Gmail
Search and read a mailbox, label mail and prepare drafts, through Google's own hosted Gmail MCP server.
This is an Express tool. Zero Human has already set up the sign-in app, the server address and the permissions, so you connect it by pressing Connect and signing in with your own account. What Express is.
What a member can do
With Gmail connected, a member can work in the mailbox of the Google account it was connected with: search threads, read a thread and its messages, list labels, add and remove labels, and write and list drafts.
It cannot send. Google's Gmail server has no tool that sends mail, so a reply a member writes is left as a draft in that mailbox for a person to read and send.
Each task names the Gmail tools it may call. gmail on a task means every tool Google's server offers; a name such
as gmail.search_threads means that tool alone. A tool the task does not name is refused, whatever the connection
allows. If Google's server does not answer when a run starts, the run carries on rather than failing, and its log
records tool.not_offered.
Who connects it
A Gmail connection acts as the Google account that signed in when it was connected. It reaches that account's mailbox and no other, and Google records what it does against that account.
Anyone who may change tools in your enterprise can connect Gmail for a member or a team. Connecting it for the whole enterprise is for the owner, and the people the owner allows.
A connection can sit on the enterprise, a team, a member, a role or a task, and the one further down replaces the one above: task, then role, then member, then team, then enterprise. A mailbox is usually one person's, so connect Gmail on the member that should work in it. Connected for the whole enterprise, every member can read that one mailbox.
A connection on anything but a task also reaches the chat of every member it covers.
What waits for you
A draft waits for you in Gmail itself: nothing a member writes there is sent until a person sends it.
In a run, nothing else on Gmail waits for you unless the task declares a gate on it. To approve each change before
it happens, gate the tools that change something, such as gmail.create_draft, on the task. See
Gates and tool scopes.
In a chat, a Gmail tool that Google does not mark as read-only asks you before it runs, unless you chose Always allow for that member and tool.
Setup
Connect it
Gmail is an Express tool, so there is no server address, key or Google Cloud project to set up. Work in one browser window throughout: Google returns to the portal in the window you started from.
- In the portal, open the member's page → Tools. To connect it for a team or the whole enterprise, open Tools in the sidebar.
- Under Express, find Gmail and choose Connect. On the Tools page you are asked who uses it: one member, a team or the whole enterprise.
- Google's sign-in opens. Choose the Google account whose mailbox the member should work in, and approve.
- You are back on Tools, and Gmail shows as connected.
- Name the tools on the task,
gmailfor all of them or each by name. - Check it. Run a task that searches the mailbox. The run page shows the call and what Google returned.
What Google asks you to approve
Google's sign-in screen lists two permissions: reading your mail, and managing drafts and sending mail. Google words the second one that way for every app that writes drafts. The Gmail server still has no tool that sends, so a member can write a draft and cannot send it.
You can take the access back at any time, from Tools in the portal (delete the connection) or from your Google account's list of connected apps.
Connecting it by hand instead
Gmail can also be connected like any other MCP server, with Add tool, if you would rather use a sign-in app you registered with Google yourself. That needs your own Google Cloud project with access to Google's Gmail MCP server. Express exists so that you do not need one.
For background access, set these values under Extra sign-in parameters before connecting or reconnecting:
access_type=offline
prompt=consent
They ask Google for access that renews itself, and for a fresh consent screen. The settings are saved with the connection for future reconnects. A connection made by hand without them stops working after about an hour and needs a new Google consent once they are in place. See Google's offline access documentation.
The Express connection needs none of this: its sign-in settings are already in place.
Troubleshooting
| What you see | Why | What to do |
|---|---|---|
| "OAuth did not complete" | You closed Google's sign-in, declined a permission, or approved in a different browser window from the one you started in | Choose Connect again, and do the whole connection in one window |
| Google says your organisation has blocked the app | Your Google Workspace admin limits which apps may reach its accounts | Ask the admin to allow Zero Human OS, then choose Connect again |
| "Only the owner of this enterprise…" | You chose the whole enterprise, and connecting a tool for everyone is the owner's | Connect it for a member or a team, or ask the owner |
| The member reads the wrong mailbox | Google was signed in as a different account when you approved | Choose Reconnect, and pick the right account on Google's screen |
The run's log says tool.not_offered for a Gmail tool |
Google's server did not answer when the run started, or the connection no longer works | Run it again; if it repeats, choose Reconnect |
tool_not_bound:gmail |
No Gmail connection reaches this run | Connect it at a layer the run reaches: its task, its member or the member's roles, its team, or the enterprise |
| Calls fail with an auth error after working | The access was removed in the Google account, or the account's password or security settings changed | Choose Reconnect and sign in again |