Launch announcement

Workspace MCP v2: Model Context Protocol All Grown Up

Fifteen months, 2 million downloads, nearly 400 contributors and 41 tools & models: how Workspace MCP got from v1 to v2.0.0

These past few years, I’ve spent an almost preposterous amount of what little free time I have working on an open source project - a project that was born out of both curiosity & necessity in early spring 2025. Spring of 2025 doesn’t sound that long ago, but in AI time that might as well be a decade ago. v1.0 was the first time I deliberately shared it with anyone, and at the time the project had a just few active folks opening issues and pull requests with exactly . Fifteen months later, v2.0 ships today and it belongs to a lot of people in a lot of different ways. The server has passed , about 1.85 million of them from PyPI. Since v1.0, have opened and opened , and of them besides myself contributed code into main.

It has of v1.0, four more Google services, about , and it was written by a cast that went from my own two hands to from Anthropic, OpenAI, DeepSeek, Qwen, Z.ai and Google. Surprisingly, we appear to have never merged anything with an obvious signature from the Grok family. This code runs at some of the largest companies in the world, and I’m proud to say that in that entire time I have never shipped a release that had to be rolled back. v1.0 went out on June 14, 2025, seven weeks after a first commit labeled ca86d59 initial scaffolding. v2.0 lands October 2, 2026, later.

v1.0 Jun 2025v2.0 Oct 2026Growth
Google services812+4
Tools411192.9x
Source code5.3k lines53.6k lines10x
Auth modes188x
Tools & models12413.4x
GitHub stars1053,27631x

Who (or what) wrote this thing?

The tooling turned over faster than the code did. Here’s the cast, in order of arrival.

  1. My very own fingers (gasp), Aider and Roo Code, April to August 2025. The first commits are artisanal, hand-typed Python, or at least the commit messages are: a7659d0 stage shitty branch on April 27, then face6bc hey it works great now nine days later. Aider and Roo Code did plenty of the typing, and neither left a fingerprint in the git log. Roo did keep its own receipts, though: its local task history logs the model on every turn, and it turns out I was model-hopping from day one. Claude 3.5 Sonnet, Claude 3.7 Sonnet, Gemini 2.5 Pro and o4-mini-high all edited code on April 27, with Gemini 2.5 Flash, Claude Sonnet 4 and Claude Opus 4 joining in May. Gemini 2.5 Pro did more of the typing that summer than any other model. The open models got a shot too: DeepSeek-R1, DeepSeek-V3, GLM-4 and Qwen3 all took a turn, and none of them shipped a line. DeepSeek-R1’s one real run, a cleanup pass in late May, died on a local branch whose next commit is local unfuck deepseek adventure.
  2. GitHub Copilot, May 2025. The first AI co-author trailer in the repo landed May 6, 2025, a month before v1.0. It kept showing up through April 2026.
  3. The first bot with its own GitHub account, July 2025. Manamama-Gemini-Cloud-AI-01 contributed a Calendar query parameter #121. An AI as a contributor, not a co-author.
  4. Claude Code, August 2025. 14e11a3 Generated with Claude Code first appears on August 5, 2025, the same day full OAuth 2.1 merged. That’s also when I switched for good: from here on, my own commits are Claude Code, and soon Codex too, just without the trailers.
  5. Codex, September 2025 on. My local Codex history holds in this repo. GPT-5-Codex came first in September 2025, then GPT-5.1-Codex, GPT-5.1-Codex-Max, GPT-5.2-Codex, GPT-5.3-Codex, GPT-5.4, and GPT-5.5, the workhorse at 112 sessions. GPT-5.6 Sol, GPT-6 Astra and GPT-6.1 Sol carried it into v2.0.
  6. Agents opening their own PRs, December 2025. copilot-swe-agent lands its first fix #317. By February 2026, CodeRabbit is summarizing and reviewing PRs and Cursor shows up in trailers.
  7. The model treadmill, 2026. Opus 4.5 and Sonnet 4.5 in January. Opus 4.6 in February, then Haiku 4.5, Sonnet 4.6 and the 1M context version of Opus 4.6 in March. That last one became the most common trailer in the repo. Opus 4.7 in April, Opus 4.8 in May, then Fable 5, Sonnet 5 and Opus 5 inside two weeks in July.
  8. September 2026. Fable 5.1 and Opus 5.5 arrive, and midna-agent, another agent with its own account, ships a Gmail fix #1132.

That’s twelve Claude models in co-author trailers, ten OpenAI models in my Codex history, seven more Claude, Gemini and OpenAI models in my Roo Code history and four open models from DeepSeek, Z.ai and Qwen that never shipped a line, plus Copilot, Cursor and CodeRabbit.

The cast, in order of arrival Apr ’25 Oct ’26

From fingers to frontier models

Git co-author trailers, local Codex sessions and Roo Code history.

  • Me, no trailer
  • Claude Code and Claude models
  • OpenAI models, from my sessions
  • Open-weight DeepSeek, Z.ai and Qwen models, from my Roo sessions
  • Gemini models, other AI tools and agent accounts
  • Single day
Tools & models Dates observed
v1.0 v2.0

Aider rides inside my own commits with no fingerprint, so it shares my row until the switch to Claude Code in August 2025. Roo Code and Codex rows come from my local session history, not git: Roo rows show the first and last day each model edited files, open-model rows show the first and last day each one was run against the repo, and Codex rows show the first and last session on each model.

The biggest leaps

The server grew from a single-user laptop tool into multi-tenant infrastructure. These are the jumps that got it there.

  1. Auth grew up v1.0 had one local OAuth 2.0 flow. Full OAuth 2.1 landed August 5, 2025 #137, seven weeks after the 2025-06-18 MCP spec revision. Then came external OAuth providers #248, domain-wide delegation service accounts #665, secretless PKCE for public clients #677, CIMD so clients like ChatGPT can register themselves #748, and trusted-gateway identity for enterprise proxies #981. Credentials can live in memory, on disk, in Valkey #328, or in GCS with customer-managed keys #724.
  2. From a laptop to a load balancer A Helm chart #146, stateless container mode #189, OpenTelemetry tracing #938 and a hosted cloud tier. v2.0 finishes the job: on the sessionless 2026-07-28 MCP protocol, any replica behind a plain load balancer can serve any request, with no sticky sessions #1202.
  3. Docs editing that nobody else does Granular editing #159, tabs #539, Markdown export with comment context #490, smart chips #649, full table operations #656, writing a tab straight from Markdown #727, and one PR that added styling, named ranges and headers in 5,100 lines #628.
  4. Four more Google services Tasks #91 and Programmable Search #134 in July 2025, then Apps Script #357 and Contacts #386 in January 2026.
  5. Agents became real users v1.0 targeted Claude Desktop over stdio. v2.0 plugs into Claude Connectors on web and mobile, ChatGPT Developer Mode, Cowork and VS Code. A CLI mode lets coding agents drive Workspace with no MCP connection at all #412, and there’s a Claude Code skill #589 and plugin #623.
  6. Hardened for people who’d notice SSRF #453, XSS in the OAuth callback #559, a CI injection hole #746, credential file permissions #657, user text kept out of logs #1037 and zip-bomb limits on Office files #1153.
  7. Two framework rewrites FastMCP 2.3.3 to v3 in February 2026 #468, then v4 and MCP SDK v2 for this release #1202.

All of that puts Workspace MCP at #20 of 139,717 servers on MCP Toplist, the top 0.1%.

MCP Toplist standing for Workspace MCP: #20 of 139,717 tracked servers, top 0.1%, with 1,007 GitHub stars gained since April 27.

The tool count, briefly

We went from 41 tools to 136, then cut back to 111 on purpose. v2.0 ships with 119. Every feature request had become its own tool, but clients had hard tool limits, and every schema burned context before the first prompt. So in March 2026 we merged the single-purpose CRUD tools into action-based ones #531. Tool tiers, read-only mode, per-service permissions and a progressive-disclosure skill were all part of the same fight.

That fight is ending. Major clients are making dynamic tool discovery a baseline capability: the model loads what it needs when it needs it, and the tool count stops being a tax.

The people who did this

Nearly 400 people filed issues or merged PRs since v1.0. That adds up to out of 799 opened by , , , 1,023 forks and over . We had at v1.0 and have today.

These outside contributors merged the most PRs since v1.0:

  • @123andy 11 PRs 38 commits

    Trusted-gateway identity, keeping user text out of logs, zip-bomb limits on Office files (and he's the type of dude who sponsors open source work, so he's a real one)

  • @mickey-mikey 7 PRs 85 commits

    The Claude Code skill and plugin marketplace, plus the most commits of anyone but me

  • @DrFaust92 7 PRs 9 commits

    OpenTelemetry tracing, Helm persistent volumes, Zoom, Webex and Teams conferencing

  • @ConnorMoss02 7 PRs 14 commits

    Gmail label colors, Calendar pagination, and a Drive sharing fix in this very release

  • @cfdude 7 PRs 19 commits

    Full Docs table operations, image insertion, Drive file metadata

  • @seidnerj 6 PRs 15 commits

    MCP tool annotations, raw and HTML email bodies, timezone-correct events

  • @Bortlesboat 6 PRs 7 commits

    Token auto-refresh in stdio mode, reply threading, camelCase argument handling

A special thanks to @jlowin and FastMCP. This server has run on FastMCP through three major versions, and its OAuth proxy, CLI tooling and sessionless transport are a big reason one person could keep pace with the spec.

And to everyone who filed a bug with useful information: thank you.

v2.0 keeps every tool working as it did and swaps in the newest foundation underneath. The next version will probably be co-authored by a model that doesn’t exist yet.