mirror of
https://github.com/openswarm-ai/openswarm.git
synced 2026-08-23 21:12:22 +02:00
google-workspace-mcp's gauth.py hardcodes token_uri to oauth2.googleapis.com and uses local CLIENT_ID/SECRET on every refresh. OAuth runs through a rotation pool on the cloud side, so the refresh_token is bound to the pool slot that minted it, not the single client baked into the DMG, and direct refreshes return unauthorized_client. Redirect spawn through a shim that monkey-patches get_credentials to point token_uri at a local proxy (/api/tools/google-oauth-token), which forwards the refresh to api.openswarm.com/api/oauth/google/refresh (pool-aware). Unblocks every Gmail/Drive/Calendar query for users on the cloud OAuth pool.