Repository navigation
RFC: Feature Configuration Service — Read/Write Scope-Based Feature Toggles #255
Description
Activity
- marked Feature Request: Add Support for Customizable OAuth Scopes to Prevent Unintended Email Operations #111 as a duplicate of this issue
on Mar 3, 2026 - marked Gemini CLI Workspace Extension wants additional access to your Google Account #86 as a duplicate of this issue
on Mar 3, 2026 one feedback: Why not unify into one list since things are already defaulted?
WORKSPACE_FEATURE_OVERRIDES="gmail.write:off,slides.write:on".
The read/write split seems sensible.LGTM.
Is the read/write split the right granularity? Or would you prefer per-tool toggles?
Read and write make sense. I assume there will be more ❌ OFF with new defaults at the end of this? If read-only scope are defaults it may help myself and others get this extension added to our google auth allow list. (note: it's currently approved for me as I'm in my own OU). However, I would like to use this tool as a power user and give it full permission to google workspace to maximize it's potential. Why else would I use a workspace MCP server :). Then users could add allows tools and disallow tools in Gemini CLI. Worth noting there are other tools (#196 (comment))
Are there other services or scopes you'd like to see supported?
May as well add keep to the list above (#159)
Enterprise user here, per tool toggles would be required for us to onboard. Specifically on disabling delete tools, but not other types of writes.
Reacted by Stefano Amorelli and Thanakom SangnetraThanks for the great feedback everyone! Here's how we're incorporating it:
@Jefftree — Love the unified env var idea. We're adopting
WORKSPACE_FEATURE_OVERRIDESwith yourfeature:on/offsyntax as the power-user configuration layer.@bdoyle0182 — We're extending the override syntax to support per-tool toggles (subtractive only from enabled groups):
WORKSPACE_FEATURE_OVERRIDES="calendar.deleteEvent:off,gmail.send:off"This lets you keep
calendar.writeenabled while disabling specific destructive tools.@raybell-md — Google Keep added to the roadmap. Good point about the enterprise allowlist — defaulting to readonly scopes will help there. We're keeping writes default-ON for now to avoid breaking existing users, but the settings UI makes it easy to turn them off.
Updated Design: Three-Layer Configuration
-
Install-time UI (via
gemini-extension.jsonsettings) — Per-service read/write toggles shown duringgemini extensions install. Users check off which services they want without touching env vars. -
Power-user overrides —
WORKSPACE_FEATURE_OVERRIDESenv var with group-level (gmail.write:off) and tool-level (calendar.deleteEvent:off) syntax. -
Baked-in defaults — Current services default ON, future/experimental services (Tasks, Slides write, Sheets write) default OFF.
Precedence: Power-user overrides > Settings UI > Defaults
This gives most users a clean install experience while giving enterprise and power users the fine-grained control they need.
Reacted by Ray Bell, Stefano Amorelli, Oskar, Thanakom Sangnetra, Brendan Doyle and Tommy Nguyen-
- added 4 commits that reference this issue
on Mar 20, 2026 This would be really valuable for MCP clients like Claude Code that already have managed connectors for Gmail and Calendar. Without service filtering, adding this server means ~35 duplicate/unused tools in the deferred tool list alongside the ~20 we actually need (Drive, Docs, Sheets, Slides).
The env var approach in the RFC looks great. Even a simpler first pass — just disabling entire services via something like
WORKSPACE_SERVICES=drive,docs,sheets,slides— would unblock adoption for a lot of us. Happy to help test if a branch lands.- added a commit that references this issue
on Apr 1, 2026
Summary
We need a configuration mechanism to let users control which services and scopes the extension requests. This solves two problems:
Contributor PRs that need new scopes — PRs like feat(tasks): add support for Google Tasks #106 (Google Tasks), fix(slides): enable reliable Slides tool usage and write operations #237/feat(slides): add write tools for Google Slides #235 (Slides write), and Feat sheets insert text #233 (Sheets write) add features requiring scopes that aren't enabled in the published GCP project. Contributors should be able to develop and test these features with their own GCP projects, while the features remain opt-in for other users.
Users want scope control — Issue Gemini CLI Workspace Extension wants additional access to your Google Account #86: users who only need a few services don't want to auth for all scopes. Issue Feature Request: Add Support for Customizable OAuth Scopes to Prevent Unintended Email Operations #111: users want to restrict Gmail to read-only to prevent accidental sends.
Proposed Design: Read/Write Feature Groups
Each service is split into read and write groups. Read groups have no side effects and use readonly scopes. Write groups perform mutations and require elevated scopes.
docsdocumentsdocsdocuments,drivedrivedrive.readonlydrivedrivecalendarcalendar.readonlycalendarcalendarchatchat.spaces.readonly,chat.messages.readonly,chat.memberships.readonlychatchat.spaces,chat.messages,chat.membershipsgmailgmail.readonlygmailgmail.modifypeopleuserinfo.profile,directory.readonlyslidespresentations.readonlyslidespresentationssheetsspreadsheets.readonlysheetsspreadsheetstimetaskstasks.readonlytaskstasksKey points:
auth.clear,auth.refreshToken) are always registeredConfiguration via Environment Variables
Rules:
WORKSPACE_DISABLED_FEATUREStakes precedence — disables even default-ON featuresWORKSPACE_ENABLED_FEATURESenables default-OFF featuresImpact on Contributors
Contributors adding new services would:
This lets contributors develop and merge new features without being blocked by the published GCP project's scope configuration.
Questions for the Community
Related Issues & PRs