Gmail for AI agents

Gmail is Google's email service with search, spam filtering, and labels, tightly integrated with the rest of Google Workspace. Teams use it to keep this process accurate at a scale manual review cannot match. Connect it once through Arc0, and your agent, or Claude, ChatGPT and Cursor, can use it through one MCP endpoint, limited to what each user approved.

EmailOAuth 2.0MCP + RESTgmail.com
AUDIT LOG · GMAILPOLICY: acme-support
09:41:07 · claude · u_8f2read
gmail.list_drafts
List Drafts✓ allowed · 212ms
09:41:08 · claude · u_8f2read
gmail.get_draft
Get Draft✓ allowed · 164ms
09:41:09 · claude · u_8f2write
gmail.create_label
Create label✓ approved · approved by user
09:41:12 · claude · u_8f2destructive
gmail.delete_draft
Delete Draft✕ blocked · policy: deny
EVERY GMAIL CALL, ON THE RECORD
01 · USE CASES

What agents do in Gmail.

01

Draft a reply for review

Create a draft reply to an email thread so the user can review and send it themselves.

02

Search for a specific email

Search the inbox for a message from a sender or subject line to answer a question.

03

Block a permanent label delete

Refuse to permanently delete an account label without explicit confirmation, since that action cannot be undone.

02 · ACTIONS

62 Gmail actions, graded by risk.

Every Gmail action is tagged read, write or destructive, so one policy covers the whole app and new actions inherit the right default.

read

25

Look things up. Allowed by default.

  • gmail.get_draft
    Get Draft
  • gmail.get_label
    Get label details
  • gmail.get_filter
    Get Gmail filter
  • gmail.get_people
    Get People
  • gmail.get_profile
    Get Profile
  • gmail.list_drafts
    List Drafts
  • gmail.list_labels
    List Gmail labels
  • gmail.get_contacts
    Get contacts
  • gmail.list_filters
    List Gmail filters
  • gmail.list_history
    List Gmail history
  • gmail.list_send_as
    List send-as aliases
  • gmail.list_threads
    List threads
  • gmail.list_messages
    List Gmail messages (Deprecated)
  • gmail.search_people
    Search People
  • gmail.get_attachment
    Get Gmail attachment
  • gmail.list_smime_info
    List S/MIME configs
+ 9 MORE

write

28

Create and change things. Allow, or ask the user first.

  • gmail.send_draft
    Send Draft
  • gmail.send_email
    Send Email
  • gmail.create_label
    Create label
  • gmail.update_draft
    Update draft
  • gmail.update_label
    Update Label
  • gmail.create_filter
    Create Gmail filter
  • gmail.update_send_as
    Update send-as alias
  • gmail.add_label_to_email
    Modify email labels
  • gmail.create_email_draft
    Create email draft
  • gmail.update_pop_settings
    Update POP settings
  • gmail.update_imap_settings
    Update IMAP settings
  • gmail.update_language_settings
    Update Language Settings
  • gmail.update_vacation_settings
    Update Vacation Settings
  • gmail.who_am_i
    Who Am I
  • gmail.stop_watch
    Stop watch notifications
  • gmail.patch_label
    Patch Label
+ 12 MORE

destructive

9

Delete, cancel or archive. Ask first, or deny outright.

  • gmail.delete_draft
    Delete Draft
  • gmail.delete_label
    Delete label from account (permanent)
  • gmail.remove_label
    Remove label (Deprecated)
  • gmail.delete_filter
    Delete Gmail filter
  • gmail.delete_thread
    Delete thread
  • gmail.delete_message
    Delete message
  • gmail.move_to_trash
    Move to Trash
  • gmail.move_thread_to_trash
    Trash thread
  • gmail.batch_delete_messages
    Batch delete Gmail messages
03 · HOW IT WORKS

Gmail in three steps.

  1. 01Your users connect GmailThey sign in to Gmail on Arc0 Connect, under your brand, and approve the access you ask for.
  2. 02You set the rulesReads run, writes like “create label” can wait for the user, and “delete Draft” can be denied outright.
  3. 03Any agent can actYour agent calls Gmail through the Arc0 SDK or MCP, and so can Claude, ChatGPT and Cursor. Every call lands on the audit log.
POLICY.TS
await arc0.policies.set('gmail', {
  read: 'allow',
  write: 'ask',        // create_label
  destructive: 'deny',  // delete_draft
})

# Claude Code: the same connection, one URL
$ claude mcp add --transport http arc0 \
    https://mcp.arc0.ai/u/u_8f2
04 · AUTH AND DATA

How Gmail connects.

Users sign in to Gmail on Arc0 Connect and approve the scopes you request. Build with Arc0’s Gmail OAuth app, or bring your own so the Gmail consent screen names you. Tokens refresh automatically, and you can export them whenever you want.

The same Gmail connection serves your agent over MCP and your own backend over REST and the proxy, so a user connects once. How Arc0 handles credentials →

AUTH
OAuth 2.0
CREDENTIALS
Per-tenant encrypted vault
MODEL SEES
Results only, never credentials
AUDIT LOG
Every call, on every plan
05 · WORKS WITH

Use Gmail from any agent.

Claude
ChatGPT
Cursor
Codex
VS Code
OpenAI Agents SDK
Claude Agent SDK
Vercel AI SDK
Mastra
LangGraph
07 · FAQ

Gmail and Arc0, answered.

Q01

Can I use Gmail with Claude, ChatGPT or Cursor?

Yes. Connect Gmail to Arc0 once, then add your Arc0 MCP URL to Claude, ChatGPT, Cursor, Claude Code or any other remote-MCP client. Each assistant only gets the Gmail actions you allow.

Q02

How do users connect Gmail?

Users sign in to Gmail on Arc0 Connect and approve the scopes you request. Build with Arc0’s Gmail OAuth app, or bring your own so the Gmail consent screen names you. Tokens refresh automatically, and you can export them whenever you want.

Q03

Which Gmail actions can my agent take?

62 in total: 25 read, 28 write and 9 destructive, such as “create label”. Your policies decide which of them each agent may call.

Q04

Can I stop my agent from deleting things in Gmail?

Yes. Actions like “delete Draft” are graded destructive. Set destructive actions to deny, or to ask so the user approves each one, and blocked calls still show up on the audit log.

Q05

Can my own backend call Gmail too?

Yes. The same Gmail connection is available over REST and through the Arc0 proxy, so your product and your agent share one connection per user.

Get started

Plug Gmail into your agent.

Your users connect Gmail once, under your brand. Your agent gets 62 actions behind your policies, with every call on the record.

Free to build · MCP + REST · Audit log on every plan