Skip to main content

Gmail, Drive, Calendar, and More

The Google Workspace integration connects Wolffish to Gmail, Google Drive, Calendar, Contacts, Tasks, and Sheets. It supports multiple Google accounts and uses OAuth 2.0 for authentication.

Setup

The integration runs on gogcli, a small Google Suite CLI Wolffish installs for you. You bring your own Google Cloud OAuth client, which is what keeps the whole thing on your own credentials.
1

Install gogcli

Open Settings → Services → Google Workspace and click Install. Wolffish downloads the prebuilt binary for your platform to ~/.wolffish/bin/gog — no package manager, no admin password. macOS, Linux and Windows are all supported. Since v1.0.263 the installer is pinned to the exact audited gogcli release (v0.37.0) rather than fetching whatever is latest, so the CLI can never change its syntax underneath a shipped release — every tool is verified command-by-command against that binary, and a mismatched older installation gets an error that names the fix: update from Settings.
2

Create an OAuth client

In the Google Cloud Console: create a project, enable the APIs you want under APIs & Services → Library (Gmail, Drive, Calendar, Sheets, Tasks, People, and any others the panel lists), set the OAuth consent screen to External and add yourself as a Test user, then Credentials → Create Credentials → OAuth client ID → Desktop app. Download the client_secret_*.json. The panel walks through every step with a confirmation for each.
3

Drop the JSON in

Drag the downloaded file onto the credentials dropzone. Wolffish validates it and stores it; the section shows the project and client it now holds.
4

Authorize an account

Type the account email and click Authorize. Your browser opens Google’s consent screen; approve, and the account lands in the Accounts list. Add as many as you like, and use Reconnect on any account whose refresh token has expired or been revoked.
Credentials and tokens are held in gogcli’s own keychain, not in Wolffish’s config. config.json keeps only safe public metadata — the client and project ids, and whether credentials are stored. Deleting the credentials from the panel removes every authorized account with them.
Leave the consent screen’s publishing status on Testing. Only test users can authorize, which is exactly right for personal use, and you can enable more APIs later without redoing any of this.

Multi-Account Support

You can authorize multiple Google accounts. The google_accounts tool lists all connected accounts, and every other Google tool requires an explicit account parameter to specify which account to use.
There is no implicit default account: even with one authorized, every call carries account explicitly. For an identity-agnostic request (“any unread mail?”) the model calls the tool once per account, in parallel.

Available Tools

Every tool is google_-prefixed and takes a required account parameter.

Accounts

Gmail

Google Drive

Google Calendar

Google Contacts

Google Tasks

Google Sheets

Triggers

The capability is not in context by default — it loads on demand when tool_search matches your request against the triggers declared in its SKILL.md:
Once loaded, its tools are callable the same turn.

Example Workflows

Configuration Reference

config.json holds only public metadata about the connection — never a token:
Manage accounts from the panel rather than by hand. The OAuth client JSON and every refresh token live in gogcli’s keychain, so editing config.json cannot add, remove, or repair an account — and Delete credentials removes all of them at once.
If Google calls start failing with 401s, open Settings → Services → Google Workspace and hit Reconnect on the affected account — that re-runs the consent flow and returns a fresh refresh token. This is what you want after revoking access from your Google account’s security settings.