Google Workspace Mcp — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Google Workspace Mcp (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
<!-- mcp-name: io.github.aringad/google-workspace-mcp -->
🇮🇹 Italiano | 🇬🇧 English
Server MCP (Model Context Protocol) per gestire Google Workspace tramite Claude AI e altri assistenti compatibili. Permette di amministrare utenti, gruppi, alias e unità organizzative tramite conversazione naturale.
| Tool | Descrizione |
|---|---|
gw_list_users | Lista utenti con ricerca e filtri |
gw_get_user | Dettaglio completo di un utente |
gw_create_user | Crea nuovo utente con password auto-generata |
gw_delete_user | Elimina utente (con conferma obbligatoria) |
gw_suspend_user | Sospendi o riattiva un utente |
gw_reset_password | Reset password con generazione automatica |
gw_manage_alias | Aggiungi, rimuovi, elenca alias email |
gw_list_groups | Lista gruppi del dominio o di un utente |
gw_manage_group_member | Aggiungi/rimuovi membri dai gruppi |
gw_list_org_units | Lista unità organizzative |
gw_move_user_org | Sposta utente tra unità organizzative |
pip install google-workspace-mcpOppure da sorgente:
git clone https://github.com/aringad/google-workspace-mcp.git
cd google-workspace-mcp
pip install -r requirements.txt#### 1. Crea progetto e abilita API
#### 2. Crea Service Account
mcp-workspace-admin)⚠️ Non serve assegnare ruoli IAM al Service Account. I permessi vengono dalla delega domain-wide.
#### 3. Delega Domain-Wide
https://www.googleapis.com/auth/admin.directory.user,https://www.googleapis.com/auth/admin.directory.group,https://www.googleapis.com/auth/admin.directory.orgunit,https://www.googleapis.com/auth/admin.directory.user.alias| Variabile | Descrizione | Default |
|---|---|---|
GOOGLE_SERVICE_ACCOUNT_FILE | Path al file JSON delle credenziali | ./credentials.json |
GOOGLE_ADMIN_EMAIL | Email del super admin con delega | (obbligatorio) |
GOOGLE_CUSTOMER_ID | Customer ID del dominio | my_customer |
Aggiungi al file di configurazione:
~/Library/Application Support/Claude/claude_desktop_config.json%APPDATA%\Claude\claude_desktop_config.json{
"mcpServers": {
"google_workspace": {
"command": "/percorso/completo/google-workspace-mcp/venv/bin/python",
"args": ["/percorso/completo/google-workspace-mcp/server.py"],
"env": {
"GOOGLE_SERVICE_ACCOUNT_FILE": "/percorso/completo/credentials.json",
"GOOGLE_ADMIN_EMAIL": "[email protected]"
}
}
}
}Chiudi completamente Claude Desktop (Cmd+Q su Mac) e riaprilo.
#### 🏢 Configurazione multi-cliente
Puoi gestire più domini aggiungendo istanze separate:
{
"mcpServers": {
"gw_cliente_alfa": {
"command": "/percorso/venv/bin/python",
"args": ["server.py"],
"env": {
"GOOGLE_SERVICE_ACCOUNT_FILE": "/percorso/credentials-alfa.json",
"GOOGLE_ADMIN_EMAIL": "[email protected]"
}
},
"gw_cliente_beta": {
"command": "/percorso/venv/bin/python",
"args": ["server.py"],
"env": {
"GOOGLE_SERVICE_ACCOUNT_FILE": "/percorso/credentials-beta.json",
"GOOGLE_ADMIN_EMAIL": "[email protected]"
}
}
}
}Una volta configurato, puoi dire a Claude:
Puoi anche copiare direttamente l'email del cliente con la richiesta e Claude interpreterà automaticamente le operazioni da eseguire.
# Verifica che il server parta
python server.py --help
# Test con MCP Inspector
npx @modelcontextprotocol/inspector python server.py<a name="english"></a>
MCP (Model Context Protocol) Server to integrate Google Workspace Admin with Claude AI and other compatible assistants. Manage users, groups, aliases and organizational units through natural conversation.
| Tool | Description |
|---|---|
gw_list_users | List users with search and filters |
gw_get_user | Full user details |
gw_create_user | Create new user with auto-generated password |
gw_delete_user | Delete user (requires explicit confirmation) |
gw_suspend_user | Suspend or reactivate a user |
gw_reset_password | Reset password with automatic generation |
gw_manage_alias | Add, remove, list email aliases |
gw_list_groups | List domain or user groups |
gw_manage_group_member | Add/remove group members |
gw_list_org_units | List organizational units |
gw_move_user_org | Move user between organizational units |
pip install google-workspace-mcpOr from source:
git clone https://github.com/aringad/google-workspace-mcp.git
cd google-workspace-mcp
pip install -r requirements.txt#### 1. Create project and enable API
#### 2. Create Service Account
mcp-workspace-admin)⚠️ No IAM roles needed on the Service Account. Permissions come from domain-wide delegation.
#### 3. Domain-Wide Delegation
https://www.googleapis.com/auth/admin.directory.user,https://www.googleapis.com/auth/admin.directory.group,https://www.googleapis.com/auth/admin.directory.orgunit,https://www.googleapis.com/auth/admin.directory.user.alias| Variable | Description | Default |
|---|---|---|
GOOGLE_SERVICE_ACCOUNT_FILE | Path to credentials JSON file | ./credentials.json |
GOOGLE_ADMIN_EMAIL | Super admin email with delegation | (required) |
GOOGLE_CUSTOMER_ID | Domain customer ID | my_customer |
Add to config file:
~/Library/Application Support/Claude/claude_desktop_config.json%APPDATA%\Claude\claude_desktop_config.json{
"mcpServers": {
"google_workspace": {
"command": "/full/path/to/google-workspace-mcp/venv/bin/python",
"args": ["/full/path/to/google-workspace-mcp/server.py"],
"env": {
"GOOGLE_SERVICE_ACCOUNT_FILE": "/full/path/to/credentials.json",
"GOOGLE_ADMIN_EMAIL": "[email protected]"
}
}
}
}Fully quit Claude Desktop (Cmd+Q on Mac) and reopen it.
Once configured, you can tell Claude:
You can also paste client emails with requests directly — Claude will automatically interpret the operations to perform.
# Verify server starts
python server.py --help
# Test with MCP Inspector
npx @modelcontextprotocol/inspector python server.pyMIT License — See LICENSE for details.
Developed by [Mediaform s.c.r.l.](https://www.media-form.it) — Genova, Italy
Built with [MCP](https://modelcontextprotocol.io) and [Google Admin SDK](https://developers.google.com/admin-sdk)
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.