This page covers the four Workspace data tools, how they are enabled, where their credentials live, and the honest state of the setup flow.
Tools
| Tool | Purpose | Actions | Key params |
|---|---|---|---|
google_calendar | List/manage calendar events | list, get, create, update, delete, search | event_id, summary, description, start, end, location, attendees, query, max_results, calendar_id |
google_contacts | Read-only contact lookup | search, list | query, max_results |
google_drive | Browse/read/create Drive files | list, search, read, info, create | file_id, query, name, content, mime_type, max_results |
google_tasks | Manage task lists and tasks | lists, tasks, create, complete, delete | tasklist_id, task_id, title, notes, due, max_results |
Notes:
google_calendarstart/endare ISO 8601 datetimes (e.g.2026-04-10T14:00:00+03:00).attendeesis a comma-separated list of email addresses.calendar_iddefaults toprimary.google_drivequeryuses Drive search syntax. Forcreate,mime_typedefaults totext/plain; useapplication/vnd.google-apps.documentto create a Google Doc.google_taskstasklist_iddefaults to@default.dueis an ISO 8601 date.google_contactsis read-only (search/list only).
API base URLs used: Calendar API v3, People API (contacts), Drive API v3, Tasks API v1.
Connect and choose access
In Desktop, open Gmail for the selected agent, or review a Google connection request in chat. Choose Gmail management and any optional Calendar, Drive, Contacts or Tasks access before continuing to Google. Google presents its own consent screen. The app shows which permissions were actually granted; declined services remain unavailable. “Extend Google access” adds services later while keeping the old connection until the new authorization succeeds for the same Google account.
From a terminal:
flowly gmail connect --services gmail,gmail_manage,calendar,drive,contacts,tasks
flowly gmail connect --extend --services gmail,gmail_manage,tasksThe plain flowly gmail connect command keeps the original Gmail read/send
selection. Native tools become available without restarting the agent after
consent. The separate integrations.googleWorkspace.enabled card still refers
to the optional CLI setup below, not native tool permission grants.
Credentials and permissions
Managed connections store a profile-local grant secret and short-lived access
token under credentials/gmail.json; the broker retains encrypted Google refresh
tokens. OAuth client secrets and refresh tokens are not sent to the agent or chat.
Historical local OAuth credential files remain supported.
| Access | OAuth scopes |
|---|---|
| Gmail read/send | gmail.readonly, gmail.send |
| Gmail management | gmail.modify (includes read/send; no immediate permanent deletion) |
| Calendar | calendar.events |
| Drive | drive.readonly, drive.file (browse/read existing files, create new files) |
| Contacts | contacts.readonly |
| Tasks | tasks |
Google API scopes above use the https://www.googleapis.com/auth/ prefix.
Enabled tools are bounded by both requested services and actual granted scopes.
Sending, Gmail management and Workspace writes require approval. There are no
native full-document editing tools for Sheets or Docs in this integration.
flowly setup google-workspace
A separate setup wizard exists:
flowly setup google-workspaceThis wizard installs and authenticates the Google Workspace CLI (gws):
- Installs
gwsvianpm install -g @googleworkspace/cli(Node.js required). - Installs the
gcloudCLI (Homebrew on macOS, apt on Linux) if missing. - Runs
gws auth setupthengws auth login. - On success, sets
integrations.googleWorkspace.enabled = true, records the detected account email, enables theexectool, and allowlists thegwsbinary so the agent can rungws *commands without per-command approval.
gws command-line path (driven through the exec tool), which is distinct from the native google_calendar/google_drive/google_contacts/google_tasks tools. Native tools use the profile-local Google connection and granted service permissions. Both paths can coexist.