Skip to main content

Set up Drive labels for Google Drive, Docs, and Sheets

Let AI agents read the classification labels on your Google Drive files (for example, sensitivity, department, or retention) through MintMCP's labels-enabled Google Drive, Docs, and Sheets servers. These servers sign users in with an OAuth client your organization owns, so a Google Cloud project admin creates the client and a MintMCP admin installs the servers with it.

The labels-enabled servers read labels only: agents can't apply, change, or remove a label through them.

Prerequisites​

  • A MintMCP admin account
  • A Google Cloud project owned by your Google Workspace organization
  • A Google Workspace edition that supports classification labels, with at least one published label. See Get started as a classification labels admin to create and publish labels.

Enable the Google APIs​

Enable these APIs in the project that will hold the OAuth client, for each server you plan to install:

ServerAPIs to enable
Google Drive (Labels)Google Drive API, Drive Labels API
Google Docs (Labels)Both of the above, plus Google Docs API
Google Sheets (Labels)Both of the above, plus Google Sheets API
  1. Open each API link and select your project.
  2. On Confirm project, check that the correct project is selected and click Next.
  3. On Enable API, click Enable.

Without the Drive Labels API, results carry label IDs but no label names, and set labelsError, which the read gate blocks.

  1. Go to console.cloud.google.com/auth/branding and select your project.
  2. If the consent screen isn't configured yet, set the user type to Internal. This limits sign-in to users in your Google Workspace organization and skips Google app verification, which external apps need for the Drive scopes.
  3. Go to Data Access, click Add or remove scopes, and add the scopes for each server you plan to install. In the tables, ... stands for https://www.googleapis.com.
ScopeAccess granted
openidOpenID Connect authentication
.../auth/userinfo.emailView user email address
.../auth/userinfo.profileView basic profile info
.../auth/drive.readonlySearch and read Drive files
.../auth/drive.fileView and manage files created or opened with this app
.../auth/drive.labels.readonlyRead the labels applied to files and their definitions
  1. Click Update, then Save.

Create an OAuth client​

One Web application client can serve all three servers, since each server requests its own scopes at sign-in.

  1. Go to console.cloud.google.com/auth/clients and select your project.

  2. Click Create client.

  3. Set Application type to Web application and give it a name (for example, MintMCP Drive labels).

    Create OAuth client ID form with application type set to Web application and a name field
  4. Under Authorized redirect URIs, click Add URI and enter the callback for your MintMCP region:

    MintMCP regionRedirect URI
    US (app.mintmcp.com)https://app.mintmcp.com/oauth/callback
    EU (eu.mintmcp.com)https://eu.mintmcp.com/oauth/callback

    Leave Authorized JavaScript origins empty. The URI must match the redirect URL MintMCP sends exactly, or sign-in fails with redirect_uri_mismatch.

  5. Click Create. Google shows the Client ID and Client secret once, so copy both now: you can't view the secret again after closing the dialog.

Allow the client in Google Workspace​

If your organization restricts third-party app access, users can't grant the client access until it's trusted.

  1. Go to admin.google.com and sign in as a super admin.
  2. Go to Security → Access and data control → API controls → Manage Third-Party App Access.
  3. Click Add app → OAuth App Name Or Client ID, search for the Client ID you created, and select it.
  4. Choose the organizational units that should use the servers and click Continue.
  5. Set the access level to Trusted, or to Specific Google data with the scopes listed above, and click Configure.

Add the servers to MintMCP​

Each labels-enabled server is a separate connector in the MintMCP store. Install the ones your organization needs and enter the same Client ID and Client secret in each.

  1. In MintMCP, go to MCP store → Manage store.
  2. Find Google Drive (Labels), Google Docs (Labels), or Google Sheets (Labels) and click to install it.
  3. Enter the Client ID and Client secret from the OAuth client you created.
  4. Click Install.

Each user signs in with their own Google account the first time they connect, and Google asks them to approve the server's scopes.

Read labels from agents​

The servers attach a file's applied labels to read results. A label read runs as the signed-in user, so agents see the same labels that user sees in Drive.

ServerLabels in the visible resultLabels in _meta.applied only
Google Drive (Labels)get_file_metadata (labels field)get_file
Google Docs (Labels)Noneget_document, get_document_images
Google Sheets (Labels)get_metadata (labels field)get_sheet_data

Agents use the visible labels field to answer questions such as "which of these files are confidential?". To block files by label, use the Google Drive labels read gate template. Custom post-phase gateway middleware can also read _meta.applied from ctx.result.

Each applied label looks like this:

{
"labelId": "37ZlnSPuGlS9eVDQTE1CQJtWNcxkSrUBtw9RNNEbbFcb",
"revisionId": "7",
"title": "Data classification",
"resolved": true,
"values": [
{
"fieldId": "62BB395EC6",
"valueType": "selection",
"choiceId": "68E9987F43",
"displayName": "Confidential",
"resolved": true
}
]
}
FieldDescription
labelId, fieldId, choiceIdStable IDs that don't change when a label or choice is renamed. Custom middleware can match on these instead of names.
title, displayNameHuman-readable names for the label and the selected choice
resolvedfalse when the label or choice definition couldn't be read, so only IDs are returned
valuesField values: selection, text (up to 256 characters), date, and integer
skippedValueTypesValue types left out of values. Person fields are always withheld (user).
labelsErrorSet when the label read failed or was incomplete. The tool still returns the file content.

A file with no labels returns an empty applied list.

Block files by label​

Use the Google Drive labels read gate middleware template to stop agents from receiving files that carry a restricted label. It checks every result from the labels-enabled servers, including file content, metadata, documents, and spreadsheets.

  1. In MintMCP, go to Guardrails → Middleware and click New middleware.

  2. Find Google Drive labels read gate in the templates and click Use template. The template is post-phase and fails closed.

    Google Drive labels read gate template card with a Post badge and a Use template button
  3. Edit RESTRICTED to list the labels to block, written as they appear in Google Drive:

    const RESTRICTED = [
    { label: "Confidential" },
    { label: "Data classification", value: "Restricted" },
    ];

    A rule with only label blocks any file carrying that label. A rule with value also requires one of the label's fields to hold that value: a selection choice, or a text, date (YYYY-MM-DD), or whole-number value. Matching ignores case and extra spaces. Person fields and text values over 256 characters aren't returned by the servers, so rules can't match them.

  4. Test it with the built-in harness, using a sample result that carries _meta.applied.

  5. Save it, then attach it to the Google Drive (Labels), Google Docs (Labels), and Google Sheets (Labels) connectors and turn on enforcement. Attach it only to these connectors, since other connectors don't return Drive labels.

ResultDecision
Carries a label that matches a RESTRICTED ruleBlocked, and the reason names the matched rules
Has labelsError setBlocked, since an unread label could be restricted. Set BLOCK_WHEN_LABELS_UNVERIFIED to false to allow these instead.
Carries no restricted labelsAllowed
Carries no label data (for example, search results)Allowed

The gate only enforces on results that carry labels, and the servers return labels only when the user granted the drive.labels.readonly scope. Keep that scope in the consent screen and in any Specific Google data list in the Admin Console, so every user's connection includes it.

Security considerations​

  • Your organization owns the OAuth client and its secret. Rotate the secret from the client's page in Google Cloud and update it in each connector's OAuth settings in MintMCP.
  • Each user authenticates individually, so label reads and file access run under their own identity and follow their Drive permissions.
  • Person fields on labels are never returned, which keeps user identities out of agent context.
  • Labels are read live on every call, so label changes made in Drive apply to the next read.

Next steps​