Back to Browse

Google Calendar MCP Server

Developer ToolsUse Caution4.2MCP RegistryLocal
Free

Server data from the Official MCP Registry

Allow AI systems to list, create, update, and manage Google Calendar events.

About

Allow AI systems to list, create, update, and manage Google Calendar events.

Security Report

4.2
Use Caution4.2High Risk

This Google Calendar MCP server implements OAuth delegation with reasonable security practices, but has several concerns that warrant attention. The server properly requires authentication for most operations, implements token validation, and avoids hardcoding secrets. However, the token validation mechanism has a critical flaw (caching based on opaque tokens without verification), the /authorize endpoint lacks CSRF protection, and there are input validation gaps in multiple tools. These issues are mitigated by the fact that tokens originate from Google's OAuth flow and the server operates as a proxy, but the implementation should be hardened. Supply chain analysis found 5 known vulnerabilities in dependencies (1 critical, 2 high severity). Package verification found 1 issue (1 critical, 0 high severity).

7 files analyzed · 16 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

env_vars

Check that this permission is expected for this type of plugin.

HTTP Network Access

Connects to external APIs or services over the internet.

File System Read

Reads files on your machine. Normal for tools that analyze or process local data.

File System Write

Writes or modifies files on your machine. Check that this is expected for the tool.

Unverified package source

We couldn't verify that the installable package matches the reviewed source code. Proceed with caution.

What You'll Need

Set these up before or after installing:

Google OAuth access token with Calendar scopes.Required

Environment variable: GOOGLE_ACCESS_TOKEN

Transport type.Optional

Environment variable: MCP_TRANSPORT

Google OAuth client ID.Optional

Environment variable: GOOGLE_CLIENT_ID

Google OAuth client secret.Required

Environment variable: GOOGLE_CLIENT_SECRET

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "io-github-domdomegg-google-cal-mcp": {
      "env": {
        "MCP_TRANSPORT": "your-mcp-transport-here",
        "GOOGLE_CLIENT_ID": "your-google-client-id-here",
        "GOOGLE_ACCESS_TOKEN": "your-google-access-token-here",
        "GOOGLE_CLIENT_SECRET": "your-google-client-secret-here"
      },
      "args": [
        "-y",
        "google-cal-mcp"
      ],
      "command": "npx"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

google-cal-mcp

MCP server for Google Calendar - list, create, update, and manage calendar events.

Use Cases

Schedule meetings: "Set up a 30-min sync with Sarah next week" → finds a free slot, creates the event with a Meet link, and sends the invite.

RSVP to invites: "Accept the team offsite but decline the vendor demo" → responds to pending invitations automatically.

Find availability: "When am I free this Thursday afternoon?" → queries your calendar and returns open slots.

Reschedule events: "Move my 1:1 with Alex to Friday at 2pm" → updates the event and notifies attendees.

Daily briefing: "What's on my calendar today?" → lists all events with times, locations, and attendees.

Block focus time: "Block 2 hours tomorrow morning for deep work" → creates a calendar event to protect your time.

(These are just examples - any workflow that needs calendar access can use this.)

Setup

1. Create Google OAuth credentials

  1. Go to Google Cloud Console
  2. Create a new project (or use existing)
  3. Enable the Google Calendar API
  4. Go to APIs & ServicesOAuth consent screen, set up consent screen
  5. Go to APIs & ServicesCredentialsCreate CredentialsOAuth client ID
  6. Choose Web application
  7. Add http://localhost:3000/callback to Authorized redirect URIs
  8. Note your Client ID and Client Secret

2. Run the server

GOOGLE_CLIENT_ID='your-client-id' \
GOOGLE_CLIENT_SECRET='your-client-secret' \
MCP_TRANSPORT=http \
npm start

The server runs on http://localhost:3000 by default. Change with PORT=3001.

3. Add to your MCP client

With the server running, follow the instructions on install-mcp, which generates the right config for your MCP client (Claude Code, Claude Desktop, Cursor, Cline, VS Code, and more).

Architecture

This server acts as an OAuth proxy to Google:

graph LR
    A[MCP client] <--> B[google-cal-mcp] <--> C[Google OAuth/API]
  1. Server advertises itself as an OAuth authorization server via /.well-known/oauth-authorization-server
  2. /register returns the Google OAuth client credentials
  3. /authorize redirects to Google, encoding the client's callback URL in state
  4. /callback receives the code from Google and forwards to the client's callback
  5. /token proxies token requests to Google, injecting client credentials
  6. /mcp handles MCP requests, using the bearer token to call Calendar API

The server holds no tokens or state - it just proxies OAuth to Google.

Tools

ToolDescription
Calendars
calendars_listList all calendars the user has access to
calendarlist_insertSubscribe to a shared calendar
calendarlist_updateUpdate calendar settings (color, visibility, reminders)
calendarlist_deleteUnsubscribe from a calendar
Events
events_listList events in a time range with search/filter
event_getGet details of a specific event
event_createCreate a new event with attendees and Meet link
event_updateUpdate an existing event
event_deleteDelete an event
event_respondRSVP to an invitation (accept/decline/tentative)
event_moveMove event to a different calendar
event_instancesGet instances of a recurring event
Availability
freebusy_queryFind free/busy times for scheduling
Sharing
acl_listList who has access to a calendar
Colors
colors_getGet available color palette for calendars/events

Calendar API Scopes

  • calendar - Full access to calendars
  • calendar.events - Read/write events

Contributing

Pull requests are welcomed on GitHub! To get started:

  1. Install Git and Node.js
  2. Clone the repository
  3. Install dependencies with npm install
  4. Run npm run test to run tests
  5. Build with npm run build

Releases

Versions follow the semantic versioning spec.

To release:

  1. Use npm version <major | minor | patch> to bump the version
  2. Run git push --follow-tags to push with tags
  3. Wait for GitHub Actions to publish to the NPM registry.

Reviews

No reviews yet

Be the first to review this server!