Enables AI agents to safely provision new Google Workspace accounts for employee onboarding, with availability checks, account creation, and credential delivery, all behind OAuth and per-user allowlists.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse
Anthropic's MCP TypeScript SDK has a ReDoS vulnerability
Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default
process.env. You'll be asked to provide them before it can run.ALLOWED_DOMAIN— │ │ • @ enforcement │ALLOWED_USERS— │ │ • allowlist │COMPANY_NAME— No Display name used in the credentials email (default: Example Corp)CREDENTIALS_FROM— No From: address for the credentials email (default: it@<ALLOWED_DOMAIN>)DWD_SERVICE_ACCOUNT— Yes Service account that self-signs the delegation JWT (keyless, via signJwt)GOOGLE_CLIENT_ID— Yes GCP OAuth 2.0 client ID (per-user sign-in)GOOGLE_CLIENT_SECRET— Yes GCP OAuth 2.0 client secretGWS_ADMIN_SUBJECT— Yes Workspace admin user the DWD service account impersonatesK_SERVICEPORT— No HTTP port (default: 8080; Cloud Run sets this automatically)SERVER_URLSLACK_BOT_TOKEN— Yes Slack bot token for the never-reuse check (from Secret Manager on Cloud Run)TARGET_OU— No Organizational unit new users are created into (default: /Employees)[](https://m8ven.ai/mcp/micahyee415-google-workspace-admin-mcp-1i5z0v)