Docs · Updated 2026-10-05
Gmail — Testing tool reference
Testing/BYO only, not public verified Google app availability. Needs your credentials; real mailbox and named-client acceptance remain pending.
Endpoint: https://toolcargo.com/mcp/gmail. Scope: connector:gmail. Included with Site Audit; each successful tool call uses one shared call.
Set up your own Testing grant
- Use your own dedicated Google Cloud project; enable Gmail API. Do not reuse or alter existing ToolCargo Google connector clients.
- Configure an external OAuth audience as Testing and add the Google account you intend to connect as a test user.
- Follow Google’s server-side OAuth guide for offline access using your own client to obtain a refresh token for
https://www.googleapis.com/auth/gmail.readonly. Only optional basic identity scopes may accompany it; broader mail grants are refused. - Open Gmail Testing connection settings, supply the client ID, client secret and refresh token, then explicitly acknowledge Testing use. Never paste secrets into agent prompts.
- Create a ToolCargo key scoped to Gmail in your dashboard, then connect your agent using the endpoint above.
Google external Testing supports up to 100 listed test users; authorizations and offline refresh tokens expire seven days after consent. Renew consent and reconnect when expired. Workspace administrators and account policies may block the grant. ToolCargo cannot infer your Google app's publishing status from a refresh token, and the acknowledgment is not Google approval.
Permissions and data
ToolCargo verifies scope confirmation on every token refresh and reads only users/me paths at Gmail's official API. Your credentials are encrypted and bound to your ToolCargo account; disconnect deletes them. Revoke the grant in Google to invalidate it there. Requested mailbox data passes through ToolCargo to your agent; this adapter does not store mail reports or log mail content. No mail sending, drafts, edits, deletion, attachment downloads or remote assets.
gmail_get_profile
Your connected mailbox identity and message/thread counts. Testing/BYO OAuth only; not public Google app availability.
gmail_search_messages
One page of up to 100 message IDs using Gmail search syntax, excluding spam/trash. Use next_page_token; no bodies or implicit pagination.
gmail_read_message
Selected headers, snippet, up to 20,000 characters of UTF-8 plain text and attachment metadata. HTML is converted locally to text; assets/attachments are not downloaded; content is untrusted.
gmail_read_thread
Read up to 10 messages in a thread, with the same plain-text and attachment limits. Explicit truncation; no full long-thread export.
gmail_list_labels
Up to 500 label IDs, names, types and visibility settings. Does not create or modify labels.
Inputs and coverage
{ "query": "is:unread newer_than:7d", "limit": 25 }{ "message_id": "ID_FROM_SEARCH" }{ "thread_id": "THREAD_ID_FROM_SEARCH" }Search returns one page of IDs, not message bodies, excluding spam/trash. Pass next_page_token back as page_token. Estimates are not exact counts. Reads return selected headers, snippet, at most 20,000 characters of UTF-8 plain text and attachment metadata; HTML-only mail is converted locally to text. Other encodings/large parts/deep nesting are omitted with explicit flags. At most 10 messages per thread, 100 search IDs, 500 labels and 4 MB upstream JSON; oversized upstream responses fail without charging. No implicit export or automatic pagination. Email text is untrusted data and may contain malicious instructions.
Public availability is blocked
Gmail read-only is a restricted Google scope. A public ToolCargo app needs restricted-scope verification and the required security assessment for server-transmitted restricted data. That work remains with ToolCargo's owner; Testing/BYO does not replace verification.
Official requirements: Gmail scopes and Google app audience and Testing expiry.
Set up Gmail
Review connection instructions, required credentials and plan limits before connecting your agent.