Nvidia NIM Nemotron Google Sheets Orchestrator
AI-driven chatbot orchestrator using Nvidia NIM Nemotron-3 (120B) to read and write Google Sheets via MCP and serverless Lambda.
README
Nvidia NIM Nemotron Google Sheets Orchestrator: MCP & Serverless Lambda
This repository contains a production-ready, AI-driven chatbot orchestrator that can read and write data to a Google Sheet using the Nvidia NIM Nemotron-3 (120B) model. It supports two distinct architectural implementations:
- Local Multi-Container MCP Stack: Client-server separation using FastMCP and Server-Sent Events (SSE) private networks.
- Serverless AWS Lambda Container: Consolidated, event-driven Lambda function behind API Gateway, using AWS Secrets Manager for OAuth token storage.
š Key Features
- Brain (LLM): Integrates the state-of-the-art
nvidia/nemotron-3-super-120b-a12bmodel via Nvidia NIM. - Decoupled MCP Architecture: FastMCP Google Sheets server communicating with a FastAPI agent client over Server-Sent Events (SSE).
- Serverless Refactoring: Collapse the SSE network architecture into a single-process containerized AWS Lambda handler with in-process tool calling.
- Security (Zero Secret Hardcoding): Google OAuth Client ID, Secret, and Refresh Token are fetched dynamically in-memory from AWS Secrets Manager at runtime (no token files baked into the image).
- Telegram Webhook Reply: Optimized Lambda response payload supporting the Telegram Webhook Reply protocol (
method: "sendMessage") for instant response routing. - Resilient OAuth Consent Helper: Native local helper script (
refresh_oauth.py) to trigger browser consent flows on the host machine and instantly sync refreshed tokens to AWS Secrets Manager.
š Architectures
1. Local Multi-Container (MCP)
[User] āā(Webhook)āā> [FastAPI Client] āā(SSE Network Bridge)āā> [FastMCP Server] āā> [Google Sheets API]
ā
(Nvidia NIM API)
ā¼
[Nemotron-3 LLM]
2. Serverless AWS Lambda (Production)
[User] āā(Telegram POST)āā> [API Gateway /webhook]
ā
ā¼
[AWS Lambda Function] (Container Image)
ā ā
(In-Process Call) (boto3) āā> [Secrets Manager]
ā¼
[app/tools.py]
ā
ā¼
[Google Sheets API]
š ļø Folder Structure
āāā app/ # Consolidated serverless Lambda source code
ā āāā __init__.py
ā āāā secrets.py # Credentials resolver (LOCAL_DEV env vs Production Secrets Manager)
ā āāā tools.py # Google Sheets API read/write tools (LangChain decorated)
ā āāā agent.py # LangGraph ReAct agent binding tools to ChatNVIDIA
ā āāā main.py # Lambda entrypoint handler & local CLI REPL
āāā client/ # Original local FastAPI Agent Client (MCP mode)
āāā server/ # Original local FastMCP Google Sheets Server (MCP mode)
āāā Dockerfile # Packages the app/ module for AWS Lambda
āāā template.yaml # AWS SAM Template declaration
āāā requirements.txt # Consolidated dependencies for AWS Lambda
āāā refresh_oauth.py # Local OAuth browser consent helper & Secrets Manager syncer
āāā .env # Local environment file (ignored by Git)
š¦ Running Locally
Step 1: Initialize OAuth Credentials
- Go to the Google Cloud Console.
- Enable the Google Sheets API.
- Setup the OAuth Consent Screen (User Type: External, Status: Testing, add your email as a Test User).
- Create an OAuth Client ID of type Desktop app.
- Download the secret JSON, rename it to
credentials.json, and place it in./server/credentials.json.
Step 2: Perform Initial Consent & Run Local Stack
- Run the local consent flow:
A browser window will open. Click 'Allow' to grant access. This generates the initialcd server pip install -r requirements.txt python sheets_mcp.pytoken.jsonfile. - Copy
.env.exampleto.envin the root and fill in your keys:NVIDIA_API_KEY: Your Nvidia API key.SPREADSHEET_ID: Your default target spreadsheet ID.TELEGRAM_BOT_TOKEN: Your Telegram Bot API token.
- Start the local multi-container stack:
docker-compose up --build -d
āļø Deploying to AWS Lambda (Serverless)
AWS Lambda container images require the Docker V2 Schema 2 format. Standard OCI manifests (with buildx attestations/SBOMs) will be rejected by AWS with an InvalidParameterValueException.
To compile, build ECR registries, build the container image securely, push, create IAM roles, upload credentials, and deploy your API Gateway triggers, a complete deployment helper is provided in the project history. You can perform these steps manually or use standard SAM CLI:
Manual SAM Build & Deploy
- Save Google Credentials to Secrets Manager:
Create a secret in AWS Secrets Manager named
sheets-orchestrator-google-oauthcontaining:{ "client_id": "YOUR_CLIENT_ID", "client_secret": "YOUR_CLIENT_SECRET", "refresh_token": "YOUR_REFRESH_TOKEN" } - Build and Deploy:
Provide your stack name, AWS Region,sam build sam deploy --guidedNvidiaApiKey, and the secret ARN. Once deployment is complete, SAM will output the public regional Webhook URL:https://<api-id>.execute-api.<region>.amazonaws.com/Prod/webhook
š Refreshing OAuth Credentials (The 7-Day Limit)
If your Google Cloud Console project is in Testing publishing status, your Google refresh token will expire after 7 days.
To resolve token expiry errors without having to redeploy your code:
- Run the local OAuth syncer from your project root:
python refresh_oauth.py - Sign in via your web browser.
- The script will automatically fetch the new refresh token, write it to your local
.env, connect to AWS, and update the secret in AWS Secrets Manager. - The Lambda function will pick up the new credentials on its next execution.
Recommended Servers
playwright-mcp
A Model Context Protocol server that enables LLMs to interact with web pages through structured accessibility snapshots without requiring vision models or screenshots.
Magic Component Platform (MCP)
An AI-powered tool that generates modern UI components from natural language descriptions, integrating with popular IDEs to streamline UI development workflow.
Audiense Insights MCP Server
Enables interaction with Audiense Insights accounts via the Model Context Protocol, facilitating the extraction and analysis of marketing insights and audience data including demographics, behavior, and influencer engagement.
VeyraX MCP
Single MCP tool to connect all your favorite tools: Gmail, Calendar and 40 more.
graphlit-mcp-server
The Model Context Protocol (MCP) Server enables integration between MCP clients and the Graphlit service. Ingest anything from Slack to Gmail to podcast feeds, in addition to web crawling, into a Graphlit project - and then retrieve relevant contents from the MCP client.
Kagi MCP Server
An MCP server that integrates Kagi search capabilities with Claude AI, enabling Claude to perform real-time web searches when answering questions that require up-to-date information.
E2B
Using MCP to run code via e2b.
Neon Database
MCP server for interacting with Neon Management API and databases
Exa Search
A Model Context Protocol (MCP) server lets AI assistants like Claude use the Exa AI Search API for web searches. This setup allows AI models to get real-time web information in a safe and controlled way.
Qdrant Server
This repository is an example of how to create a MCP server for Qdrant, a vector search engine.