[{"data":1,"prerenderedAt":40},["ShallowReactive",2],{"$f1cfm9dbrjyyt2":3},{"href":4,"title":5,"description":6,"kind":7,"mark":8,"planned":9,"contributors":10,"provenance":8,"express":11,"html":12,"headings":13},"\u002Fdocs\u002Ftools\u002Fgmail","Gmail","Search and read a mailbox, label mail and prepare drafts, through Google's own hosted Gmail MCP server.","integrates",null,false,[],true,"\u003Ch2 id=\"what-a-member-can-do\">What a member can do\u003C\u002Fh2>\n\u003Cp>With Gmail connected, a member can work in the mailbox of the Google account it was connected with: search threads,\nread a thread and its messages, list labels, add and remove labels, and write and list drafts.\u003C\u002Fp>\n\u003Cp>It cannot send. Google's Gmail server has no tool that sends mail, so a reply a member writes is left as a draft in\nthat mailbox for a person to read and send.\u003C\u002Fp>\n\u003Cp>Each task names the Gmail tools it may call. \u003Ccode>gmail\u003C\u002Fcode> on a task means every tool Google's server offers; a name such\nas \u003Ccode>gmail.search_threads\u003C\u002Fcode> means that tool alone. A tool the task does not name is refused, whatever the connection\nallows. If Google's server does not answer when a run starts, the run carries on rather than failing, and its log\nrecords \u003Ccode>tool.not_offered\u003C\u002Fcode>.\u003C\u002Fp>\n\u003Ch2 id=\"who-connects-it\">Who connects it\u003C\u002Fh2>\n\u003Cp>A Gmail connection acts as \u003Cstrong>the Google account that signed in\u003C\u002Fstrong> when it was connected. It reaches that account's\nmailbox and no other, and Google records what it does against that account.\u003C\u002Fp>\n\u003Cp>Anyone who may change tools in your enterprise can connect Gmail for a member or a team. Connecting it for the whole\nenterprise is for the owner, and the people the owner allows.\u003C\u002Fp>\n\u003Cp>A connection can sit on the enterprise, a team, a member, a role or a task, and the one further down replaces the\none above: task, then role, then member, then team, then enterprise. A mailbox is usually one person's, so connect\nGmail on the member that should work in it. Connected for the whole enterprise, every member can read that one\nmailbox.\u003C\u002Fp>\n\u003Cp>A connection on anything but a task also reaches the \u003Ca href=\"\u002Fdocs\u002Fwork\u002Fchat\">chat\u003C\u002Fa> of every member it covers.\u003C\u002Fp>\n\u003Ch2 id=\"what-waits-for-you\">What waits for you\u003C\u002Fh2>\n\u003Cp>A draft waits for you in Gmail itself: nothing a member writes there is sent until a person sends it.\u003C\u002Fp>\n\u003Cp>In a run, nothing else on Gmail waits for you unless the task declares a gate on it. To approve each change before\nit happens, gate the tools that change something, such as \u003Ccode>gmail.create_draft\u003C\u002Fcode>, on the task. See\n\u003Ca href=\"\u002Fdocs\u002Fcontrol\u002Fgates\">Gates and tool scopes\u003C\u002Fa>.\u003C\u002Fp>\n\u003Cp>In a chat, a Gmail tool that Google does not mark as read-only asks you before it runs, unless you chose\n\u003Cstrong>Always allow\u003C\u002Fstrong> for that member and tool.\u003C\u002Fp>\n\u003Ch2 id=\"setup\">Setup\u003C\u002Fh2>\n\u003Ch3 id=\"connect-it\">Connect it\u003C\u002Fh3>\n\u003Cp>Gmail is an Express tool, so there is no server address, key or Google Cloud project to set up. Work in one browser\nwindow throughout: Google returns to the portal in the window you started from.\u003C\u002Fp>\n\u003Col>\n\u003Cli>In the portal, open the member's page → \u003Cstrong>Tools\u003C\u002Fstrong>. To connect it for a team or the whole enterprise, open\n\u003Cstrong>Tools\u003C\u002Fstrong> in the sidebar.\u003C\u002Fli>\n\u003Cli>Under \u003Cstrong>Express\u003C\u002Fstrong>, find \u003Cstrong>Gmail\u003C\u002Fstrong> and choose \u003Cstrong>Connect\u003C\u002Fstrong>. On the Tools page you are asked who uses it: one\nmember, a team or the whole enterprise.\u003C\u002Fli>\n\u003Cli>Google's sign-in opens. Choose the Google account whose mailbox the member should work in, and approve.\u003C\u002Fli>\n\u003Cli>You are back on \u003Cstrong>Tools\u003C\u002Fstrong>, and Gmail shows as connected.\u003C\u002Fli>\n\u003Cli>Name the tools on the task, \u003Ccode>gmail\u003C\u002Fcode> for all of them or each by name.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Check it.\u003C\u002Fstrong> Run a task that searches the mailbox. The run page shows the call and what Google returned.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch3 id=\"what-google-asks-you-to-approve\">What Google asks you to approve\u003C\u002Fh3>\n\u003Cp>Google's sign-in screen lists two permissions: reading your mail, and managing drafts and sending mail. Google\nwords the second one that way for every app that writes drafts. The Gmail server still has no tool that sends, so a\nmember can write a draft and cannot send it.\u003C\u002Fp>\n\u003Cp>You can take the access back at any time, from \u003Cstrong>Tools\u003C\u002Fstrong> in the portal (delete the connection) or from your Google\naccount's list of connected apps.\u003C\u002Fp>\n\u003Ch3 id=\"connecting-it-by-hand-instead\">Connecting it by hand instead\u003C\u002Fh3>\n\u003Cp>Gmail can also be connected like any other MCP server, with \u003Cstrong>Add tool\u003C\u002Fstrong>, if you would rather use a sign-in app you\nregistered with Google yourself. That needs your own Google Cloud project with access to Google's Gmail MCP server.\nExpress exists so that you do not need one.\u003C\u002Fp>\n\u003Cp>For background access, set these values under \u003Cstrong>Extra sign-in parameters\u003C\u002Fstrong> before connecting or reconnecting:\u003C\u002Fp>\n\u003Cpre>\u003Ccode class=\"language-text\">access_type=offline\nprompt=consent\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>They ask Google for access that renews itself, and for a fresh consent screen. The settings are saved with the\nconnection for future reconnects. A connection made by hand without them stops working after about an hour and\nneeds a new Google consent once they are in place. See\n\u003Ca href=\"https:\u002F\u002Fdevelopers.google.com\u002Fidentity\u002Fprotocols\u002Foauth2\u002Fweb-server#offline\">Google's offline access documentation\u003C\u002Fa>.\u003C\u002Fp>\n\u003Cp>The Express connection needs none of this: its sign-in settings are already in place.\u003C\u002Fp>\n\u003Ch2 id=\"troubleshooting\">Troubleshooting\u003C\u002Fh2>\n\u003Cdiv class=\"prose__table\">\n\u003Ctable>\n\u003Cthead>\n\u003Ctr>\n\u003Cth>What you see\u003C\u002Fth>\n\u003Cth>Why\u003C\u002Fth>\n\u003Cth>What to do\u003C\u002Fth>\n\u003C\u002Ftr>\n\u003C\u002Fthead>\n\u003Ctbody>\n\u003Ctr>\n\u003Ctd>&quot;OAuth did not complete&quot;\u003C\u002Ftd>\n\u003Ctd>You closed Google's sign-in, declined a permission, or approved in a different browser window from the one you started in\u003C\u002Ftd>\n\u003Ctd>Choose \u003Cstrong>Connect\u003C\u002Fstrong> again, and do the whole connection in one window\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>Google says your organisation has blocked the app\u003C\u002Ftd>\n\u003Ctd>Your Google Workspace admin limits which apps may reach its accounts\u003C\u002Ftd>\n\u003Ctd>Ask the admin to allow Zero Human OS, then choose \u003Cstrong>Connect\u003C\u002Fstrong> again\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>&quot;Only the owner of this enterprise…&quot;\u003C\u002Ftd>\n\u003Ctd>You chose the whole enterprise, and connecting a tool for everyone is the owner's\u003C\u002Ftd>\n\u003Ctd>Connect it for a member or a team, or ask the owner\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>The member reads the wrong mailbox\u003C\u002Ftd>\n\u003Ctd>Google was signed in as a different account when you approved\u003C\u002Ftd>\n\u003Ctd>Choose \u003Cstrong>Reconnect\u003C\u002Fstrong>, and pick the right account on Google's screen\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>The run's log says \u003Ccode>tool.not_offered\u003C\u002Fcode> for a Gmail tool\u003C\u002Ftd>\n\u003Ctd>Google's server did not answer when the run started, or the connection no longer works\u003C\u002Ftd>\n\u003Ctd>Run it again; if it repeats, choose \u003Cstrong>Reconnect\u003C\u002Fstrong>\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>\u003Ccode>tool_not_bound:gmail\u003C\u002Fcode>\u003C\u002Ftd>\n\u003Ctd>No Gmail connection reaches this run\u003C\u002Ftd>\n\u003Ctd>Connect it at a layer the run reaches: its task, its member or the member's roles, its team, or the enterprise\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>Calls fail with an auth error after working\u003C\u002Ftd>\n\u003Ctd>The access was removed in the Google account, or the account's password or security settings changed\u003C\u002Ftd>\n\u003Ctd>Choose \u003Cstrong>Reconnect\u003C\u002Fstrong> and sign in again\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003C\u002Ftbody>\n\u003C\u002Ftable>\n\u003C\u002Fdiv>\n",[14,18,21,24,27,31,34,37],{"id":15,"text":16,"level":17,"planned":9},"what-a-member-can-do","What a member can do",2,{"id":19,"text":20,"level":17,"planned":9},"who-connects-it","Who connects it",{"id":22,"text":23,"level":17,"planned":9},"what-waits-for-you","What waits for you",{"id":25,"text":26,"level":17,"planned":9},"setup","Setup",{"id":28,"text":29,"level":30,"planned":9},"connect-it","Connect it",3,{"id":32,"text":33,"level":30,"planned":9},"what-google-asks-you-to-approve","What Google asks you to approve",{"id":35,"text":36,"level":30,"planned":9},"connecting-it-by-hand-instead","Connecting it by hand instead",{"id":38,"text":39,"level":17,"planned":9},"troubleshooting","Troubleshooting",1791596247918]