Skip to main content
The hub gives Claude one connector that reaches several Google accounts at once. It runs in your own Google Cloud project, so your Google sign-ins and your bill stay yours. Setting it up is done from the installer. You will not run any commands. Prefer to watch along? There is a full install video that walks through every step on this page, start to finish.
Access follows a licence, granted per account. If the installer page does not show an MCP Hub section, buy one at hub.magicmealkits.com/buy with the same address you sign in to the installer with.

What you will need

  • A Google Cloud project with billing linked. The hub costs almost nothing to run and scales to zero when nobody is using it, but Cloud Run will not deploy into a project with no billing account attached. If you have never used Google Cloud, see below.
  • About twenty minutes of clicking, in two sittings, with a wait in between while Google approves your project. That is usually about a working day, which is why applying is the second thing you do rather than the last.
  • A Google Workspace account, if you have one. You can set the hub up without one, but Google’s Developer Preview application will only accept a Workspace address. There is a way around that, covered below and in Developer Preview.

If you have never used Google Cloud

If you do not have a Google Cloud account at all yet, see Signing up for Google Cloud first, then come back here. Already signed up but have no project? The installer will show No projects found and tell you what to do, which is: open the Google Cloud console, accept the terms, set up billing, and come back. Then Create new project on the installer makes your first one without leaving the page. A new project can take a few minutes to appear in the list. There is a refresh beside the dropdown for that.

Deploy the hub

Open the installer, sign in, and scroll to MCP Hub. You will need to be connected with the Google account you use for Google Cloud; the installer needs that to see your projects and to deploy into one.
1

Choose a project, run the check, and deploy

Pick a project from the Google Cloud project dropdown in the Deploy your hub card. A project of its own is worth it: the hub is given access to secrets across the whole project it lives in, so anything else you keep in that project is in reach. Sharing a project works, it is just a wider door than it needs to be. Set the region now too; changing it later means stopping the hub and deploying again.Press Run check first. It turns on the Google APIs the hub needs and tells you which ones worked. Nothing is created and nothing is billed.
All of them turning on does not mean you are approved. The APIs switch on with or without Developer Preview approval. This screen cannot tell you which, and without approval the refusal arrives later, when Claude actually asks for something.
Then tick the acknowledgement and press Deploy hub.
The deploy card, with the project dropdown, region, run-check button, acknowledgement checkbox and deploy button, each numbered in order
It takes a couple of minutes and says what it is doing as it goes. If it stops on billing, link a billing account to the project from the button in the message and deploy again.
2

The hub is running

The hub running card, showing the admin UI address, a hidden admin token with reveal and copy buttons, and the button to open the admin UI
Copy the admin token, then press Open the admin UI. You do not have to write the token down anywhere clever; it stays on this card, behind the reveal and copy buttons, whenever you come back to the installer.
3

Sign in

The hub's admin UI login screen, with a field for the admin token and a sign-in button
Paste the token into the field and sign in. Do this now rather than later: it is the quickest way to know the install worked, and everything after this point happens in this screen.

Apply for Developer Preview

Do this next. Approval usually comes back within a working day, and everything else below can happen while you wait for it. Google keeps the Gmail, Calendar and Drive services this hub uses closed until your project is approved. Until then the hub runs and looks healthy, and every request comes back refused. Back on the installer, scroll down to Apply for the Developer Preview Program. It opens Google’s form with your project number already filled in.
The installer's Developer Preview Program card, with the project number pre-filled and an apply button, plus a second card underneath for requesting on your behalf if you have no Workspace account
The email must be a Workspace address. Google’s form asks What Email should we grant access to Developer Preview features? and rejects Gmail addresses, service accounts and group addresses. This is the single most common reason an application comes back rejected.No Workspace account? Use the Don’t have a Workspace account? card underneath and we apply on your behalf.
Fill in the remaining required fields and submit. The full picture, including a walk through the form itself and what to do while you wait, is on Developer Preview.

Create your OAuth client

This is the one part the installer cannot do for you: Google offers no way to create these credentials automatically, so you make them yourself in the console. They live in your project. We never hold them.
The installer's OAuth client card, with three numbered steps, each opening the Google Cloud console, and the redirect address to copy
The card has a button for each step. It takes about ten minutes and produces two values, a client ID and a client secret, which the next section asks for. Creating your OAuth client walks it through one screen at a time, including the step that stops your accounts signing themselves out every week.

Add a Google account

This is where you decide which of your Google accounts the hub may act on. One entry per account, and each one says which services it may reach. Nothing is connected until you add it here, and removing it here disconnects it. An account and a client are two different things, and this screen asks for both. Accounts and clients is a two minute read if that distinction is not clear yet.
The hub's Accounts screen with no accounts yet, and an Add account button
Press Add account. Give the account a short name, choose the OAuth client to sign it in with, and pick the services you want. Select all turns on every service at once. The name is what you will say to Claude when you want it to act on that account, so keep it obvious: personal, work. Lowercase letters, numbers, - and _ only. For the very first account there is no client yet, so choose Enter a new client and paste the client ID and secret from the previous step. After that the client is in the list and every further account picks it automatically.
The add account form, with the account name field, the OAuth client choice set to enter a new client, and the client ID and secret fields
Then choose the services this account should reach. The hub can currently reach Calendar, Chat, Docs, Drive, Gmail, Contacts, Sheets and Slides, chosen per account, so a work account can have more turned on than a personal one.
The service checklist on the add account screen, with a select all control and the add account button

Connect it to Google

Press Connect, and you land in Google’s own sign-in flow.
1

Connect now

The hub confirming the account was added, with a Connect now button and a note that you have to sign in with that account next
The account exists in the hub, but nothing is granted yet. Press Connect now and sign in with the Google account you named it after.
2

Choose the account

Google's Choose an account screen
3

Google warns the app is unverified

Google's Google hasn't verified this app warning, with an Advanced link
That warning is about apps Google has not reviewed, and it is aimed at people being sent to a stranger’s app. This one is yours. You made it a few minutes ago, in your own project, and nobody else can use it. Press Advanced.
4

Go to the app anyway

The expanded warning, with a Go to (app name) (unsafe) link revealed underneath

The link only appears after you expand Advanced.

Take the Go to … (unsafe) link. Going ahead is the expected path here, not a risk being taken.
5

Continue

The Sign in to your hub screen, explaining what the app will be able to access, with a Continue button
6

Tick Select all

The Google permissions screen, with a Select all checkbox above the individual permission list
Tick Select all. Google leaves every box empty, and pressing Continue without them connects the account successfully and grants nothing. It looks like it worked. Nothing works.
Scroll down for the rest of the permission list, then press Continue.
7

Trust the app, and continue

The final Make sure you trust screen, with Cancel and Continue buttons
8

Connected

The hub showing the account as connected, with its granted services listed and an assistant connection section showing its own MCP address
Back in the hub, the account shows as connected, with the services it can reach. Notice the Assistant connection section right on this page: it already shows an MCP address for this hub, the same one the Connect Claude step below asks you to copy.

Add a second account

Add as many accounts as you like, and mix personal and work accounts freely. The steps are the same as above, with one shortcut: you do not need a new OAuth client.
1

Add account, again

The accounts screen, now showing the first account connected, with the Add account button
2

Name it, and reuse the existing client

The add account form for a second account, with the account name field and the existing OAuth client already selected instead of enter a new client
Give it a name, work for instance, and this time pick the client you already made instead of Enter a new client. Almost always one client covers a personal Gmail account and a work Workspace account both. The one case it does not, and what to do instead, is covered in how many projects you need.
3

Choose services and submit

The service checklist for the second account, with every service selected
4

Connect it

The hub confirming the second account was added, with a Connect now button
Press Connect now and sign in with the second account. The Google screens are the same ones you just saw: choose the account, past the unverified warning, Select all, and continue.
5

Both accounts connected

The accounts screen showing both accounts connected, with their respective services listed
6

Check it back on the installer

The installer's Add account card now showing two accounts connected, with the Claude connect card visible underneath
The installer’s Add account card now shows how many accounts are connected. Beneath it sits the Connect Claude card, which is what the next section uses.

Optional: open the admin screen with your Google account

Nothing above depends on this and you can come back to it any time. This is only about how you get into the admin screen. Out of the box that is the admin token, which means anyone holding the token can open it. Turning this on lets you sign in with your Google account instead, and only the address you signed up with is allowed through. Token sign-in keeps working either way. This adds a door rather than moving one.
The optional card for turning on Google sign-in, with its numbered steps and the fields for a client ID and secret
It reuses the OAuth client you already made. The card numbers the steps and has a button for each, in the same style as the OAuth card:
  1. Copy the redirect address it shows you. This is a second address, for signing in rather than for connecting accounts.
  2. Open client settings takes you to the client you made earlier. Add the address there, alongside the one already in the list. Do not replace it.
  3. Open consent screen takes you to Data access, where you tick openid and email. These say the app may see who you are and your address, and nothing else.
  4. Paste the client ID and secret back into the card and press Apply.
  5. Open the admin screen again. There should now be a Sign in with Google button on it.

Connect Claude

1

Copy the MCP address

The installer's Connect Claude card, with the MCP address and a copy button
The Connect Claude card on the installer has it, and so does the assistant connection section on any connected account’s page.
2

Add a custom connector in Claude

Claude's Settings, Connectors screen, with the Add menu open and Add custom connector highlighted
In Claude, open Settings, then Connectors, then Add, then Add custom connector.
3

Paste the address

The Add custom connector dialog, with a name field and the MCP URL pasted in, OAuth client ID and secret left blank
Name it whatever you like, paste the address, and leave the client ID and client secret fields empty. Press Add.
4

Connect

The new connector's detail page in Claude, not yet connected, with a Connect button
5

Allow it

Claude's Allow this connector screen, listing what it will reach for each connected account, with the write-capable permissions highlighted
The same screen scrolled down, showing the full scope list, a note that the connector stays connected and can renew its own access, and the Allow button
A browser window opens showing exactly what each of your connected accounts grants Claude, permission by permission, with the ones that can change or send something called out. This does not widen anything you already granted the hub; it is showing you what you already gave it. It stays connected: once you press Allow, Claude can renew its own access without asking you again. Press Allow.
That address is not a password. Anyone who has it reaches your sign-in screen and gets no further, so it is safe in a screenshot or a support thread. The same address works in ChatGPT and in anything else that speaks MCP; the screen it goes into is named differently in each, but the address does not change. To check it worked, ask for something that names an account: “search my last 3 emails using account personal”.

Choose how much Claude can do on its own

Once connected, Claude’s Connector settings for the hub carry a Tool permissions panel. Every tool the hub exposes falls into one of three groups, and each group can be set independently to Needs approval, Always allow, or Never allow.
The Tool permissions panel, showing Interactive tools and Read-only tools groups, both set to Needs approval by default
By default everything needs approval, so Claude asks before every call, even a read. Interactive tools (diagnosing the hub) and read-only tools (searching mail, listing events) are usually safe to set to always allow, so Claude can work through a multi-step request without stopping to ask each time.
The same panel with Interactive tools and Read-only tools both switched to Always allow
Write and delete tools are a different question, because a mistaken call here sends a message or deletes something rather than just reading it.
The Write/delete tools group, mostly set to Always allow, with one tool, Create label, deliberately left on Needs approval
Setting the whole group to always allow lets Claude carry out a task like sending a draft or moving a message to trash without stopping to ask each time, which is convenient but leaves less room to catch a mistake. Leaving individual tools on needs approval, the way Create label is left set in the screenshot above, keeps Claude pausing before that specific action while everything else in the group runs freely.

That is the setup done

Until Developer Preview approval lands, requests will still come back refused. When the approval email arrives, open the admin screen and press Refresh next to the schema status once, and the tools appear.

Next