Back to Browse

Google Apps Script MCP Server

Developer ToolsLow Risk10.0MCP RegistryLocal
Free

Server data from the Official MCP Registry

MCP server for the Google Apps Script API: projects, code, versions, deployments and executions.

About

MCP server for the Google Apps Script API: projects, code, versions, deployments and executions.

Security Report

10.0
Low Risk10.0Low Risk

Valid MCP server (1 strong, 1 medium validity signals). No known CVEs in dependencies. Package registry verified. Imported from the Official MCP Registry. Trust signals: trusted author (13/13 approved).

4 files analyzed · 1 issue found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

HTTP Network Access

Connects to external APIs or services over the internet.

What You'll Need

Set these up before or after installing:

Google OAuth2 client id (refresh-token flow).Optional

Environment variable: GOOGLE_APPS_SCRIPT_CLIENT_ID

Google OAuth2 client secret (refresh-token flow). Treat it as a secret.Required

Environment variable: GOOGLE_APPS_SCRIPT_CLIENT_SECRET

Google OAuth2 refresh token, exchanged for access tokens automatically. Treat it as a secret.Required

Environment variable: GOOGLE_APPS_SCRIPT_REFRESH_TOKEN

Static OAuth2 access token (~1h lifetime) — alternative to the refresh-token trio, mostly for testing.Required

Environment variable: GOOGLE_APPS_SCRIPT_ACCESS_TOKEN

API root override.Optional

Environment variable: GOOGLE_APPS_SCRIPT_API_BASE

Per-request timeout in milliseconds.Optional

Environment variable: GOOGLE_APPS_SCRIPT_TIMEOUT_MS

Retries on transient errors (429 always; 5xx/network for reads).Optional

Environment variable: GOOGLE_APPS_SCRIPT_MAX_RETRIES

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "io-github-a1-x-tech-mcp-google-apps-script": {
      "env": {
        "GOOGLE_APPS_SCRIPT_API_BASE": "your-google-apps-script-api-base-here",
        "GOOGLE_APPS_SCRIPT_CLIENT_ID": "your-google-apps-script-client-id-here",
        "GOOGLE_APPS_SCRIPT_TIMEOUT_MS": "your-google-apps-script-timeout-ms-here",
        "GOOGLE_APPS_SCRIPT_MAX_RETRIES": "your-google-apps-script-max-retries-here",
        "GOOGLE_APPS_SCRIPT_ACCESS_TOKEN": "your-google-apps-script-access-token-here",
        "GOOGLE_APPS_SCRIPT_CLIENT_SECRET": "your-google-apps-script-client-secret-here",
        "GOOGLE_APPS_SCRIPT_REFRESH_TOKEN": "your-google-apps-script-refresh-token-here"
      },
      "args": [
        "-y",
        "mcp-google-apps-script"
      ],
      "command": "npx"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

Google Apps Script MCP

English | Русский

npm CI Glama License: MIT

A1 Google Apps Script MCP lets an AI app write and operate Google Apps Script in plain language. Create a script project, read and edit its code, snapshot versions, manage deployments, run functions and read the execution history.

It uses the Google Apps Script API with your Google account. It distinguishes the editable HEAD code from immutable versions and makes the limits of the Apps Script API explicit instead of implying that every scripting task is possible.

  • 13 tools. Create standalone and bound projects, read and update code files, snapshot immutable versions, manage deployments, run functions, and inspect execution history and metrics.
  • Versions are immutable. A version snapshots HEAD and can never be edited or deleted; deployments point at versions, so you ship and roll back without changing a URL.
  • The manifest always survives. Merge mode keeps the appsscript manifest and every file you did not mention; replace mode refuses a file set without the manifest before any network traffic.
  • Keep your scriptId. The API cannot list projects and cannot delete them — the scriptId returned by create_project is the only handle.
  • Minimal Google scopes. Each operation names its own scope (script.projects, script.deployments, script.processes, script.metrics); request only what your tasks need.

Start with a read-only question:

Show me the files in my report script and which functions failed this week.

Connect the server · Explore use cases · Open technical documentation


See it work in a minute

You: Show the code and the recent runs of my report script.

Assistant: Shows every file with its source and the execution history — which functions ran, when, and which failed. Nothing changes.

You: Add a formatDate helper to the Utils file and keep everything else as is.

Assistant: Shows the proposed source and confirms that merge mode leaves the other files untouched, then asks for confirmation before writing.

You: Confirm.

Assistant: Writes the file to HEAD. It does not create a version, redeploy or run anything unless you ask separately.

Contents

Quick start

You need Node.js 20+, a Google account and OAuth credentials from a Google Cloud project with the Google Apps Script API enabled.

  1. Prepare Google OAuth access.
  2. Add the server to your AI app.
  3. Ask the read-only question above.

In the app: open Settings → MCP servers, select Add server, choose STDIO, enter the command npx -y mcp-google-apps-script@latest and environment variables GOOGLE_APPS_SCRIPT_CLIENT_ID, GOOGLE_APPS_SCRIPT_CLIENT_SECRET, GOOGLE_APPS_SCRIPT_REFRESH_TOKEN, then select Save and Restart.

From the command line:

codex mcp add google-apps-script \
  --env GOOGLE_APPS_SCRIPT_CLIENT_ID=your_client_id \
  --env GOOGLE_APPS_SCRIPT_CLIENT_SECRET=your_client_secret \
  --env GOOGLE_APPS_SCRIPT_REFRESH_TOKEN=your_refresh_token \
  -- npx -y mcp-google-apps-script@latest
codex mcp list

Codex MCP documentation

claude mcp add \
  --env GOOGLE_APPS_SCRIPT_CLIENT_ID=your_client_id \
  --env GOOGLE_APPS_SCRIPT_CLIENT_SECRET=your_client_secret \
  --env GOOGLE_APPS_SCRIPT_REFRESH_TOKEN=your_refresh_token \
  --transport stdio --scope user google-apps-script \
  -- npx -y mcp-google-apps-script@latest
claude mcp list

Claude Code MCP documentation

The current official path is Settings → Extensions. For a custom desktop extension, open Advanced settings → Extension Developer → Install Extension…, select a .mcpb file and follow the prompts.

This repository currently publishes an npm stdio package and does not contain a .mcpb bundle. For Claude Desktop builds that still support local configuration, use the following JSON stdio configuration as a fallback:

{
  "mcpServers": {
    "google-apps-script": {
      "command": "npx",
      "args": ["-y", "mcp-google-apps-script@latest"],
      "env": {
        "GOOGLE_APPS_SCRIPT_CLIENT_ID": "your_client_id",
        "GOOGLE_APPS_SCRIPT_CLIENT_SECRET": "your_client_secret",
        "GOOGLE_APPS_SCRIPT_REFRESH_TOKEN": "your_refresh_token"
      }
    }
  }
}

In those builds, save it to ~/Library/Application Support/Claude/claude_desktop_config.json on macOS or %APPDATA%\Claude\claude_desktop_config.json on Windows.

Claude Desktop MCP documentation

Add this to ~/.cursor/mcp.json on macOS/Linux or %USERPROFILE%\.cursor\mcp.json on Windows:

{
  "mcpServers": {
    "google-apps-script": {
      "type": "stdio",
      "command": "npx",
      "args": ["-y", "mcp-google-apps-script@latest"],
      "env": {
        "GOOGLE_APPS_SCRIPT_CLIENT_ID": "your_client_id",
        "GOOGLE_APPS_SCRIPT_CLIENT_SECRET": "your_client_secret",
        "GOOGLE_APPS_SCRIPT_REFRESH_TOKEN": "your_refresh_token"
      }
    }
  }
}

Cursor MCP documentation

Run MCP: Open User Configuration and add:

{
  "servers": {
    "google-apps-script": {
      "type": "stdio",
      "command": "npx",
      "args": ["-y", "mcp-google-apps-script@latest"],
      "env": {
        "GOOGLE_APPS_SCRIPT_CLIENT_ID": "${input:apps_script_client_id}",
        "GOOGLE_APPS_SCRIPT_CLIENT_SECRET": "${input:apps_script_client_secret}",
        "GOOGLE_APPS_SCRIPT_REFRESH_TOKEN": "${input:apps_script_refresh_token}"
      }
    }
  },
  "inputs": [
    { "type": "promptString", "id": "apps_script_client_id", "description": "Google OAuth client ID" },
    { "type": "promptString", "id": "apps_script_client_secret", "description": "Google OAuth client secret", "password": true },
    { "type": "promptString", "id": "apps_script_refresh_token", "description": "Google OAuth refresh token", "password": true }
  ]
}

Check it with MCP: List Servers.

VS Code MCP documentation

What you can ask it to do

Inspect a project and its runs

  • Show this script's files and explain what each function does.
  • Which functions failed this week? Show the execution history for sendDigest.
  • How many users, executions and failures did this script have over the last 7 days?

Write and evolve code

  • Create a standalone project, or a script bound to a Doc, Sheet, Slides or Form.
  • Add a helper function to one file without touching the others.
  • Snapshot the current code as a version with a description before we refactor.

Ship, run and roll back

  • Deploy version 4 and show its entry points — web app URL or API-executable config.
  • Run sendDigest and show the result; if the script throws, show the stack trace.
  • Repoint the deployment back to version 3 without changing its URL.

How a project changes

  1. create_project creates a project — standalone, or bound to a Doc, Sheet, Slides or Form. Keep the returned scriptId: the API cannot list projects.
  2. Code lives at HEAD as files addressed by name without extension. update_project_content merges by default — it upserts the files you name and keeps the rest — and only replaces the entire set when asked; the appsscript manifest can never be deleted.
  3. create_version snapshots HEAD as an immutable version — no edit, no delete, numbers only grow.
  4. A deployment exposes a version as a web app or API executable. Updating a deployment repoints it at another version without changing its URL; the automatic @HEAD deployment cannot be deleted.

The API cannot delete a project either — that means deleting its Drive file, which this server does not cover. run_function requires an API-executable deployment, an OAuth client from the same Cloud project as the script and the script's own scopes on the token; Apps Script stops any execution after 6 minutes. The execution history shows status and timing but no error messages — those live in Cloud Logging or come from re-running the function.

What can change

OperationWhat happensConfirmation boundary
Read a project, its code, versions, runs or metricsReads dataNo change
Create a projectAdds a standalone or bound script projectChanges Google Apps Script
Update project filesOverwrites code at HEAD; replace mode swaps the entire file setChanges a project
Create a versionAdds an immutable snapshot that can never be removedChanges a project
Create or update a deploymentChanges what a live URL or API endpoint servesChanges a project's live behavior
Delete a deploymentPermanently breaks the deployment URLDestructive
Run a functionExecutes real code with real side effectsDestructive
Raw API requestCan call API methods without a dedicated toolPotentially destructive

The AI client controls confirmation prompts. The server marks reads, writes and destructive tools so the client can distinguish an inspection from a live change.

Getting access

The Google Apps Script API requires OAuth 2.0; an API key is not enough.

  1. Create or select a Google Cloud project and enable Google Apps Script API.

  2. Turn on the per-account toggle at script.google.com/home/usersettings — without it every call fails with 403.

  3. Configure the OAuth consent screen and create a Desktop app OAuth client.

  4. Authorize the Google account that owns the scripts. The OAuth 2.0 Playground can obtain the refresh token when Use your own OAuth credentials is enabled.

  5. Request the scopes for the tools you plan to use:

    https://www.googleapis.com/auth/script.projects
    https://www.googleapis.com/auth/script.deployments
    https://www.googleapis.com/auth/script.processes
    https://www.googleapis.com/auth/script.metrics
    

    For inspection-only use, replace the first two with the read-only variants script.projects.readonly and script.deployments.readonly; list_processes and get_project_metrics still need script.processes and script.metrics, which have no narrower form. run_function needs none of these scopes — instead the token must carry every scope the target script itself uses, and the OAuth client must belong to the same Cloud project as the script.

Testing-mode OAuth refresh tokens can expire after seven days. Publish the OAuth app, or use an Internal app in a Workspace domain, when you need long-lived access. Treat the client secret and refresh token as passwords.

The setup_instructions tool returns this same checklist and works even before credentials are configured.

Configuration

VariableRequiredDescription
GOOGLE_APPS_SCRIPT_CLIENT_IDYes*OAuth client ID.
GOOGLE_APPS_SCRIPT_CLIENT_SECRETYes*OAuth client secret.
GOOGLE_APPS_SCRIPT_REFRESH_TOKENYes*OAuth refresh token.
GOOGLE_APPS_SCRIPT_ACCESS_TOKENYes*Short-lived alternative to the OAuth trio.
GOOGLE_APPS_SCRIPT_API_BASENoGoogle Apps Script API base URL override.
GOOGLE_APPS_SCRIPT_TIMEOUT_MSNoPer-request timeout; default 60000 ms.
GOOGLE_APPS_SCRIPT_MAX_RETRIESNoTemporary-error retries; default 3.

* Provide either the OAuth trio or an access token.

Data, limits and background work

  • Requests go to Google Apps Script. The local server refreshes Google OAuth tokens and calls the Apps Script API. Its anonymous telemetry contains an installation ID, package version, AI client and platform versions, and tool names — never OAuth tokens, script sources, tool arguments or prompts. Set ASKADS_TELEMETRY=0 to opt out.
  • Writes are never replayed blindly. On 429, the server uses backoff; reads also retry after network and 5xx errors, while writes are not replayed after an uncertain failure — a duplicated create_version piles up immutable versions, and a duplicated run_function executes side effects twice. After an ambiguous failure, check list_versions or the execution history instead of re-sending.
  • There is no background polling. The server runs only when called, and a function executes only when you ask for it. Scripts keep their own Apps Script triggers on Google's side; if your AI app supports scheduled tasks, it can also check the execution history periodically.

Technical documentation

Support

Found a bug or need a scenario? Create an issue or write in Telegram.

Reviews

No reviews yet

Be the first to review this server!