Skip to content
Scalekit Docs
Talk to an Engineer Dashboard

Connect AI agents to Google Workspace (DWD)

Scalekit connector
Open markdown

The Google Workspace (DWD) connector lets your AI agent work with Google Workspace (DWD). You connect it once with a service account, and Scalekit authenticates every call, so your agent never handles credentials. It comes with 100 tools.

Tools
100
What they doRead · write · destructive
51 · 37 · 1251 read37 write12 destructive
Users sign in with

What you can do

  • Read and search emails: fetch messages, threads, and attachments from any Gmail label or inbox
  • Send and manage emails: compose messages, manage drafts, and modify labels on Gmail messages
  • Manage Google Drive files: share, move, copy, and query activity on files and folders in Google Drive
  • Access Google Calendar: read, create, and manage calendar events across a user’s calendars
  • Manage Google Vault: list matters and manage legal holds in Google Vault
  • Administer user settings: update vacation auto-reply settings and other Gmail account configurations

Setup

  1. Install the SDK

    Terminal window
    npm install @scalekit-sdk/node dotenv
  2. Set your credentials

    Add your Scalekit credentials to your .env file. Find values in app.scalekit.com > Developers > API Credentials.

    .env
    SCALEKIT_ENVIRONMENT_URL=<your-environment-url>
    SCALEKIT_CLIENT_ID=<your-client-id>
    SCALEKIT_CLIENT_SECRET=<your-client-secret>
  3. Create the Google Workspace (DWD) connection

    In AgentKit > Connections, create a Google Workspace (DWD) connection. The name you give it is the connection_name your code passes. See Configure connections.

    Console steps with screenshots

    Register your Scalekit environment with the Google Workspace (DWD) connector so Scalekit can act on behalf of any user in your Google Workspace domain. DWD uses a service account — no per-user login flows are required.

    1. Create a connection in Scalekit

      • In Scalekit dashboard, go to AgentKit > Connections > Create Connection. Find Google Workspace (DWD) and click Create.

      • Under Scopes, add each Google API scope your agent needs. Enter the full scope URI, for example:

        • https://www.googleapis.com/auth/gmail.readonly
        • https://www.googleapis.com/auth/calendar
        • https://www.googleapis.com/auth/drive

        See the Google OAuth 2.0 Scopes reference for the full list.

    2. Create a GCP service account

      • Go to Google Cloud Console → IAM & Admin → Service Accounts.
      • Click + Create Service Account, enter a name and description, and click Create and Continue.
      • Skip the optional role and user access steps and click Done.
    3. Download the service account JSON key

      • In Google Cloud Console, go to IAM & Admin → Service Accounts and click your service account.
      • Go to the Keys tab → Add Key → Create new key.
      • Select JSON and click Create. The key file downloads automatically.
    4. Add the service account JSON in Scalekit

      • In Scalekit dashboard, go to AgentKit > Connections and open the connection you created in step 1.
      • Paste the full contents of the downloaded JSON key file into the Service Account JSON field. Treat this JSON key as a secret credential — restrict access to the connection settings and rotate or revoke the key immediately if it is exposed.
      • Click Save.

    Authorize the service account in Google Admin

    The admin of the Google Workspace organization you want to connect to must complete these steps to authorize your service account.

    1. Open API controls in Google Admin

      • Sign in to Google Admin console as a super admin.
      • Go to Security → Access and data control → API controls.
      • Click Manage Domain Wide Delegation → Add new.
    2. Authorize the service account

      • In Client ID, enter the Unique ID of the service account created during setup (visible in GCP Console → IAM & Admin → Service Accounts → click the service account → Details tab).
      • In OAuth scopes, enter the scopes comma-separated — these must match exactly what was configured in the Scalekit connection. For example:
        • https://www.googleapis.com/auth/gmail.readonly, https://www.googleapis.com/auth/calendar, https://www.googleapis.com/auth/drive
      • Click Authorize.

    You can now impersonate any user in that workspace with your service account via Scalekit connected accounts.

This connector uses Service Account with Domain-Wide Delegation (DWD). You create a GCP service account, grant it domain-wide delegation in Google Admin, and provide Scalekit with the service account JSON key. Scalekit then impersonates any user in your Google Workspace domain on demand — no per-user OAuth redirects required.

Before executing tools, create a connected account for each Google Workspace user you want to impersonate. Pass the user’s email as subject — this tells Scalekit which Workspace user the service account should act as. The identifier is your application’s ID for that user.

response = scalekit_client.actions.create_connected_account(
# connection_name: the name of the connection you created in the setup step above
connection_name='googledwd',
identifier='user_123',
authorization_details={
"google_dwd": {
# subject: the Google Workspace user you want to impersonate
"subject": "alice@yourcompany.com",
}
},
)
print(response.connected_account.id)
print(response.connected_account.status)
Execute a tool

Use the identifier you set when creating the connected account. Scalekit resolves the impersonated Workspace user from that mapping.

response = scalekit_client.actions.execute_tool(
# connection_name: the name of the connection you created in the setup step above
connection_name='googledwd',
identifier='user_123',
tool_name='googledwd_fetch_mails',
tool_input={
"max_results": 5,
"format": "metadata",
"include_spam_trash": False,
},
)
print(response)

Tools

Pass the exact name to execute_tool
Try in PlaygroundRequest a tool
  • googledwd_fetch_mailsFetch emails from a connected Gmail account using search filters.Read-only

    Fetch Emails from Gmail

    Fetch emails from a connected Gmail account using search filters. Uses DWD service account credentials.

    Inputs

    formatstring
    Format of the returned message.one of minimalfullrawmetadatadefault metadata
    include_spam_trashboolean
    Whether to fetch emails from spam and trash foldersdefault false
    label_idsarray
    Gmail label IDs to filter messages
    max_resultsinteger
    Maximum number of emails to fetch
    page_tokenstring
    Page token for pagination
    querystring
    Search query string using Gmail's search syntax (e.g., 'is:unread from:user@example.com')

    Also accepts schema_version and tool_version to pin a version.

  • googledwd_get_admin_groupRetrieve details of a specific Google Workspace group by its email address or unique group ID using the Admin Directory API.Read-only

    Get Admin Group

    Retrieve details of a specific Google Workspace group by its email address or unique group ID using the Admin Directory API. Uses DWD service account credentials.

    Inputs

    group_keystringrequired
    Group email address or unique group ID to retrieve (e.g., 'engineering@example.com' or a numeric ID).

    Also accepts schema_version and tool_version to pin a version.

  • googledwd_get_admin_userRetrieve details of a specific Google Workspace user by their primary email address or unique user ID using the Admin Directory API.Read-only

    Get Admin User

    Retrieve details of a specific Google Workspace user by their primary email address or unique user ID using the Admin Directory API. Uses DWD service account credentials.

    Inputs

    user_keystringrequired
    Primary email address or unique user ID of the user to retrieve (e.g., 'john@example.com' or '123456789').

    Also accepts schema_version and tool_version to pin a version.

  • googledwd_get_alertGet details of a specific security alert from Google Workspace Alert Center.Read-only

    Get Alert

    Get details of a specific security alert from Google Workspace Alert Center. Uses DWD service account credentials.

    Inputs

    alert_idstringrequired
    The unique identifier of the alert to retrieve. Example: 'a1b2c3d4-e5f6-7890-abcd-ef1234567890'

    Also accepts schema_version and tool_version to pin a version.

  • googledwd_get_alert_metadataGet metadata for a specific alert including acknowledgement status and assignee.Read-only

    Get Alert Metadata

    Get metadata for a specific alert including acknowledgement status and assignee. Uses DWD service account credentials.

    Inputs

    alert_idstringrequired
    The unique identifier of the alert whose metadata to retrieve. Example: 'a1b2c3d4-e5f6-7890-abcd-ef1234567890'

    Also accepts schema_version and tool_version to pin a version.

  • googledwd_get_attachment_by_idRetrieve a specific attachment from a Gmail message using the message ID and attachment ID.Read-only

    Fetch Attachment by Gmail ID

    Retrieve a specific attachment from a Gmail message using the message ID and attachment ID. Uses DWD service account credentials.

    Inputs

    attachment_idstringrequired
    Unique Gmail attachment ID
    message_idstringrequired
    Unique Gmail message ID that contains the attachment
    file_namestring
    Preferred filename to use when saving/returning the attachment

    Also accepts schema_version and tool_version to pin a version.

  • googledwd_get_chat_spaceRetrieve details of a specific Google Chat space (room or direct message) by its resource name (e.g., 'spaces/AAAA').Read-only

    Get Chat Space

    Retrieve details of a specific Google Chat space (room or direct message) by its resource name (e.g., 'spaces/AAAA'). Uses DWD service account credentials.

    Inputs

    space_namestringrequired
    Resource name of the Chat space to retrieve (e.g., 'spaces/AAAABBBBCCCC').

    Also accepts schema_version and tool_version to pin a version.

  • googledwd_get_contactsFetch a list of contacts from the connected Gmail account.Read-only

    Fetch Gmail Contacts

    Fetch a list of contacts from the connected Gmail account. Supports pagination and field filtering. Uses DWD service account credentials.

    Inputs

    max_resultsinteger
    Maximum number of contacts to fetch
    page_tokenstring
    Token to retrieve the next page of results
    person_fieldsarray
    Fields to include for each person

    Also accepts schema_version and tool_version to pin a version.

Workflows

Create a connected account

Before executing tools, create a connected account for each Google Workspace user you want to impersonate. Pass the user’s email as subject — this tells Scalekit which Workspace user the service account should act as. The identifier is your application’s ID for that user.

response = scalekit_client.actions.create_connected_account(
# connection_name: the name of the connection you created in the setup step above
connection_name='googledwd',
identifier='user_123',
authorization_details={
"google_dwd": {
# subject: the Google Workspace user you want to impersonate
"subject": "alice@yourcompany.com",
}
},
)
print(response.connected_account.id)
print(response.connected_account.status)
Execute a tool

Use the identifier you set when creating the connected account. Scalekit resolves the impersonated Workspace user from that mapping.

response = scalekit_client.actions.execute_tool(
# connection_name: the name of the connection you created in the setup step above
connection_name='googledwd',
identifier='user_123',
tool_name='googledwd_fetch_mails',
tool_input={
"max_results": 5,
"format": "metadata",
"include_spam_trash": False,
},
)
print(response)