Create and edit Google Slides presentations: slides, text, images, shapes and tables.
Google Slides ships in the w6w first-party pack. It declares 17 actions, 2 health checks, and the host runs its code in a sandbox that never sees the credential.
io.w6w.google-slidesGoogle Slides builds and edits presentations from a workflow — create a deck, add and reorder slides, insert or replace text across the whole presentation, drop in images and shapes, build a table, and duplicate or delete any object on a page.
The common editing verbs (create a slide, insert text, replace text everywhere, swap a shape for an image, build a table) are exposed as plain form fields; deeper formatting and structural edits — text style, borders, table row and column editing — go through Slides’ own raw batch-update payload, so nothing here goes stale the moment Google adds a style property. Text and shape replacement report exactly how many matches they changed, so a template run that silently matched nothing can be caught and failed on purpose rather than shipping a deck with a stale placeholder.
It fits report-generation and templating workflows — filling a pitch deck from CRM data, swapping a logo across every slide, or assembling a deck slide by slide from another system — for a Google account or a service account with access to the presentation.
Three routes to the same 17 actions. The Workflow tab is generated from Google Slides's own manifest and carries its real ids, so it is copy-pasteable; the Code and CLI examples are the same call for any action on any app, so every app-specific value in them is a blank you fill in.
element-alt-text-update Set the alt text title and/or description of a page element, for screen readers.
object-duplicate Duplicate a slide or a page element, optionally naming the copies' object IDs.
page-get Fetch a single page (slide, layout, master or notes page) and its page elements by object ID.
page-get-thumbnail Render a page to a PNG and return a short-lived URL to it. Counts against Google's expensive-read quota.
presentation-batch-update Send an arbitrary array of Google Slides `Request` objects to `presentations.batchUpdate`. Use the per-verb actions when one exists; this is the escape hatch for the rest of the 44-member union.
presentation-create Create a new, blank Google Slides presentation with a title.
presentation-get Fetch a presentation's metadata plus every slide, layout and master — including the object IDs the write actions need.
shape-create Add a shape — a text box, rectangle, ellipse, arrow or any other Slides shape type.
shapes-replace-with-image Swap every shape containing a marker string for an image, reporting how many shapes changed.
slide-create Add a slide, optionally from a layout and with named placeholder object IDs.
text-replace-all Replace every occurrence of a string across the presentation (or specific pages), reporting how many occurrences changed.
A workflow step names the app and the action, and the editor fills in the
connection when you pick one. This is the Step shape from the
workflow spec, carrying Google Slides's real ids.
{
"manifestVersion": "2",
"name": "google-slides-example",
"steps": [
{
"id": "element-alt-text-update",
"uses": {
"app": "io.w6w.google-slides",
"action": "element-alt-text-update",
"connection": "conn_YOUR_CONNECTION_ID"
},
"with": {
"presentationId": "<presentationId>",
"objectId": "<objectId>"
}
}
]
}element-alt-text-update image-create object-duplicate page-get page-get-thumbnail +12 more actions available
Every app-specific value here is a blank you have to fill in. An
app action is reached through the connection that authenticates it, so the
address is a connection id, not the app id — and connections belong to your account,
so a public page cannot know yours. Create one for Google Slides, then fill in
the three blanks: conn_YOUR_CONNECTION_ID, the action key, and the
parameters that action declares. The call itself is real — the shape is transcribed
from the studio's own snippet builder, which prints the same kind of blanks — but
nothing in it is specific to Google Slides. The Workflow tab is where this app's
real ids are.
npm install @w6w/sdkyarn add @w6w/sdkpnpm add @w6w/sdkdeno add npm:@w6w/sdkimport { W6wClient, isActionRun } from "@w6w/sdk";
// Reads W6W_BASE_URL and W6W_TOKEN from the environment when omitted.
const client = new W6wClient();
const envelope = await client.run({
urn: "conn_YOUR_CONNECTION_ID",
action: "presentation-create",
payload: {
title: "<value>",
// presentationId: "<value>",
},
});
if (isActionRun(envelope)) console.log(envelope.value); npm install -g @w6w/cli w6w run conn_YOUR_CONNECTION_ID --action presentation-create --payload '{"title":"<value>"}' Give an AI agent Google Slides — without giving it Google Slides's credentials. One MCP endpoint exposes every app, function and workflow the caller is entitled to, as tools it can discover and run. Access is granted per team while we onboard.
One tool call{
"name": "w6w_invoke",
"arguments": {
"ref": "app:io.w6w.google-slides#element-alt-text-update",
"input": {
"presentationId": "<presentationId>",
"objectId": "<objectId>"
}
}
}
Every tool names its target with a single ref. The
app: form above doesn't name a connection at all — the
host resolves which of the caller's Google Slides connections to sign
with, and refuses rather than guesses when the answer is ambiguous.
The token is attached host-side, at the moment of the call. It is never a tool argument, never in the model's context, and never in a transcript — so a prompt injection has nothing to exfiltrate.
Tools are derived per end user from what that person has actually connected and is entitled to — not one shared bot identity carrying the union of everyone's access.
Multi-step work runs on the workflow engine and returns a run handle the agent can poll — retries, branching and state survive the conversation that started them.
Google Slides's declared health checks are on the surface too, so an agent can tell "the vendor is down" from "your credential expired" before it burns a retry on either.
The MCP surface is part of the hosted platform. Google Slides itself is MIT, and the runtime that executes it is source-available (FSL).
Google Slides declares its own checks, so its health is a property of the app rather than something the host guesses at.
Open incidents for Google Slides on the Google Workspace Status Dashboard. Unauthenticated and unsigned.