Video Chapters
0:00 What we are doing today
0:31 Why a server needs its own email
1:23 The six console steps
2:25 The key, and how people lose it
3:02 Sharing the folder
4:13 When search finds nothing
5:10 What it can and cannot do
5:51 Check that it works
6:33 Where the map stands

Give your helper a key to your Drive

Lesson 4 of 30, Module 1: The Whole Idea. You understand what MCP is, why it exists, and you have FELT the problem it solves.

Table of Contents
Downloads

Lesson 4 of 30, Module 1: The Whole Idea. You understand what MCP is, why it exists, and you have FELT the problem it solves.

What you can do after this lesson

An automated process needs its own credentialed identity before it can touch your resources, and the act that actually grants access is sharing the resource itself, not configuring roles somewhere upstream. Anywhere you connect code to an account you do not control by hand, ask two questions: who is this running as, and did I actually grant IT the resource, or just configure permissions near it. The corollary travels too: a system that indexes for search can lag behind a write that already succeeded, so verify a just-created or just-shared resource by its direct ID, never by searching for it by name.

Code in this lesson

Every block the lesson shows on screen, in the order it appears.

[email protected]
key.json
echo "# My first draft

This is a test. Ths line has a typo in it." > draft.md
https://drive.google.com/drive/folders/1AbCdEfGhIjKlMnOpQrSt
q = f"name = '{name}' and '{FOLDER}' in parents and trashed = false"
python3 verify_drive_access.py key.json YOUR_FOLDER_ID
RESULT: read yes. change yes. create no.

Downloads

Prefer to read?

The written version of this part of the course is on Substack: https://genaiunplugged.substack.com/p/why-mcp-was-created-full-course-lesson.

Lesson transcript

What we are doing today

Your server is about to become somebody. It gets an email address of its own, and you hand it a key.

Hello, and welcome to lesson 4 of the MCP Masterclass. Last lesson we got your machine ready. Today we give your AI a key to one folder in your Google Drive. And we start with our map, as always.

Still 6 lit boxes, and the folder at the far right of the diagram is about to become real.

Well, this is the lesson where I see most people get stuck, so we are going to go slowly. A few minutes of careful clicking, and 4 traps that I will call out before you reach them.

Why a server needs its own email

So let us take the idea first.

Your MCP server has to be somebody.

When a program asks Google for a document, Google wants to know who is asking. A program cannot log in the way you do, with a password and a code on your phone.

So Google lets you make a robot user. It is called a service account.

A service account is nothing but a user with an email address and no human behind it. You share files with it exactly the way you would share with a colleague.

That is the whole trick. Your server becomes a member of staff who can open one folder.

And this is where the name earns itself. Scribe is somebody, so in a minute you are going to give Scribe an email address and hand it a key.

Now, what are we about to do here?

6 steps in the Google Cloud console, then 1 step in Google Drive itself. Take them one at a time. None of them is hard, and none of them costs you money.

The six console steps

Step 1. Make a project.

Go to console.cloud.google.com and sign in with your normal Google account.

At the top of the page there is a project picker. Click it, choose New Project, name it scribe, and create it.

A project is nothing but a box that holds your settings. Nothing is running in it yet.

Step 2. Turn on the Drive API.

In the left menu, open APIs and Services, then Library. Search for Google Drive API, and turn it on.

This is free. Google says that all standard use of the Drive API costs nothing extra, and what we do here is a handful of calls a day.

Step 3. Make the service account.

In the left menu, open IAM and Admin, then Service Accounts.

Click Create service account. Give it the name scribe, then click Done. Skip the optional steps in the middle, because you do not need any of them.

Step 4. Copy its email address.

Your new robot user now has an email address. It looks like this on your screen.

[email protected]

Copy it somewhere you can reach in a minute. You need it in step 6.

The key, and how people lose it

Step 5. Make a key.

Click on the service account you just made, then open the Keys tab.

Click Add Key, then Create new key, then choose the JSON option, then Create.

A file downloads to your machine. Move it into your scribe folder and rename it to key.json.

And here is trap number 1. That file downloads once, and only once. Google does not keep a copy for you. If you lose it, come back here and make a new key.

Trap number 2. That file is a password in a costume. Anybody holding it can reach whatever you shared. So it never goes into git. Make an ignore file right now with one line in it.

key.json

Sharing the folder

Step 6. Share the folder.

Open Google Drive in your browser and make a folder called Drafts.

Now put a document in it. It has to be a plain text file, either mark down or txt.

That word has is doing real work there. A normal Google Doc will not work in this course, because Google Docs need a completely different API. And Drive cannot make a mark down file from its New button either.

So write a short file on your own machine and upload it.

echo "# My first draft

This is a test. Ths line has a typo in it." > draft.md

Upload that file into the Drafts folder.

Now right click the folder, choose Share, paste in the service account email from step 4, and give it the Editor role.

And here is trap number 3, and this is the big one. Sharing the folder is what grants access. Roles you set back in the Cloud console do not.

Google says this in its own docs, in plain words. Roles set in the console do not give access to Drive files. Only sharing does.

Skip this step and everything else will look correct while returning nothing at all. This is the single most common reason a setup like this fails.

One more thing while you are here. Open the folder and look at the address bar.

https://drive.google.com/drive/folders/1AbCdEfGhIjKlMnOpQrSt

That last part is the folder id. Copy it and keep it next to your key, because every lesson from here on needs it.

When search finds nothing

And that brings me to trap number 4, which is the sneakiest of the lot. Right after you share that folder, a search will find nothing at all.

Nothing is wrong. Sharing works the instant you press the button. But Google keeps a separate search index, and that index takes a while to catch up. So for the next few minutes your robot can open the folder perfectly well and still find it in no search results.

I ran into this myself, 3 minutes after sharing. Asking for the folder by its id worked straight away, and every search came back empty.

So there are 2 lessons in that. Give it a few minutes before you panic. And always ask by id, or search inside the folder, rather than by name alone.

That is why you copied the folder id a minute ago, and it is why every piece of code in this course looks like this.

q = f"name = '{name}' and '{FOLDER}' in parents and trashed = false"

I found this one by running it. A search by name alone gave me nothing at all, for a file I had edited successfully 10 seconds earlier.

What it can and cannot do

So what can your robot actually do, and what can it not do?

And here is the honest part, which is better news than it sounds.

A service account owns no storage space of its own. Zero bytes. And that has one effect you need to know about.

It can read a file you shared with it. It can change a file you own. But it cannot make a brand new file.

Making a file fails with an error about storage, and Google explains why in the error itself.

So this account can change your documents. It cannot make new ones, and for this course that is exactly what we want.

Scribe exists to fix drafts you already wrote. Never once does it need to create a file. And right at the end of this course I will show you how to lift this limit, if you ever want to.

Check that it works

So let us prove that it works.

Run the setup check that came in your module 1 checkpoint.

python3 verify_drive_access.py key.json YOUR_FOLDER_ID

Give it your folder id as well as your key. It then asks Google for that folder directly, which the search index cannot lie about.

You want to see this at the bottom.

RESULT: read yes. change yes. create no.

Read yes. Change yes. Create no. If you got that, your setup is correct, and the rest of this course will run.

And if it fails, the message tells you which of the 3 broke. A folder it cannot reach at all almost always means step 6 was missed.

One last time, because I have watched it catch people. If the check says it can reach your folder, but a search shows 0 files, you are fine. That is the index catching up, and nothing else.

Where the map stands

So where does our map stand at the end of this lesson?

Your Google Drive folder is now real, and your machine can reach it. Still 6 boxes, and still a hole in the middle.

Next lesson is the fun one. We try the obvious way, and we watch it fall over.

Bye now, and I will see you in the next lesson.

Frequently Asked Questions

The written version of this part of the course is on Substack: https://genaiunplugged.substack.com/p/why-mcp-was-created-full-course-lesson.

Dheeraj Sharma

Dheeraj Sharma

AI Systems Builder
Creator of the n8n Zero to Hero course (42 lessons, 31+ hours). I help solopreneurs build AI systems that grow revenue without growing workload.

Get the Scribe checkpoints and code

Every module ships a checkpoint zip with the server exactly as the module leaves it, so you can start any lesson from working code.

Open the GitHub repo