Gmail for AI agents
Gmail is Google's email service with search, spam filtering, and labels, tightly integrated with the rest of Google Workspace. Teams use it to keep this process accurate at a scale manual review cannot match. Connect it once through Arc0, and your agent, or Claude, ChatGPT and Cursor, can use it through one MCP endpoint, limited to what each user approved.
What agents do in Gmail.
Draft a reply for review
Create a draft reply to an email thread so the user can review and send it themselves.
Search for a specific email
Search the inbox for a message from a sender or subject line to answer a question.
Block a permanent label delete
Refuse to permanently delete an account label without explicit confirmation, since that action cannot be undone.
62 Gmail actions, graded by risk.
Every Gmail action is tagged read, write or destructive, so one policy covers the whole app and new actions inherit the right default.
read
25Look things up. Allowed by default.
- gmail.get_draftGet Draft
- gmail.get_labelGet label details
- gmail.get_filterGet Gmail filter
- gmail.get_peopleGet People
- gmail.get_profileGet Profile
- gmail.list_draftsList Drafts
- gmail.list_labelsList Gmail labels
- gmail.get_contactsGet contacts
- gmail.list_filtersList Gmail filters
- gmail.list_historyList Gmail history
- gmail.list_send_asList send-as aliases
- gmail.list_threadsList threads
- gmail.list_messagesList Gmail messages (Deprecated)
- gmail.search_peopleSearch People
- gmail.get_attachmentGet Gmail attachment
- gmail.list_smime_infoList S/MIME configs
write
28Create and change things. Allow, or ask the user first.
- gmail.send_draftSend Draft
- gmail.send_emailSend Email
- gmail.create_labelCreate label
- gmail.update_draftUpdate draft
- gmail.update_labelUpdate Label
- gmail.create_filterCreate Gmail filter
- gmail.update_send_asUpdate send-as alias
- gmail.add_label_to_emailModify email labels
- gmail.create_email_draftCreate email draft
- gmail.update_pop_settingsUpdate POP settings
- gmail.update_imap_settingsUpdate IMAP settings
- gmail.update_language_settingsUpdate Language Settings
- gmail.update_vacation_settingsUpdate Vacation Settings
- gmail.who_am_iWho Am I
- gmail.stop_watchStop watch notifications
- gmail.patch_labelPatch Label
destructive
9Delete, cancel or archive. Ask first, or deny outright.
- gmail.delete_draftDelete Draft
- gmail.delete_labelDelete label from account (permanent)
- gmail.remove_labelRemove label (Deprecated)
- gmail.delete_filterDelete Gmail filter
- gmail.delete_threadDelete thread
- gmail.delete_messageDelete message
- gmail.move_to_trashMove to Trash
- gmail.move_thread_to_trashTrash thread
- gmail.batch_delete_messagesBatch delete Gmail messages
Gmail in three steps.
- 01Your users connect GmailThey sign in to Gmail on Arc0 Connect, under your brand, and approve the access you ask for.
- 02You set the rulesReads run, writes like “create label” can wait for the user, and “delete Draft” can be denied outright.
- 03Any agent can actYour agent calls Gmail through the Arc0 SDK or MCP, and so can Claude, ChatGPT and Cursor. Every call lands on the audit log.
await arc0.policies.set('gmail', { read: 'allow', write: 'ask', // create_label destructive: 'deny', // delete_draft }) # Claude Code: the same connection, one URL $ claude mcp add --transport http arc0 \ https://mcp.arc0.ai/u/u_8f2
How Gmail connects.
Users sign in to Gmail on Arc0 Connect and approve the scopes you request. Build with Arc0’s Gmail OAuth app, or bring your own so the Gmail consent screen names you. Tokens refresh automatically, and you can export them whenever you want.
The same Gmail connection serves your agent over MCP and your own backend over REST and the proxy, so a user connects once. How Arc0 handles credentials →
- AUTH
- OAuth 2.0
- CREDENTIALS
- Per-tenant encrypted vault
- MODEL SEES
- Results only, never credentials
- AUDIT LOG
- Every call, on every plan
Use Gmail from any agent.
Gmail and Arc0, answered.
Can I use Gmail with Claude, ChatGPT or Cursor?
Yes. Connect Gmail to Arc0 once, then add your Arc0 MCP URL to Claude, ChatGPT, Cursor, Claude Code or any other remote-MCP client. Each assistant only gets the Gmail actions you allow.
How do users connect Gmail?
Users sign in to Gmail on Arc0 Connect and approve the scopes you request. Build with Arc0’s Gmail OAuth app, or bring your own so the Gmail consent screen names you. Tokens refresh automatically, and you can export them whenever you want.
Which Gmail actions can my agent take?
62 in total: 25 read, 28 write and 9 destructive, such as “create label”. Your policies decide which of them each agent may call.
Can I stop my agent from deleting things in Gmail?
Yes. Actions like “delete Draft” are graded destructive. Set destructive actions to deny, or to ask so the user approves each one, and blocked calls still show up on the audit log.
Can my own backend call Gmail too?
Yes. The same Gmail connection is available over REST and through the Arc0 proxy, so your product and your agent share one connection per user.
Plug Gmail into your agent.
Your users connect Gmail once, under your brand. Your agent gets 62 actions behind your policies, with every call on the record.
Free to build · MCP + REST · Audit log on every plan