Skip to main content
Connections are added inside an Access bundle. At claude.ai/admin-settings/claude-tag, open Access bundles in the left navigation, click into a bundle (or Create one), and go to its Credentials tab.
Connecting Google Drive, Calendar, and Gmail lets Claude read documents, spreadsheets, calendar events, and email from any channel under the bundle’s scope. You add it as a connection inside an Access bundle; the credential belongs to the agent, not to any person. This is an HTTP API connection, not a personal claude.ai connector. A member’s own Google connector applies only in DMs.

Choose OAuth or a service account

The connection picker offers two routes: Both routes create a credential and an allowed-websites rule path-scoped to that Google service (the Drive API path for Drive, the Calendar API path for Calendar, the Gmail API path for Gmail).

Add the connection with OAuth

Use a dedicated Google account for this connection (for example, claude@yourcompany.example.com), not your own. The connection is shared: anyone in a channel under the bundle’s scope can ask Claude to read whatever this account can see in Drive, Calendar, and Gmail. A dedicated account starts with no access until you share the specific folders and calendars Claude needs, and keeps its activity under a separate identity in Google’s audit log.
In the bundle, click Connect next to Google Drive, Google Calendar, or Google Gmail. A scope checklist appears with read-only scopes selected by default. Each scope grants a specific permission: Check write scopes only if Claude should create or edit. Click Sign in with Google Calendar (or Sign in with Google Drive, or Sign in with Google Gmail), approve the Google consent screen, and the credential is saved. The connection’s reach is whatever the signed-in Google account can see. Share the relevant folders and calendars with that account in Google before testing.

Add the connection with a service account

In the bundle, click Connect another tool and choose GCP access token (with Service Account Key). For Google Workspace data (Drive, Calendar, Gmail, Docs), the service account needs domain-wide delegation configured in your Google Admin console with the matching API scopes. Google’s guide is at developers.google.com/identity/protocols/oauth2/service-account. The Agent Proxy injects the credential at the network boundary; the model and the sandbox are not given the key. See how Agent Proxy works.

Verify the connection

In a channel under the bundle’s scope, in a new thread:
Google Drive, Calendar, or Gmail appears in the list once the connection is live. New threads pick up the connection on their own; in an existing thread, ask Claude to use the service by name. The credential row in the bundle shows Never used until Claude first uses the connection. The label tracks usage, not health, so a working connection stays on Never used until someone exercises it. To confirm the connection works, ask Claude in the same thread to read something from the service, such as today’s calendar events or a named document. The label updates after that first read.