mirror of
https://github.com/paperclipai/paperclip.git
synced 2026-10-06 10:48:12 +02:00
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work > - Governed MCP access spans contracts, runtime enforcement, adapters, UI surfaces, and operator verification > - The parity reference PR #9534 is too large for effective automated or human review > - The feature therefore needs a linear stack whose individual diffs stay below the 100-file review limit > - This pull request is split 1/8 and focuses on fixture and demo MCP servers > - The benefit is a standalone, testable review boundary while preserving byte-for-byte parity at the top of the stack ## Linked Issues or Issue Description - Related parity reference: #9534 - Problem: Developers need deterministic local MCP fixtures and visible demo servers without pulling in the governed production runtime. - Proposed solution: Adds the Google Sheets and KV demo MCP packages, fixture catalog/servers, smoke harness, guide, and the root smoke/typecheck registration hunks. - Alternatives considered: keeping #9534 as one 403-file review, or rewriting the feature to manufacture seams; both were rejected in favor of path extraction plus compile-driven boundary moves. - Roadmap alignment: this advances the existing governed MCP/tool-access work already represented by #9534; it does not introduce a separate roadmap initiative. - Stack position: base branch is `master`. - Merge policy: merge bottom-up, in order, only after the complete eight-PR stack has been reviewed and the top-of-stack parity gate remains empty. - Requested review: QA for fixture and smoke coverage; Greptile on every PR. ## What Changed - Adds the Google Sheets and KV demo MCP packages, fixture catalog/servers, smoke harness, guide, and the root smoke/typecheck registration hunks. - Keeps this PR below 100 changed files and independently typecheckable. - Preserves the final tree from #9534 when combined with the other seven stack levels. ## Verification - `pnpm typecheck` - `pnpm --filter @paperclipai/google-sheets-mcp-server test` — 27 tests passed - `pnpm --filter @paperclipai/kv-demo-mcp-server test` — 12 tests passed ## Risks - The new packages add dependencies that are intentionally not committed to `pnpm-lock.yaml`, per repository policy. - Stack risk: merging out of order can expose incomplete layers; mitigate by following the documented bottom-up merge policy. - Parity risk: later edits to an intermediate branch can drift from #9534; mitigate by re-running the empty top-of-stack diff before merge. > For core feature work, check [`ROADMAP.md`](ROADMAP.md) first and discuss it in `#dev` before opening the PR. Feature PRs that overlap with planned core work may need to be redirected — check the roadmap first. See `CONTRIBUTING.md`. ## Model Used - OpenAI Codex, exact model ID `gpt-5.4`; runtime-managed context window; medium reasoning with repository, shell, Git, GitHub CLI, and code-execution tools enabled. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] Internal references are omitted except the execution-plan link explicitly required for this coordinated split stack - [x] My branch name describes the change and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [ ] All Paperclip CI gates are green - [ ] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge ## Stack Coordination - Internal execution plan: [PAP-13874](/PAP/issues/PAP-13874#document-plan) - Parity reference: #9534 - Stack: #9556 → #9557 → #9558 → #9559 → #9560 → #9561 → #9562 → #9563 - Merge bottom-up only after full-stack review and an empty parity diff at #9563. --------- Co-authored-by: Paperclip <noreply@paperclip.ing>
115 lines
4.2 KiB
Markdown
115 lines
4.2 KiB
Markdown
# Google Sheets MCP Server
|
|
|
|
First-party MCP server for Google Sheets API v4. It can run as a Paperclip
|
|
`local_stdio` gallery connection or as a local Streamable HTTP server for
|
|
Paperclip's `remote_http` connect-by-link flow.
|
|
|
|
## Configuration
|
|
|
|
The server uses Google service-account credentials only. OAuth is intentionally
|
|
not supported in v1.
|
|
|
|
Required:
|
|
|
|
- `GOOGLE_SHEETS_ALLOWED_SPREADSHEET_IDS`: comma or newline separated spreadsheet
|
|
IDs the server may access.
|
|
- One of:
|
|
- `GOOGLE_SHEETS_SERVICE_ACCOUNT_JSON`: inline service-account JSON, or a path
|
|
to a service-account JSON file.
|
|
- `GOOGLE_SHEETS_SERVICE_ACCOUNT_JSON_PATH`: path to a service-account JSON
|
|
file.
|
|
|
|
Equivalent CLI flags are available for local stdio templates:
|
|
|
|
```sh
|
|
paperclip-google-sheets-mcp-server \
|
|
--service-account-json-path /path/to/service-account.json \
|
|
--allowed-spreadsheet-ids sheet_id_1,sheet_id_2
|
|
```
|
|
|
|
Share each allowed spreadsheet with the service account's `client_email`.
|
|
|
|
## Paperclip `local_stdio` Test Path
|
|
|
|
Use the Google Sheets gallery app when you want Paperclip to supervise the
|
|
server as a stdio MCP process:
|
|
|
|
1. Configure Paperclip's Google Sheets service account environment so the
|
|
gallery marks Google Sheets as available. The service account JSON must be
|
|
provided by `GOOGLE_SHEETS_SERVICE_ACCOUNT_JSON` or
|
|
`GOOGLE_SHEETS_SERVICE_ACCOUNT_JSON_PATH`.
|
|
2. Share every spreadsheet you want to test with the service account's
|
|
`client_email`.
|
|
3. In Paperclip, open the tool app gallery, choose **Google Sheets**, and paste
|
|
one or more Google Sheets links.
|
|
4. Save the app connection. Paperclip creates a `local_stdio` connection using
|
|
the `paperclip.google-sheets` template and passes the selected spreadsheet
|
|
IDs to this server as `GOOGLE_SHEETS_ALLOWED_SPREADSHEET_IDS`.
|
|
5. Refresh the tool catalog and verify the Google Sheets tools appear for the
|
|
connection.
|
|
|
|
In this path, the spreadsheet allowlist comes from the gallery wizard. Every
|
|
tool call is still checked against the server-side allowlist before the server
|
|
calls Google.
|
|
|
|
## Paperclip `remote_http` Test Path
|
|
|
|
Use the HTTP binary when you want to exercise the same tools through
|
|
Paperclip's `remote_http` gateway:
|
|
|
|
```sh
|
|
GOOGLE_SHEETS_SERVICE_ACCOUNT_JSON_PATH=/path/to/service-account.json \
|
|
GOOGLE_SHEETS_ALLOWED_SPREADSHEET_IDS=sheet_id_1,sheet_id_2 \
|
|
GOOGLE_SHEETS_MCP_HOST=127.0.0.1 \
|
|
GOOGLE_SHEETS_MCP_PORT=8849 \
|
|
GOOGLE_SHEETS_MCP_TOKEN=local-test-token \
|
|
paperclip-google-sheets-mcp-http-server
|
|
```
|
|
|
|
The HTTP server prints the MCP endpoint on startup. With the values above, use:
|
|
|
|
```text
|
|
http://127.0.0.1:8849/mcp
|
|
```
|
|
|
|
Then in Paperclip, choose the remote HTTP or "connect with a link" path, paste
|
|
the `/mcp` URL, and configure the bearer token if `GOOGLE_SHEETS_MCP_TOKEN` is
|
|
set. The HTTP server accepts the token only as an `Authorization: Bearer
|
|
<token>` header.
|
|
|
|
HTTP configuration:
|
|
|
|
- `GOOGLE_SHEETS_MCP_HOST`: host to bind. Defaults to `127.0.0.1`. If this is
|
|
not a loopback host, `GOOGLE_SHEETS_MCP_TOKEN` is required and startup fails
|
|
closed when the token is omitted.
|
|
- `GOOGLE_SHEETS_MCP_PORT`: port to bind. Defaults to `8849`.
|
|
- `PORT`: platform-style port override. When set, it takes precedence over
|
|
`GOOGLE_SHEETS_MCP_PORT`.
|
|
- `GOOGLE_SHEETS_MCP_TOKEN`: optional shared secret for the `/mcp` route. Omit
|
|
only for loopback/local single-operator testing where no other process can
|
|
reach the server.
|
|
|
|
The HTTP server reuses the same service-account and spreadsheet allowlist
|
|
environment as stdio. In this phase, the HTTP spreadsheet allowlist is
|
|
process-level configuration (`GOOGLE_SHEETS_ALLOWED_SPREADSHEET_IDS` or
|
|
`GOOGLE_SHEETS_SPREADSHEET_IDS`), not a per-connection Paperclip gallery wizard
|
|
setting or shared multi-tenant policy. Treat this as a local/single-operator
|
|
test path. Restart the HTTP process with a different allowlist when you need to
|
|
test a different spreadsheet set.
|
|
|
|
## Tools
|
|
|
|
- `list_spreadsheets` (read)
|
|
- `get_spreadsheet_info` (read)
|
|
- `read_values` (read)
|
|
- `search_rows` (read)
|
|
- `append_rows` (write)
|
|
- `update_values` (write)
|
|
- `add_sheet_tab` (write)
|
|
- `clear_values` (destructive)
|
|
- `delete_rows` (destructive)
|
|
|
|
Every tool that accepts a spreadsheet ID rejects IDs outside the configured
|
|
allowlist before calling Google. `list_spreadsheets` lists only the allowlisted
|
|
IDs.
|