Connect Google Drive, Calendar, and Gmail changedclaude-tag/admins/connections/google
Nearest release: v2.1.283, published 5 hours before upstream edited the page. Shown because the two are within 24 hours of each other. Nothing here says the release caused the edit.
Upstream edited this page at 25 Sep 2026 23:59 UTC, give or take a minute or two: the time comes from Anthropic’s own sitemap rather than from a commit. This site recorded the change at 26 Sep 2026 00:07 UTC.
Upstream edited
Recorded here
Lines+9added
Lines−7removed
From line
35
where the diff opens
First seen
14 Aug 2026
this site's first read of the page
Recorded edits6to this page, all time
The whole hunk
from line 35, old and new numbered
/
from line 35
3535
3636In the bundle, click **Connect** next to **Custom tool** and choose **GCP access token (with Service Account Key)**.
3737
38| Field | Value |
39| :----------------------------- | :-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
40| GCP service account key (JSON) | The JSON key file from Google Cloud Console |
41| Scopes (optional) | The Google API scopes to request (for example `https://www.googleapis.com/auth/drive.readonly`). The field is labeled optional, but Drive and Calendar calls fail without the matching scope listed here. |
42| Subject (optional) | A user email to impersonate via domain-wide delegation. Set this for Workspace data (Drive, Calendar, Gmail, Docs). |
43| Allowed websites | `*.googleapis.com` |
38| Field | Value |
39| :----------------------------- | :------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
40| GCP service account key (JSON) | The JSON key file from Google Cloud Console |
41| Scopes (optional) | The Google API scopes to request (for example `https://www.googleapis.com/auth/drive.readonly`). If you leave the field empty, the connection requests `https://www.googleapis.com/auth/cloud-platform`. |
42| Subject (optional) | A user email to impersonate via domain-wide delegation. Set this for Workspace data (Drive, Calendar, Gmail, Docs). |
43| Allowed websites | `*.googleapis.com` |
4444
45For Google Workspace data (Drive, Calendar, Gmail, Docs), the service account needs domain-wide delegation configured in your Google Admin console with the matching API scopes. Google's guide is at [developers.google.com/identity/protocols/oauth2/service-account](https://developers.google.com/identity/protocols/oauth2/service-account#delegatingauthority).
45For Google Workspace data (Drive, Calendar, Gmail, Docs), the service account needs domain-wide delegation configured in your Google Admin console. In the service account's domain-wide delegation entry, list every scope you entered in **Scopes**, or `https://www.googleapis.com/auth/cloud-platform` if you left **Scopes** empty. Google's guide is at [developers.google.com/identity/protocols/oauth2/service-account](https://developers.google.com/identity/protocols/oauth2/service-account#delegatingauthority).
46
47Google refuses the token request when the domain-wide delegation entry is missing one of the requested scopes. Claude then reports HTTP 502 with a reason that starts with `injection failed ("<connection name>")`.
4648
4749The Agent Proxy injects the credential at the network boundary; the model and the sandbox are not given the key. See [how Agent Proxy works](/docs/claude-tag/concepts/agent-identity#agent-proxy).
4850
No line in this hunk matches that.