Workspace

Document Workflow Agent

Work with Drive, Sheets, and Slides together for document workflows.

document_workflow.py
"""
Document Workflow Agent
=======================

Work with Drive, Sheets, and Slides together for document workflows.

Use cases:
- Search Drive for files by name or content
- Read data from Sheets
- Find and analyze presentations
- Organize files across folders

Setup:
  1. Enable Drive, Sheets, and Slides APIs at https://console.cloud.google.com
  2. Create OAuth 2.0 credentials (Desktop app)
  3. Set env vars:
     - GOOGLE_CLIENT_ID
     - GOOGLE_CLIENT_SECRET
     - GOOGLE_TOKEN_ENCRYPTION_KEY (generate with: python -c "from agno.utils.encryption import generate_encryption_key; print(generate_encryption_key())")

First run opens browser for OAuth consent, saves encrypted token to DB.
Subsequent runs load the encrypted token — no re-auth needed.

Run:
  .venvs/demo/bin/python cookbook/91_tools/google/workspace/document_workflow.py
"""

from agno.agent import Agent
from agno.db.sqlite import SqliteDb
from agno.models.openai import OpenAIResponses
from agno.tools.google.auth import AuthConfig
from agno.tools.google.drive import GoogleDriveTools
from agno.tools.google.sheets import GoogleSheetsTools
from agno.tools.google.slides import GoogleSlidesTools
from agno.utils.encryption import generate_encryption_key  # noqa: F401

# Token encryption: set GOOGLE_TOKEN_ENCRYPTION_KEY env var (recommended)
# Or pass explicitly: AuthConfig(db=db, token_encryption_key=generate_encryption_key())
db = SqliteDb(db_file="tmp/document_workflow.db")
auth = AuthConfig(db=db)

agent = Agent(
    name="Document Assistant",
    model=OpenAIResponses(id="gpt-5.5"),
    tools=[
        GoogleDriveTools(auth=auth),
        GoogleSheetsTools(auth=auth),
        GoogleSlidesTools(auth=auth),
    ],
    instructions=[
        "You help manage and analyze documents in Google Drive.",
        "When searching, try multiple search terms if the first doesn't find results.",
        "Summarize spreadsheet data clearly with key metrics.",
        "For presentations, focus on the main themes and structure.",
    ],
    add_datetime_to_context=True,
    markdown=True,
)

if __name__ == "__main__":
    agent.print_response(
        "Search my Drive for any spreadsheets from this week and summarize what data they contain",
        stream=True,
    )

The database here stores OAuth credentials; it is not passed as the agent's session database. Drive and Sheets are configured for reading, while Slides uses its default editing tools. This configuration cannot move Drive files between folders. To read a Sheet, provide its tab name and range, or use Drive's CSV export when appropriate.

Run the Example

Set up your virtual environment

uv venv --python 3.12
source .venv/bin/activate

Install dependencies

uv pip install -U agno cryptography google-api-python-client google-auth google-auth-httplib2 google-auth-oauthlib openai openpyxl python-docx python-pptx sqlalchemy

Export environment variables

export GOOGLE_CLIENT_ID="your_google_client_id_here"
export GOOGLE_CLIENT_SECRET="your_google_client_secret_here"
export GOOGLE_PROJECT_ID="your_google_project_id_here"
export GOOGLE_TOKEN_ENCRYPTION_KEY="your_google_token_encryption_key_here"
export OPENAI_API_KEY="your_openai_api_key_here"

Configure shared OAuth and token encryption

Enable every Google API listed in the example and create a Desktop OAuth client. Export its client ID, secret, and project ID. The first tool call requests the combined scopes registered by the toolkits sharing auth.

Generate a token-encryption key once:

python -c "from agno.utils.encryption import generate_encryption_key; print(generate_encryption_key())"

Set GOOGLE_TOKEN_ENCRYPTION_KEY to that value instead of the placeholder and keep the same key across restarts. Creating a new key each launch prevents reading previously encrypted tokens. With encryption required but no key, tokens are not saved to the database.

This example stores one Google identity in its SQLite token table. An Agno user_id does not select a different Google account. Reuse also depends on valid credentials, granted scopes, and refresh access; revoked or unusable credentials can require consent again.

Run the example

Save the code above as document_workflow.py, then run:

python document_workflow.py

Full source: cookbook/91_tools/google/workspace/document_workflow.py