Workspace MCP 2.0
October 2, 2026 · Taylor Wilsdon
Fifteen months, 2 million downloads and clones, nearly 400 contributors, and 29 frontier models: how Workspace MCP got from v1.0 to v2.0.
What changed in v2.0.0
v2.0.0 moves the server to FastMCP 4 and MCP Python SDK v2. Clients on the sessionless 2026-07-28 protocol can reach any replica behind a plain load balancer, with no sticky sessions. Older clients keep their existing session handshake.
- Framework and security: Upgraded to
fastmcp>=4.0.10andmcp>=2.2.0, including upstream fixes for tokens appearing in request URLs, cancelled sessions leaking, and client OAuth authorization-server confusion. A matchingOriginandHostis trusted as same-origin only in OAuth 2.1 mode. #1202 - Session cleanup: Abandoned Streamable HTTP sessions now expire after 61 minutes of inactivity by default. Configure this with
WORKSPACE_MCP_SESSION_IDLE_TIMEOUT. Setting it to0defers to FastMCP'sFASTMCP_HTTP_SESSION_IDLE_TIMEOUT; if that is unset, sessions do not expire. Stateless mode ignores this setting. #1202 - Deployment and performance:
WORKSPACE_MCP_GOOGLE_API_WORKERSconfigures the thread pool for blocking Google API calls, and HTTP connections to Google are pooled and reused. Docker and Helm run Python as PID 1 for clean SIGTERM shutdowns. The startup banner shows the modes the server actually resolved. #1202 - Stdio authentication:
user_google_emailnow reaches the auth middleware correctly, anduserGoogleEmailis normalized before authentication reads it. #1202 - Drive sharing:
set_drive_file_permissionschecks every page of permissions before reporting link sharing off, so public grants beyond the first page are removed. Thanks to @ConnorMoss02. #1218 - Gmail attachments:
get_gmail_attachment_contentfalls back toattachment_indexwhen an attachment ID has gone stale, even without aWORKSPACE_MCP_MAX_FILE_BYTEScap, and selects the right file when several attachments share a size. #1216
Upgrading from v1.30.1: No tool migration is required. The major version reflects the new framework and protocol underneath. Stateful HTTP clients returning after the idle timeout receive 404 Session not found and must start a new session.
Full changelog: v1.30.1 → v2.0.0
Fifteen months later
I've spent an almost preposterous amount of what little free time I have working on an open source project born out of curiosity and necessity in early spring 2025. That doesn't sound that long, but in AI time it might as well be a decade ago.
v1.0 was the first time I deliberately shared it with anyone. The project had just a few active folks opening issues and pull requests, and exactly 105 GitHub stars. Fifteen months later, v2.0 belongs to a lot of people in a lot of different ways. The server has been downloaded or cloned more than 2 million times, including about 1.85 million downloads from PyPI. Since v1.0, nearly 400 people have filed issues or merged PRs, and more than 150 people besides me have contributed code to main.
It has 10x the codebase of v1.0, four more Google services, about 31x the GitHub stars, and a cast that went from my own two hands to 29 different frontier models from Anthropic, OpenAI, and Google. This code runs at some of the largest companies in the world, and I'm proud to say that in that entire time I have never shipped a release that had to be rolled back.
v1.0 went out on June 14, 2025, seven weeks after a commit labeled ca86d59 — initial scaffolding. v2.0 lands on October 2, 2026, 15 months and 109 releases later: about one release every four days.
Figures below are as of October 2, 2026.
| Metric | v1.0 (June 2025) | v2.0 (October 2026) | Growth |
|---|---|---|---|
| Google services | 8 | 12 | +4 |
| Tools | 41 | 119 | 2.9x |
| Source code | 5.3k lines | 53.6k lines | 10x |
| Auth modes | 1 | 8 | 8x |
| Frontier models | 7 | 29 | 4.1x |
| GitHub stars | 105 | 3,276 | 31x |
Who wrote this thing
The tooling turned over faster than the code did. Here's the cast, in order of arrival.
-
My very own fingers (gasp), Aider, and Roo Code, April to August 2025. The first commits are artisanal, hand-typed Python, or at least the commit messages are:
a7659d0— stage shitty branch on April 27, thenface6bc— hey it works great now nine days later. Aider and Roo Code did plenty of the typing, and neither left a fingerprint in the git log. Roo did keep its own receipts, though: its local task history logs the model on every turn, and it turns out I was model-hopping from day one. Claude 3.5 Sonnet, Claude 3.7 Sonnet, Gemini 2.5 Pro, and o4-mini-high all edited code on April 27, with Gemini 2.5 Flash, Claude Sonnet 4, and Claude Opus 4 joining in May. Gemini 2.5 Pro did more of the typing that summer than any other model. The open models got a shot too: DeepSeek-R1, DeepSeek-V3, GLM-4, and Qwen3 all took a turn, and none of them shipped a line. DeepSeek-R1's one real run, a cleanup pass in late May, died on a local branch whose next commit isunfuck deepseek adventure. -
GitHub Copilot, May 2025. The first AI co-author trailer in the repo landed May 6, 2025, a month before v1.0. It kept showing up through April 2026.
-
The first bot with its own GitHub account, July 2025.
Manamama-Gemini-Cloud-AI-01contributed a Calendar query parameter in #121. An AI as a contributor, not a co-author. -
Claude Code, August 2025.
14e11a3— Generated with Claude Code first appears on August 5, 2025, the same day full OAuth 2.1 merged. That's also when I switched for good: from here on, my own commits are Claude Code, and soon Codex too, just without the trailers. -
Codex, September 2025 on. My local Codex history holds 412 sessions in this repo across ten OpenAI models. GPT-5-Codex came first in September 2025, then GPT-5.1-Codex, GPT-5.1-Codex-Max, GPT-5.2-Codex, GPT-5.3-Codex, GPT-5.4, and GPT-5.5, the workhorse at 112 sessions. GPT-5.6 Sol, GPT-6 Astra, and GPT-6.1 Sol carried it into v2.0.
-
Agents opening their own PRs, December 2025.
copilot-swe-agentlands its first fix in #317. By February 2026, CodeRabbit is summarizing and reviewing PRs, and Cursor shows up in trailers. -
The model treadmill, 2026. Opus 4.5 and Sonnet 4.5 in January. Opus 4.6 in February, then Haiku 4.5, Sonnet 4.6, and the 1M context version of Opus 4.6 in March. That last one became the most common trailer in the repo. Opus 4.7 in April, Opus 4.8 in May, then Fable 5, Sonnet 5, and Opus 5 inside two weeks in July.
-
September 2026. Fable 5.1 and Opus 5.5 arrive, and
midna-agent, another agent with its own account, ships a Gmail fix in #1132.
That's twelve Claude models in co-author trailers, ten OpenAI models in my Codex history, and seven more Claude, Gemini, and OpenAI models in my Roo Code history, plus Copilot, Cursor, and CodeRabbit.
Those counts combine git co-author trailers with local session history. Aider rides inside my own commits with no fingerprint. Roo Code and Codex records come from local history: Roo logs the models that edited files, and Codex logs the model used in each session.
The biggest leaps since v1.0
The server grew from a single-user laptop tool into multi-tenant infrastructure. These are the jumps that got it there, across the releases leading up to v2.0.
-
Auth grew up. v1.0 had one local OAuth 2.0 flow. Full OAuth 2.1 landed August 5, 2025 in #137, seven weeks after the 2025-06-18 MCP spec revision. Then came external OAuth providers #248, domain-wide delegation service accounts #665, secretless PKCE for public clients #677, Client ID Metadata Documents (CIMD) so clients like ChatGPT can register themselves #748, and trusted-gateway identity for enterprise proxies #981. Credentials can live in memory, on disk, in Valkey #328, or in Google Cloud Storage with customer-managed keys #724.
-
From a laptop to a load balancer. A Helm chart #146, stateless container mode #189, OpenTelemetry tracing #938, and a hosted cloud tier. v2.0 finishes the job: on the sessionless 2026-07-28 MCP protocol, any replica behind a plain load balancer can serve any request, with no sticky sessions #1202.
-
Docs editing beyond plain text. Granular editing #159, tabs #539, Markdown export with comment context #490, smart chips #649, full table operations #656, writing a tab straight from Markdown #727, and one PR that added styling, named ranges, and headers in 5,100 lines #628.
-
Four more Google services. Tasks #91 and Programmable Search #134 in July 2025, then Apps Script #357 and Contacts #386 in January 2026.
-
Agents became first-class users. v1.0 targeted Claude Desktop over stdio. v2.0 plugs into Claude Connectors on web and mobile, ChatGPT Developer Mode, Cowork, and VS Code. A CLI mode lets coding agents drive Workspace with no MCP connection at all #412, and there's a Claude Code skill #589 and plugin #623.
-
Hardening for real deployments. Fixes for server-side request forgery (SSRF) #453, cross-site scripting in the OAuth callback #559, a CI injection hole #746, credential file permissions #657, user text kept out of logs #1037, and zip-bomb limits on Office files #1153.
-
Two framework rewrites. FastMCP 2.3.3 to v3 in February 2026 #468, then v4 and MCP SDK v2 for this release #1202. Neither framework migration required changes to the tool interfaces.
The tool count, briefly
We went from 41 tools to 136, then cut back to 111 on purpose. v2.0 ships with 119. Every feature request had become its own tool, but clients had hard tool limits, and every schema burned context before the first prompt. So in March 2026 we merged the single-purpose CRUD tools into action-based ones #531. Tool tiers, read-only mode, per-service permissions, and a progressive-disclosure skill were all part of the same fight.
Dynamic tool discovery lets models load the tools they need when they need them, reducing how much context a large tool catalog consumes up front.
The people who did this
Nearly 400 people filed issues or merged PRs since v1.0. That adds up to 441 merged PRs: 163 from me and 278 from everyone else, across 158 authors, including me, 154 other people, and three bots and agents. There were 405 issues, 316 of them closed, and 109 releases, about one every four days. The project has 1,023 forks, more than 2 million downloads and clones, and 3,276 stars, up from 105 at v1.0.
These outside contributors merged the most PRs since v1.0:
- @123andy — 11 PRs, 38 commits. Trusted-gateway identity, keeping user text out of logs, and zip-bomb limits on Office files. And he's the type of dude who sponsors open source work, so he's a real one.
- @mickey-mikey — 7 PRs, 85 commits. The Claude Code skill and plugin marketplace, plus the most commits of anyone but me.
- @DrFaust92 — 7 PRs, 9 commits. OpenTelemetry tracing, Helm persistent volumes, and Zoom, Webex, and Teams conferencing.
- @ConnorMoss02 — 7 PRs, 14 commits. Gmail label colors, Calendar pagination, and a Drive sharing fix in this very release.
- @cfdude — 7 PRs, 19 commits. Full Docs table operations, image insertion, and Drive file metadata.
- @seidnerj — 6 PRs, 15 commits. MCP tool annotations, raw and HTML email bodies, and timezone-correct events.
- @Bortlesboat — 6 PRs, 7 commits. Token auto-refresh in stdio mode, reply threading, and camelCase argument handling.
A special thanks to @jlowin and FastMCP. This server has run on FastMCP through three major versions, and its OAuth proxy, CLI tooling, and sessionless transport are a big reason one person could keep pace with the spec.
And to everyone who filed a bug with useful information: thank you.
v2.0 swaps in the newest foundation underneath the tools you already use. The next version will probably be co-authored by a model that doesn't exist yet.