How to Connect Google Workspace to OpenClaw
Blog

How to Connect Google Workspace to OpenClaw

The Google Workspace CLI repository advertises 100+ agent skills and 50 curated recipes for Gmail, Calendar, Drive, Docs, and Sheets. This guide walks through creating a Google Cloud project, setting up OAuth credentials, installing the CLI and its skills, and choosing least-privilege scopes. It also explains Google's Developer Preview remote MCP servers and why Google Analytics requires a separate integration.

TL;DR
  • The Google Workspace CLI repository advertises 100+ agent skills and 50 curated recipes
  • Install the CLI and its agent skills separately; the CLI is not an officially supported Google product
  • Google's remote MCP servers for Gmail, Drive, and Calendar are currently in Developer Preview
  • Create a Google Cloud project, enable only the APIs you need, and configure OAuth credentials
  • Start with least-privilege scopes, then expand permissions only when a workflow requires them
  • Google Analytics requires a separate integration; enabling its API alone does not expose it to OpenClaw
OpenClaw Direct Team ·

OpenClaw skills for Google Workspace integration let your agent read Gmail, check Google Calendar, find files in Drive, and work with Docs and Sheets. The Google Workspace CLI repository includes 100+ agent skills, so you can connect the services where your work already happens instead of leaving your assistant locked out of the office.

This guide covers the CLI skills path and Google’s newer remote Workspace MCP servers, plus Google Cloud setup, OAuth credentials, permissions, and security. The CLI project is hosted in Google’s Workspace organization but is not an officially supported Google product; the remote MCP servers are currently in Developer Preview.

OpenClaw Skills: Google Workspace Integration Setup

The setup has five steps: start a working OpenClaw agent, create a Google Cloud project, enable the Workspace APIs you need, create OAuth credentials, and connect either the CLI skills or a compatible MCP client. Start with read-only access; add write permissions only when a workflow requires them.

  1. Start OpenClaw and confirm that your agent responds.
  2. Create a project in Google Cloud Console.
  3. Enable the Gmail, Calendar, Drive, Docs, or Sheets APIs you need.
  4. Create a Desktop app OAuth client and add your account as a test user.
  5. Install the CLI and its skills, or configure Google’s Developer Preview MCP servers in a compatible client.

Before you connect anything to Google Workspace, you need an OpenClaw agent that’s actually running. If you haven’t set one up yet, you can sign up at openclaw.direct or use a self-hosted OpenClaw installation.

OpenClaw Direct hosts your agent for you, so there’s no server or Docker installation to maintain. If you already have OpenClaw running locally or on your own VPS, that works too.

Either way, make sure your agent is responding to messages before you move on. Send it a quick “hello” and confirm it replies. Good? Let’s keep going.

Why Use OpenClaw Skills With Google Workspace?

There’s a reason the most recommended tools for OpenClaw almost always include Google Workspace. It’s not because it’s the flashiest integration or the one that demos the best at conferences.

It’s because Google Workspace is where your work actually happens. Your inbox is your to-do list, your calendar is your commitment ledger, your Drive is your filing cabinet, and your Sheets are your dashboards. An AI agent without access to these services is operating blind, no matter how intelligent the model underneath might be.

The Google Workspace CLI is built for both people and AI agents. Its repository advertises 100+ agent skills and 50 curated recipes covering Gmail, Calendar, Drive, Docs, and Sheets. It is actively developed and still approaching version 1.0, so expect its commands and setup details to change.

The CLI builds commands dynamically from Google’s Discovery Service for supported Workspace APIs, including Gmail, Calendar, Drive, Sheets, Docs, Slides, Chat, Tasks, Keep, and Meet. Each API remains subject to its current quota and billing rules.

Two OpenClaw Google Workspace Integration Options

The CLI skills cover a broad set of Workspace APIs and packaged workflows. Google also offers remote Model Context Protocol (MCP) servers for Gmail, Drive, and Calendar, but they are currently in the Google Workspace Developer Preview Program and require a compatible MCP client.

Install Google Workspace CLI Skills for OpenClaw

Install the CLI with npm install -g @googleworkspace/cli. Then install its agent skills separately with npx skills add https://github.com/googleworkspace/cli, or copy only the skills you need into ~/.openclaw/skills/.

Each skill is a self-contained SKILL.md file that teaches the agent how to call the CLI. The repository also includes curated multi-step recipes, such as summarizing unread email and calendar events.

Use Google’s Remote Workspace MCP Servers

Google’s current Workspace MCP documentation lists separate remote servers for Gmail, Drive, and Calendar. Setup requires Developer Preview enrollment, a Google Cloud project, the relevant APIs and MCP services, OAuth, and an MCP-capable client.

Choose the CLI when you want broader Workspace coverage and packaged skills. Choose the remote MCP servers when your client supports MCP and you need the currently available Gmail, Drive, or Calendar tools. Follow the setup instructions for the path you choose; their authentication and configuration steps are not interchangeable.

Setting Up Your Google Cloud Project

This sounds intimidating. It isn’t.

Everything your agent needs to access Google Workspace flows through a Google Cloud project, and creating one is free. You can even have your OpenClaw agent walk you through it step by step while you do the clicking.

Head to console.cloud.google.com and create a new project. Name it something descriptive like “OpenClaw Workspace” — you’ll thank yourself later when you have multiple projects and can’t remember which is which. Once the project is created, navigate to “APIs & Services” and click “Library.”

Search for and enable each API you want. At minimum: Gmail API, Google Calendar API, and Google Drive API. Want spreadsheets? Enable Sheets too.

Google Analytics is separate from the current Workspace CLI skill index. Enabling the Google Analytics Data API in the same Cloud project does not automatically expose Analytics to OpenClaw; you still need a separate Analytics integration and the appropriate property access and OAuth scopes.

Creating Your OAuth Credentials

With the APIs enabled, configure the OAuth consent screen. Choose “External” for a personal account or an app used outside your organization. Choose “Internal” only when the Cloud project belongs to your Google Workspace organization and access should be limited to that organization. Fill in the app name, support email, and developer contact.

Now here’s the step that trips up almost everyone.

For an external app in Testing, add your Google account under “Test users.” Only listed test users can authorize the app, and refresh tokens for external testing apps generally expire after seven days. For a long-running integration, review Google’s publishing and verification requirements rather than assuming Testing mode is permanent.

Next, go to “Credentials” and click “Create Credentials,” then “OAuth client ID.” Select “Desktop app” as the application type, give it a name, and click create. Google will show you a client ID and client secret — download the JSON file and save it to ~/.config/gws/client_secret.json.

Treat this file like a password. Don’t commit it to Git, don’t share it, don’t leave it in a public directory.

Connecting Gmail: Your Agent’s Most Powerful New Ability

With the Cloud project and credentials in place, this is where things get exciting. Run gws auth login (or just tell your OpenClaw agent to do it), and a browser window opens asking you to authorize the app.

Pay attention to the permissions list. If your agent only needs to read email, request https://www.googleapis.com/auth/gmail.readonly. You can expand access later. Starting narrow is smart.

Once authorized, your agent can search your inbox, read specific messages, and check for unread mail from particular senders. Google’s current Gmail API limits include both a 1.2 million-unit project limit and a much lower 6,000-unit per-user-per-project limit per minute, so the lower user limit usually matters more for a personal agent.

A useful first workflow is email triage. Tell your agent something like “every morning, check my inbox for emails from clients, flag anything that needs a response today, and send me a summary on Telegram.” Combined with a scheduled cron job, it can deliver that summary automatically.

Adding Google Calendar: Your Agent Learns Your Schedule

Calendar integration turns your agent from smart to contextually aware. That’s a bigger leap than it sounds.

When your agent knows your schedule, it can warn you about back-to-back meetings, suggest prep time before important calls, and — when combined with Gmail — tell you that the person you’re meeting at 2 PM sent you an email at midnight you haven’t read yet. That kind of ambient awareness is what separates “I have an AI tool” from “I have an AI assistant that actually understands my day.”

Setup mirrors what you did for Gmail. Use https://www.googleapis.com/auth/calendar.readonly for read-only calendar access, or https://www.googleapis.com/auth/calendar.events if the agent must create and modify events. Calendar requests remain subject to Google’s current quotas.

Here’s a pattern people tend to overlook: ask your agent to cross-reference your calendar with your research monitoring. If you’ve got proactive research monitoring set up, your agent can surface relevant industry news before meetings with specific clients. Walking into a call already knowing that your client’s company just raised a funding round? That used to require a dedicated research analyst. Now it’s a cron job.

Google Drive: Giving Your Agent a Filing Cabinet

Drive extends your agent’s reach into documents and files. Search by name or content, read documents and spreadsheets, create new files, and organize folders. Google’s current Drive API limits use quota units per minute and include a 750 GB daily upload-and-copy limit per Google Workspace user across My Drive and shared drives.

A narrow scope to consider is https://www.googleapis.com/auth/drive.file. It limits access to files the app creates or that the user explicitly opens or shares with the app, rather than exposing the entire Drive. Expand access only when the workflow requires it.

The workflow that tends to unlock the most value? Automated reporting. Connect Drive with Sheets and your agent pulls data from spreadsheets, analyzes trends, and saves summaries directly to a shared folder. If you run a team, you can have a weekly performance report waiting in a shared folder every Monday morning. No dashboard logins, no copy-pasting between tabs. Just a finished document ready when your team arrives.

Google Analytics Requires a Separate Integration

The current Workspace CLI skills index does not list Google Analytics. To let an agent answer questions such as “how did my blog do last week?”, configure the Google Analytics Data API separately with access to the relevant GA4 property. Merely enabling the API in the Cloud project is not enough.

Combine this with the morning briefing pattern and you get something genuinely useful. Your agent wakes up at 7 AM, pulls email highlights, checks your calendar, grabs analytics data, and delivers one synthesized message: “You have three meetings today, the earliest at 10 AM. Two client emails need responses. Blog traffic was up 12% yesterday, with the new post on AI-powered blog SEO driving most of the growth. Your top keyword gained two positions.”

That’s not a collection of data points. That’s a briefing from an assistant that understands how your work connects.

How Should You Handle Security?

Connecting an agent to email, calendars, and files requires deliberate guardrails. Google’s OAuth scopes let you limit permissions, but you also need to review how your OpenClaw host, model provider, logs, and backups handle Workspace data.

The current gws CLI encrypts stored credentials with AES-256-GCM and keeps the encryption key in the operating system keyring, or in a local key file when its file backend is configured. That protects stored credentials; it does not guarantee that message or file contents stay on the same machine while the agent processes them.

Start read-only where possible. Grant only the Gmail, Calendar, and Drive scopes needed for the workflow. Watch what your agent does before considering write permissions.

Want your agent to manage your calendar? Add the calendar.events scope. To send email, use gmail.send; to create and manage drafts, use gmail.compose. Each expansion should be a deliberate choice, not a blanket grant.

What Your Morning Looks Like After Setup

Remember that brilliant assistant locked out of the office? They’ve got the keys now.

Your agent wakes up before you do (assuming you’ve set up cron jobs), scans your inbox, checks your calendar, pulls analytics, and sends one concise morning briefing. Throughout the day, it monitors your email and nudges you when something genuinely needs attention. Before each meeting, it surfaces recent emails from that contact, related documents in Drive, research it’s flagged. When you ask it to draft a follow-up or create a meeting summary, it saves to Drive and shares with the right people.

Gartner projected that 40% of enterprise applications would feature task-specific AI agents by the end of 2026, up from less than 5% in 2025. The practical value still depends on choosing narrow, repeatable workflows and reviewing their results.

And if you signed up at OpenClaw Direct like we suggested at the start, all of this runs around the clock without you thinking about it. Morning briefings fire when they’re supposed to. Email monitors keep watching. Your agent keeps working when you’re not — which is kind of the whole point.

Frequently Asked Questions

Does connecting Google Workspace to OpenClaw cost anything?

Standard use of Gmail, Drive, and Calendar APIs is currently available at no additional cost within documented limits. Google’s current quota pages say charges for usage beyond daily thresholds are planned later in 2026. Your OpenClaw hosting and model usage may still have separate costs.

Is it safe to give my AI agent access to my email?

It can be, if you limit access and understand the data path. Start with gmail.readonly so the agent can read but not send or modify email. Then review your OpenClaw host, model provider, logging, and retention settings before processing sensitive messages. Our AI agent safety guide covers more best practices.

Which OpenClaw Google Workspace integration should I choose — CLI or MCP?

For broader Workspace coverage and packaged skills, use the Google Workspace CLI. If you are enrolled in Google’s Developer Preview and your client supports MCP, consider the separate remote servers for Gmail, Drive, and Calendar. Follow each option’s current setup instructions rather than assuming their configuration is interchangeable.

Can I connect Google Workspace to OpenClaw on a VPS or server?

Yes. For the current CLI’s documented headless flow, authenticate on a machine with a browser, export credentials with gws auth export --unmasked > credentials.json, transfer that file securely, and set GOOGLE_WORKSPACE_CLI_CREDENTIALS_FILE on the server. Treat the exported file as a secret.

Do I need an OpenClaw account to get started?

You need a running OpenClaw agent. You can use OpenClaw Direct for managed hosting or self-host OpenClaw and manage the server yourself.


Sources: Google Workspace CLI repository and setup guide, Google Workspace MCP server documentation, Google OAuth consent guidance, Gmail API usage limits, Drive API usage limits, Gmail OAuth scopes, and Drive OAuth scopes.