google Workspacetaracodlabs/aiden849—~1.1kAutomated safety check: PassApache-2.0
GCP Workspace Pivotwgpsec/AboutSecurity1.8k—~2.9kAutomated safety check: PassNone
Community Google WorkspaceArgentAIOS/argentos-core126—~2.8kAutomated safety check: PassMIT
Google WorkspaceTommy-yw/RunbookHermes5461 repos~2.7kAutomated safety check: PassMIT
Google Workspaceericrisco/rsc-harness156—~3.2kAutomated safety check: PassMIT

Similar skills

  • Google Workspace

    taracodlabs/aiden

    Gmail, Calendar, Drive, Sheets, Docs via Google API (SA / OAuth)

    849 GitHub stars~1.1k tokensUpdated 24 days ago
    Documents & OfficeAuto-check passed
  • GCP Workspace Pivot

    wgpsec/AboutSecurity

    GCP 到 Google Workspace 的穿越攻击方法论。当已获取 GCP Service Account 或 Project 权限并发现目标组织使用 Google Workspace、需要从云平台穿越到企业邮件/文档/管理控制台、或发现 Domain-Wide Delegation 配置时使用。覆盖 Domain-Wide Delegation 滥用、OAuth…

    1.8k GitHub stars~2.9k tokensUpdated 4 days ago
    Backend & APIsAuto-check passed
  • Community Google Workspace

    ArgentAIOS/argentos-core

    Gmail, Calendar, Drive, Contacts, Sheets, and Docs integration for community skills.

    126 GitHub stars~2.8k tokensUpdated 3 mo ago
    Documents & OfficeAuto-check passed
  • Google Workspace

    Tommy-yw/RunbookHermes

    Gmail, Calendar, Drive, Contacts, Sheets, and Docs integration for Hermes.

    546 GitHub starsUsed in 1 repo~2.7k tokens
    Documents & OfficeAuto-check passed
  • Google Workspace

    ericrisco/rsc-harness

    A skill your agent uses when server-side code reads or writes Gmail, Drive, Calendar, or Sheets with a GCP service account and no human in the OAuth loop: picking the auth mode (app-owned vs…

    156 GitHub stars~3.2k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Google Workspace

    google/adk-recipes

    Official

    Read/write Google Drive, Docs, Sheets, Gmail, Calendar, Chat, Tasks, Slides via the gws CLI.

    10k GitHub stars~4.6k tokensUpdated 2 days ago
    Documents & OfficeAuto-check passed

More from jezweb/claude-skills

All 52 skills in this repo
  • Elevenlabs Agents

    jezweb/claude-skills

    Build conversational AI voice agents on the ElevenLabs platform.

    1.1k GitHub starsUsed in 1 repo~3.3k tokens
    Auto-check passed
  • Favicon Gen

    jezweb/claude-skills

    Generate custom favicons from logos, text, or brand colours.

    1.1k GitHub starsUsed in 1 repo~1k tokens
    Auto-check passed
  • Tailwind Theme Builder

    jezweb/claude-skills

    Set up Tailwind v4 + shadcn/ui themed UI with dark mode. An agent skill from jezweb/claude-skills.

    1.1k GitHub starsUsed in 1 repo~3.2k tokens
    Auto-check passed
  • Responsiveness Check

    jezweb/claude-skills

    Test website responsiveness across viewport widths using browser automation.

    1.1k GitHub starsUsed in 1 repo~1.7k tokens
    Auto-check passed
  • MCP Builder

    jezweb/claude-skills

    Build MCP servers in Python with FastMCP. An agent skill from jezweb/claude-skills.

    1.1k GitHub stars~3.1k tokensUpdated 2 days ago
    Auto-check: notes
  • UX Compare

    jezweb/claude-skills

    Compare UX patterns across multiple reference apps using pattern libraries produced by ux-extract.

    1.1k GitHub starsUsed in 1 repo~2.2k tokens
    Auto-check passed

Questions about Gws Setup

What does Gws Setup do?

Set up the Google Workspace CLI (gws) from scratch. An agent skill from jezweb/claude-skills. Gws Setup is an agent skill from jezweb/claude-skills. Set up the Google Workspace CLI (gws) from scratch.

When should I use Gws Setup?

Gws Setup fits situations like: the user wants to set up gws for the first time; configure Google Workspace API access; install the Google Workspace CLI; troubleshoot gws auth issues.

How do I install Gws Setup in Claude Code?

Run `npx skills add jezweb/claude-skills --skill gws-setup -a claude-code`. Or copy the skill folder (plugins/integrations/skills/gws-setup in jezweb/claude-skills) into .claude/skills/gws-setup in your project. Claude Code loads it when a task matches its description.

How do I install Gws Setup in Codex?

Run `npx skills add jezweb/claude-skills --skill gws-setup -a codex`. Or copy the skill folder (plugins/integrations/skills/gws-setup in jezweb/claude-skills) into .agents/skills/gws-setup in your project. Codex loads it when a task matches its description.

Can I use Gws Setup in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jezweb/claude-skills --skill gws-setup -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/gws-setup, .gemini/skills/gws-setup, .github/skills/gws-setup and .opencode/skills/gws-setup in your project.

What does Gws Setup need to run?

Going by SKILL.md and its folder, Gws Setup needs the command-line tools its instructions call (npm and npx) and credentials named GOOGLE_WORKSPACE_CLI_CLIENT_SECRET. Our summary lists: Node.js; A credential in GOOGLE_WORKSPACE_CLI_CLIENT_SECRET. Compatibility (from SKILL.md): claude-code-only.

Does Gws Setup access the network?

SKILL.md names 3 domains. In commands or code: console.cloud.google.com, accounts.google.com and oauth2.googleapis.com; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is Gws Setup safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Gws Setup use?

Gws Setup is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Gws Setup use?

About 2.3k tokens (SKILL.md is roughly 9.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Gws Setup?

Skills that share tags, products or a category with Gws Setup: Google Workspace (taracodlabs/aiden, 849 stars), GCP Workspace Pivot (wgpsec/AboutSecurity, 1.8k stars), Community Google Workspace (ArgentAIOS/argentos-core, 126 stars) and Google Workspace (Tommy-yw/RunbookHermes, 546 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Gws Setup?

jezweb (a GitHub user) maintains it in jezweb/claude-skills, which has 1,050 GitHub stars. The repository holds 52 skills in this directory. The repository was last updated on October 5, 2026.

Source: jezweb/claude-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.