{"_id":"@armoryworks/drive-mcp","_rev":"4-006231918c4ebb0c2addd93d69f598a8","name":"@armoryworks/drive-mcp","dist-tags":{"latest":"0.2.4"},"versions":{"0.1.0":{"name":"@armoryworks/drive-mcp","version":"0.1.0","keywords":["mcp","model-context-protocol","google-drive","google-docs","google-sheets","claude","anthropic"],"author":{"name":"Armory Works Technology, LLC"},"license":"MIT","_id":"@armoryworks/drive-mcp@0.1.0","maintainers":[{"name":"danielhokanson","email":"daniel.hokanson+npm@gmail.com"}],"homepage":"https://github.com/armoryworks/drive-mcp#readme","bugs":{"url":"https://github.com/armoryworks/drive-mcp/issues"},"bin":{"armoryworks-drive-mcp":"dist/index.js","armoryworks-drive-mcp-auth":"dist/auth-cli.js"},"dist":{"shasum":"dc465c8a13d0151559a020ec35478c00a44d788a","tarball":"https://registry.npmjs.org/@armoryworks/drive-mcp/-/drive-mcp-0.1.0.tgz","fileCount":36,"integrity":"sha512-O41MVuuRavg5wzN+M04mPVHrvUtG8PBYFkHDcsFNxBeADgaBXM4ogfHVfqhyb1fvNnTd5qtsLwc3yAf2lqKM7A==","signatures":[{"sig":"MEUCIQDET197ZKu+I5qQcH+ZKYYyAHDcy/kP68tBnnDa8w0rfAIgBEqSPZpq8kQLBqZXcmB89qesBfoLOyLS3VjhZC7XRJs=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":122454},"main":"dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=20"},"gitHead":"eb732a5293edd2840cfee17b47a118edff7b8abe","scripts":{"dev":"tsc --watch","auth":"node dist/auth-cli.js","lint":"tsc --noEmit","test":"vitest run","build":"tsc","start":"node dist/index.js","test:watch":"vitest","prepublishOnly":"npm run build"},"_npmUser":{"name":"danielhokanson","email":"daniel.hokanson+npm@gmail.com"},"repository":{"url":"git+https://github.com/armoryworks/drive-mcp.git","type":"git"},"_npmVersion":"11.8.0","description":"MCP server exposing Google Drive, Docs, and Sheets write operations (move, rename, delete, in-place edit) that the official Google Drive MCP doesn't.","directories":{},"_nodeVersion":"24.13.1","dependencies":{"zod":"^3.23.0","open":"^10.1.0","googleapis":"^144.0.0","zod-to-json-schema":"^3.23.0","google-auth-library":"^9.14.0","@modelcontextprotocol/sdk":"^1.0.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.0.0","typescript":"^5.5.0","@types/node":"^22.0.0"},"_npmOperationalInternal":{"tmp":"tmp/drive-mcp_0.1.0_1778482606820_0.8891017830995607","host":"s3://npm-registry-packages-npm-production"}},"0.1.1":{"name":"@armoryworks/drive-mcp","version":"0.1.1","keywords":["mcp","model-context-protocol","google-drive","google-docs","google-sheets","claude","anthropic"],"author":{"name":"Armory Works Technology, LLC"},"license":"MIT","_id":"@armoryworks/drive-mcp@0.1.1","maintainers":[{"name":"danielhokanson","email":"daniel.hokanson+npm@gmail.com"}],"homepage":"https://github.com/armoryworks/drive-mcp#readme","bugs":{"url":"https://github.com/armoryworks/drive-mcp/issues"},"bin":{"drive-mcp":"dist/index.js","drive-mcp-auth":"dist/auth-cli.js","armoryworks-drive-mcp":"dist/index.js","armoryworks-drive-mcp-auth":"dist/auth-cli.js"},"dist":{"shasum":"a02263e47979509b487a43069e2d500aaf1457e4","tarball":"https://registry.npmjs.org/@armoryworks/drive-mcp/-/drive-mcp-0.1.1.tgz","fileCount":36,"integrity":"sha512-EVUJqtDkRp16hU8EKRzKHFSsXCt03A3ZAKaABR+kmDmmbEFJ/qTS98PzXK6GhOmNPh+1EHvBjg+sjXewbs3h8g==","signatures":[{"sig":"MEUCIH6wQ1T/oIi5R3YbSyLISD9jezv0caQPztCnhtXqqx5PAiEA3favTgImauYd046vCwRL3OGVsMkruSRPl8MMfgB4pD4=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":122579},"main":"dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=20"},"gitHead":"eb732a5293edd2840cfee17b47a118edff7b8abe","scripts":{"dev":"tsc --watch","auth":"node dist/auth-cli.js","lint":"tsc --noEmit","test":"vitest run","build":"tsc","start":"node dist/index.js","test:watch":"vitest","prepublishOnly":"npm run build"},"_npmUser":{"name":"danielhokanson","email":"daniel.hokanson+npm@gmail.com"},"repository":{"url":"git+https://github.com/armoryworks/drive-mcp.git","type":"git"},"_npmVersion":"11.8.0","description":"MCP server exposing Google Drive, Docs, and Sheets write operations (move, rename, delete, in-place edit) that the official Google Drive MCP doesn't.","directories":{},"_nodeVersion":"24.13.1","dependencies":{"zod":"^3.23.0","open":"^10.1.0","googleapis":"^144.0.0","zod-to-json-schema":"^3.23.0","google-auth-library":"^9.14.0","@modelcontextprotocol/sdk":"^1.0.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.0.0","typescript":"^5.5.0","@types/node":"^22.0.0"},"_npmOperationalInternal":{"tmp":"tmp/drive-mcp_0.1.1_1778484375334_0.5760055641919943","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"@armoryworks/drive-mcp","version":"0.2.0","keywords":["mcp","model-context-protocol","google-drive","google-docs","google-sheets","claude","anthropic"],"author":{"name":"Armory Works Technology, LLC"},"license":"MIT","_id":"@armoryworks/drive-mcp@0.2.0","maintainers":[{"name":"danielhokanson","email":"daniel.hokanson+npm@gmail.com"}],"homepage":"https://github.com/armoryworks/drive-mcp#readme","bugs":{"url":"https://github.com/armoryworks/drive-mcp/issues"},"bin":{"drive-mcp":"dist/index.js","drive-mcp-auth":"dist/auth-cli.js","armoryworks-drive-mcp":"dist/index.js","armoryworks-drive-mcp-auth":"dist/auth-cli.js"},"dist":{"shasum":"055c04307a55d0f6bec7fb2dba48c8c23c7cb8ed","tarball":"https://registry.npmjs.org/@armoryworks/drive-mcp/-/drive-mcp-0.2.0.tgz","fileCount":72,"integrity":"sha512-JxDuIIP+N6wp/A1KFWMRRoHHHnVEv1bY7lfhyiHS3x3NGxoiPBySbR5o5alghKSVdCZGqpNg1VLDw9KZhv0bIA==","signatures":[{"sig":"MEQCIEjIfIXK5kZvUFcE10ojWAhUsQNrgeL4c1CE9AijGs7FAiAyFb63ePBB4AZuly2eienIna1xUPFvaKE9uHbyEt6HEw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":406242},"main":"dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=20"},"gitHead":"a3ba378d792885d941d13fa01f8ca26d7a001f4d","scripts":{"dev":"tsc --watch","auth":"node dist/auth-cli.js","lint":"tsc --noEmit","test":"vitest run","build":"tsc","start":"node dist/index.js","test:watch":"vitest","prepublishOnly":"npm run build"},"_npmUser":{"name":"danielhokanson","email":"daniel.hokanson+npm@gmail.com"},"repository":{"url":"git+https://github.com/armoryworks/drive-mcp.git","type":"git"},"_npmVersion":"11.8.0","description":"MCP server exposing Google Drive, Docs, and Sheets write operations (move, rename, delete, in-place edit) that the official Google Drive MCP doesn't.","directories":{},"_nodeVersion":"24.13.1","dependencies":{"zod":"^3.23.0","open":"^10.1.0","googleapis":"^144.0.0","zod-to-json-schema":"^3.23.0","google-auth-library":"^9.14.0","@modelcontextprotocol/sdk":"^1.0.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.0.0","typescript":"^5.5.0","@types/node":"^22.0.0"},"_npmOperationalInternal":{"tmp":"tmp/drive-mcp_0.2.0_1778488201840_0.6817202906080957","host":"s3://npm-registry-packages-npm-production"}},"0.2.4":{"name":"@armoryworks/drive-mcp","version":"0.2.4","description":"MCP server exposing Google Drive, Docs, and Sheets write operations (move, rename, delete, in-place edit) that the official Google Drive MCP doesn't.","license":"MIT","author":{"name":"Armory Works Technology, LLC"},"type":"module","main":"dist/index.js","bin":{"drive-mcp":"dist/index.js","drive-mcp-auth":"dist/auth-cli.js","armoryworks-drive-mcp":"dist/index.js","armoryworks-drive-mcp-auth":"dist/auth-cli.js"},"publishConfig":{"access":"public"},"scripts":{"build":"tsc","start":"node dist/index.js","auth":"node dist/auth-cli.js","dev":"tsc --watch","test":"vitest run","test:watch":"vitest","lint":"tsc --noEmit","prepublishOnly":"npm run build"},"dependencies":{"@modelcontextprotocol/sdk":"^1.0.0","google-auth-library":"^9.14.0","googleapis":"^144.0.0","open":"^10.1.0","zod":"^3.23.0","zod-to-json-schema":"^3.23.0"},"devDependencies":{"@types/node":"^22.0.0","typescript":"^5.5.0","vitest":"^4.0.0"},"engines":{"node":">=20"},"repository":{"type":"git","url":"git+https://github.com/armoryworks/drive-mcp.git"},"bugs":{"url":"https://github.com/armoryworks/drive-mcp/issues"},"homepage":"https://github.com/armoryworks/drive-mcp#readme","keywords":["mcp","model-context-protocol","google-drive","google-docs","google-sheets","claude","anthropic"],"gitHead":"0bd0d69ce41dbe9fd78a4297773450fad60e8d94","types":"./dist/index.d.ts","_id":"@armoryworks/drive-mcp@0.2.4","_nodeVersion":"24.14.1","_npmVersion":"11.11.0","dist":{"integrity":"sha512-MAbJyuoL3iSNrIDVtQM7s4sFMJEonRRgyIso/Nh56Wu4caWqQibxmDL9Y9n3NrsgI7/uoxzJ5oXxlImWaVCx8w==","shasum":"94ddc211ec3e4516a3285c089500d81cc9570b6a","tarball":"https://registry.npmjs.org/@armoryworks/drive-mcp/-/drive-mcp-0.2.4.tgz","fileCount":64,"unpackedSize":432988,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@armoryworks%2fdrive-mcp@0.2.4","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQCRIH2mkGUs+Jw7kfexqEDjWhrg2bplio4q+e+yzAE+GQIgHcq4qXFAIeMDftaRugkKDMOJ6ufd+r0Z78abEmyIBxI="}]},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:ca3343cb-c8a1-490a-ac7a-3416533a7cb5"}},"directories":{},"maintainers":[{"name":"danielhokanson","email":"daniel.hokanson+npm@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/drive-mcp_0.2.4_1778702542910_0.2589433020019667"},"_hasShrinkwrap":false}},"time":{"created":"2026-05-11T06:56:46.713Z","modified":"2026-05-13T20:02:23.342Z","0.1.0":"2026-05-11T06:56:46.974Z","0.1.1":"2026-05-11T07:26:15.485Z","0.2.0":"2026-05-11T08:30:02.034Z","0.2.4":"2026-05-13T20:02:23.067Z"},"bugs":{"url":"https://github.com/armoryworks/drive-mcp/issues"},"author":{"name":"Armory Works Technology, LLC"},"license":"MIT","homepage":"https://github.com/armoryworks/drive-mcp#readme","keywords":["mcp","model-context-protocol","google-drive","google-docs","google-sheets","claude","anthropic"],"repository":{"type":"git","url":"git+https://github.com/armoryworks/drive-mcp.git"},"description":"MCP server exposing Google Drive, Docs, and Sheets write operations (move, rename, delete, in-place edit) that the official Google Drive MCP doesn't.","maintainers":[{"name":"danielhokanson","email":"daniel.hokanson+npm@gmail.com"}],"readme":"# @armoryworks/drive-mcp\n\nAn [MCP](https://modelcontextprotocol.io/) server that gives AI agents full lifecycle control over Google Drive, Docs, and Sheets — create, read, update, delete, restructure, share, and export.\n\nBuilt by [Armory Works Technology, LLC](https://armoryworks.com) for use with [Forge](https://forge.armoryworks.com) and adopted internally for organizing the firm's own Google Workspace. MIT licensed; reuse freely.\n\n## What is this for\n\nGoogle ships an official Drive MCP that is intentionally conservative: read + create only, no destructive operations, no in-place edits. That's defensible for a public default — but it means an AI agent helping you organize your Drive can create folders and copy files but can't delete the duplicates it created, fix metadata, restructure a document, or share work with collaborators.\n\nThis MCP closes that gap. After v0.2.0, it is a complete Drive toolkit: 56 tools spanning all the operations a working agent actually needs. The wrapper is single-user — designed for you to install on your own machine with your own OAuth credentials. It is not a multi-tenant service.\n\n## Tools (v0.2.0)\n\n### Read\n| Tool | What it does |\n|---|---|\n| `get_document` | Read a Doc's paragraph structure + text + indices. **Use this before editing.** |\n| `get_spreadsheet` | Read a Sheet's tabs + values + ranges. |\n| `get_file_metadata` | Owner, size, mime, parents, sharing state for any file. |\n\n### Drive\n| Tool | What it does |\n|---|---|\n| `move_file` | Change a file's parent folder. |\n| `rename_file` | Change a file's title (ID stable). |\n| `delete_file` | Trash (default) or permanently delete (requires `confirm_permanent`). |\n| `restore_file` | Restore a trashed file. |\n| `list_folder` | List a folder's contents. |\n| `create_folder` | Create a new folder inside a parent. |\n| `create_doc` | Create a new Google Doc with optional initial content. |\n| `create_sheet` | Create a new Sheets spreadsheet with a named first tab. |\n| `copy_file` | Copy + optional rename + optional target folder in one call. |\n| `search_files` | Search by name, full-text, mime type, parent, modification time, or raw query. |\n\n### Docs\n| Tool | What it does |\n|---|---|\n| `find_and_replace` | Sweep a Doc replacing one string with another. Supports `dry_run`. |\n| `append_to_doc` | Append text to the end of a Doc. |\n| `insert_at_heading` | Insert content at a specific anchor by exact text. |\n| `apply_text_style` | Bold/italic/underline/color on every occurrence. |\n| `apply_paragraph_style` | Heading 1/2/3, alignment, indent, line spacing on a paragraph. |\n| `delete_paragraph` | Remove a whole paragraph cleanly (including its newline). |\n| `insert_table` | Insert N×M empty table at an anchor. |\n| `update_table_cell` | Set content of a specific (table, row, column). |\n| `insert_image` | Embed an image from a URL at an anchor. |\n| `apply_list_style` | Promote a paragraph to a bulleted or numbered list. |\n\n### Sheets\n| Tool | What it does |\n|---|---|\n| `append_row` | Append a row to the bottom of a tab. |\n| `update_cell` | Set a single cell via A1 notation. |\n| `update_range` | Set a 2D range of cells. |\n| `find_and_replace_in_sheet` | Sheet-wide or whole-spreadsheet find-and-replace. Supports `dry_run`. |\n| `add_sheet` / `delete_sheet` / `rename_sheet` | Tab management. |\n| `format_range` | Bold/color/alignment/number-format on a range. |\n| `delete_rows` / `delete_columns` / `insert_rows` / `insert_columns` | Structural row/column ops. |\n| `create_chart` | Add a chart (column/bar/line/area/pie/scatter/combo/histogram) sourcing a range. |\n| `add_data_validation` | Dropdown lists, number ranges, custom-formula validation. |\n\n### Permissions\n| Tool | What it does |\n|---|---|\n| `share_file` | Share with user/group/domain/anyone at a role. |\n| `list_permissions` | List the ACL on a file. |\n| `revoke_permission` | Revoke a permission by ID (self-lockout protected). |\n| `create_share_link` | Generate a public anyone-with-link URL. |\n\n### Batch\n| Tool | What it does |\n|---|---|\n| `batch_doc_update` | Bundle multiple Doc edits into one atomic batchUpdate call. |\n| `batch_sheet_update` | Bundle multiple Sheet edits (values + structural). |\n| `batch_move` | Move many files in one call. Supports `dry_run`. |\n| `batch_delete` | Delete many files in one call. Supports `dry_run`. Capped at 20 when permanent. |\n\n### Comments / Review\n| Tool | What it does |\n|---|---|\n| `add_comment` | Add a comment to a file. |\n| `list_comments` | List comments (filter by resolved/deleted). |\n| `resolve_comment` | Mark a comment resolved. |\n| `accept_all_suggestions` / `reject_all_suggestions` | (Currently surface a structured error — the Docs API does not support bulk accept/reject; v0.3.0 may add iteration over individual suggestionIds.) |\n\n### Exports\n| Tool | What it does |\n|---|---|\n| `export_to_pdf` | Export a Doc/Sheet/Slide to PDF (base64 bytes). |\n| `export_to_docx` | Export a Doc to Microsoft Word. |\n| `export_to_xlsx` | Export a Sheet to Microsoft Excel. |\n| `get_thumbnail` | Get a thumbnail link (short-lived). |\n\n## Quick start\n\n### 1. Install\n\n```bash\nnpm install -g @armoryworks/drive-mcp\n```\n\nOr use `npx` without installing globally — Claude Desktop will spawn the binary on demand.\n\n### 2. One-time OAuth setup\n\nYou need your own Google Cloud project and OAuth credentials. This is a Google requirement; it ensures *your* tokens are scoped to *your* control.\n\n```bash\nnpx -y -p @armoryworks/drive-mcp armoryworks-drive-mcp-auth\n```\n\nThe first run tells you exactly where to put your `credentials.json` and walks you through the consent flow. Tokens are saved to `~/.armoryworks/drive-mcp/tokens.json` (mode 0600) and refresh automatically. See [docs/oauth-setup.md](./docs/oauth-setup.md) for the full step-by-step.\n\n### 3. Wire into Claude Desktop\n\nAdd to your `claude_desktop_config.json` (Settings → Developer → Edit Config in Claude Desktop):\n\n```json\n{\n  \"mcpServers\": {\n    \"armoryworks-drive\": {\n      \"command\": \"npx\",\n      \"args\": [\"-y\", \"@armoryworks/drive-mcp\"]\n    }\n  }\n}\n```\n\nOn Windows the spawning may need a `cmd /c` wrapper:\n\n```json\n{\n  \"mcpServers\": {\n    \"armoryworks-drive\": {\n      \"command\": \"cmd.exe\",\n      \"args\": [\"/c\", \"npx.cmd\", \"-y\", \"@armoryworks/drive-mcp\"]\n    }\n  }\n}\n```\n\nRestart Claude Desktop. The tools appear in any new conversation.\n\n## Safety considerations\n\nThis MCP can move files to Trash, change permissions, and overwrite content. The threat model is **agent misbehavior or accidental misuse**, not a malicious actor — if someone has filesystem access to your machine, they already have your tokens.\n\n**The MCP runs safe by default.** Dangerous capabilities (public sharing, arbitrary image URLs, large content inserts) require explicit opt-in via env var. You have to deliberately loosen each control.\n\n### Always-on built-in protections (cannot be disabled)\n\n- **No permanent deletion.** `delete_file` and `batch_delete` only Trash. The user recovers from Drive UI within 30 days. Permanent deletion is intentionally not exposed.\n- **Self-lockout protection.** `revoke_permission` refuses to revoke your own access unless `force_revoke_self: true`.\n- **Per-tool rate limits.** `batch_delete`: 5/min, `delete_file`: 30/min, `revoke_permission`: 20/min, `share_file`: 50/min, `create_share_link`: 20/min.\n- **Per-document rate limit.** Any one file: 60 modifications/minute (configurable). Catches agent loops on a single doc.\n- **Session destructive-op budget.** Hard cap of 500 destructive operations per server process (configurable). Forces restart for \"this agent is doing a lot.\"\n- **Replay detection.** Identical tool+args within 2s window are refused. Catches retry loops.\n- **Body-size cap on inserts.** Text inserts capped at 256 KiB by default. Prevents content bombing.\n- **Audit logging.** Every destructive op writes a structured stderr line (`LOG_LEVEL=info` for full audit). Optional `AUDIT_WEBHOOK_URL` posts the same events to a webhook.\n- **Dry-run mode** on `batch_move`, `batch_delete`, `find_and_replace`, `find_and_replace_in_sheet`.\n\n### Fail-closed defaults — set explicitly to loosen\n\n| Env var | Default (safe) | What it controls |\n|---|---|---|\n| `ALLOW_PUBLIC_SHARING` | `false` (deny) | Set to `true` to allow `share_file` with `type=anyone` and `create_share_link`. |\n| `INSERT_IMAGE_ALLOWED_HOSTS` | `drive.google.com,lh3.googleusercontent.com,googleusercontent.com` | Allowlist for `insert_image` URLs. Set `*` to allow any host (not recommended). |\n| `INSERT_IMAGE_REQUIRE_HTTPS` | `true` (deny `http://`) | Set `false` to permit plain-HTTP image URLs. |\n| `BACKUP_BEFORE_DESTRUCTIVE` | `true` (always backup) | Set `false` to skip automatic backups before destructive content edits. Backups land in `_drive-mcp-backups/` at your Drive root. |\n\n### Opt-in tighter modes (default off — set to enable)\n\n| Env var | Default | What it does |\n|---|---|---|\n| `READ_ONLY` | unset | Set `true` to disable ALL write/delete/share tools. Useful for exploration sessions. |\n| `PROTECTED_FOLDER_IDS` | empty | Comma-separated folder IDs. Destructive ops on files inside are refused. |\n| `LOCKED_FILE_IDS` | empty | Comma-separated file IDs. Cannot be modified or deleted. |\n| `DRY_RUN_ALL` | `false` | Set `true` to force every destructive op into preview mode regardless of how invoked. |\n| `AUDIT_WEBHOOK_URL` | unset | URL to POST audit events to in addition to stderr logging. |\n\n### Tunable thresholds\n\n| Env var | Default | What it tunes |\n|---|---|---|\n| `MAX_INSERT_BYTES` | `262144` (256 KiB) | Per-call cap on inserted text. |\n| `MAX_DESTRUCTIVE_OPS_PER_SESSION` | `500` | Session budget for destructive ops. |\n| `PER_DOC_OPS_PER_MINUTE` | `60` | Per-document modification rate. |\n| `REPLAY_WINDOW_MS` | `2000` | Window for replay detection. |\n| `LOG_LEVEL` | `warn` | `debug` / `info` / `warn` / `error` / `silent`. |\n\n### Operational recommendations\n\n- Keep a periodic Drive backup (Google Takeout or third-party). Drive Trash isn't a backup; 30 days isn't forever. `BACKUP_BEFORE_DESTRUCTIVE=true` (the default) snapshots files before edits but doesn't replace whole-drive backups.\n- Use `dry_run: true` (or set `DRY_RUN_ALL=true` for the whole session) on bulk operations affecting more than a few files.\n- Run with `LOG_LEVEL=info` for a complete record of destructive actions.\n- For high-stakes work, run with `READ_ONLY=true` first to let the agent plan, then re-run without it once you've reviewed the plan.\n\n## Configuration reference\n\n| Env var | Default | Effect |\n|---|---|---|\n| `ARMORYWORKS_DRIVE_MCP_HOME` | `~/.armoryworks/drive-mcp` | Where credentials.json and tokens.json live. |\n| `ALLOW_PUBLIC_SHARING` | unset (allows) | Set to `false` to block anyone-with-link sharing. |\n| `PROTECTED_FOLDER_IDS` | unset (no protection) | Comma-separated Drive folder IDs; ops on files inside are refused. |\n| `LOG_LEVEL` | `warn` | `debug` / `info` / `warn` / `error` / `silent`. |\n\n## Security and trust model\n\nThis wrapper requests **full read/write access** to your Drive, Docs, and Sheets. There is no narrower scope set that supports the operations exposed; Google's scope granularity puts \"list files\" and \"delete file\" on the same drive-wide scope.\n\nThe implications:\n\n- **Single-user.** Designed for one person to install on their own machine using their own Google account. Not a multi-tenant service.\n- **Your tokens, your machine.** OAuth tokens are stored in `~/.armoryworks/drive-mcp/tokens.json` with mode `0600`. They never leave your machine.\n- **Your Google Cloud project.** You create the OAuth client; you control it. Revoke anytime at [myaccount.google.com/permissions](https://myaccount.google.com/permissions).\n- **No telemetry.** This package does not phone home. Network traffic goes to `googleapis.com` only.\n\nIf you're not comfortable granting full-Drive access, this wrapper isn't for you — but neither is any other MCP that can write to Drive.\n\n## Development\n\n```bash\ngit clone https://github.com/armoryworks/drive-mcp.git\ncd drive-mcp\nnpm install\nnpm run build\nnpm run auth          # one-time OAuth setup\nnpm test              # run the test suite\n```\n\nThe codebase is small (~3,000 lines TypeScript). Tools are grouped by Google product under `src/tools/`. The MCP server wiring is in `src/index.ts`. Everything is ESM, Node 20+, strict TypeScript.\n\n## License\n\nMIT — see [LICENSE](./LICENSE).\n\n— [Armory Works](https://armoryworks.com)\n","readmeFilename":"README.md"}