The Gmail connector uses a Google-managed OAuth app to access your Gmail data. You don't need to enable Gmail APIs, create your own OAuth app, add OAuth scopes, or create OAuth client credentials.
Depending on how your organization restricts OAuth app access, a Google Workspace administrator might need to add the Google-managed OAuth app to your organization's OAuth app allowlist before users can authorize the connector. For instructions, see Allowlist the Google-managed OAuth app.
Allowlist the Google-managed OAuth app
If your Google Workspace organization restricts OAuth app access, a Google Workspace administrator must add the Google-managed OAuth app to your organization's OAuth app allowlist before users can authorize the Gmail connector.
To add the OAuth app to the allowlist, follow these steps:
Sign in to the Google Admin console as a Google Workspace administrator.
Go to Security > Access and data control > API controls.
Under App access control, click Manage third-party app access.
Click Configure new app > OAuth App Name Or Client ID.
In the search field, enter the following Gemini Enterprise OAuth client ID:
502998392228-hpelhql0ouj9ckiu3l39lllsir24b02s.apps.googleusercontent.comSelect the app from the search results and click Select.
Choose an access level for the app: Trusted, Limited, or Blocked. To let users authorize the Gmail connector, select Trusted or Limited: Allow users to access any Google service.
Click Continue and then Finish to save the change.
For more information about OAuth app allowlisting, see Control which third-party & internal apps access Google Workspace data in the Google Workspace Admin Help.