Gmail Overview
The Gmail connector indexes approved email conversations as OpenCore knowledge. An Admin creates and maintains the Google credential, selects it when creating the connector, and verifies the indexed result before attaching its document set to an Agent.
What the connector indexes
Each Gmail thread becomes one document. The first available subject is its title, and each message contributes a section linked to the thread in Gmail.
The connector does not expose Drive-style file, folder, or shared-drive filters. Gmail coverage is determined by the mailbox accounts available through the selected credential.
Choose an authentication method
Both methods request the Gmail read-only scope plus read-only Workspace user and group directory scopes. Choose the method that matches how your organization administers Google access; do not use a Service Account for a personal Gmail mailbox.
Mailbox permissions and synchronization
For each indexed thread, OpenCore records a non-public external-access entry for the mailbox address used to fetch it. The Gmail connector does not add Google group IDs to that entry and does not turn a thread into public content.
When the deployment runs Gmail permission synchronization, it revisits slim thread records in the synchronization time window and updates the external-access record for each returned thread. This path preserves the same mailbox-only, non-public boundary; it does not infer broader visibility from message recipients or Workspace groups.
Updates and multiple credentials
The connector creation form defaults to pulling new content every 30 minutes. An Admin can choose another refresh frequency of at least one minute and can set an indexing start date to bound the initial historical query. Source changes appear only after a later successful index attempt.
Creating a second Gmail credential preserves existing Gmail credentials. Use separate credentials and connectors when Google environments or mailbox access boundaries differ, and confirm which credential is selected before creating the connector. Revoking or replacing one credential affects the connectors that use it, not unrelated Gmail credentials.
Before you connect
- Use Standard mode, because connectors and document indexing require a vector database.
- Obtain approval for the mailboxes and historical period that will be indexed.
- Start with a narrow indexing start date and a representative account boundary.
- Review the first index attempt and its document set before attaching it to an Agent.
Next steps
- Gmail OAuth covers the uploaded OAuth app JSON and browser authorization flow.
- Gmail Service Account covers Domain-Wide Delegation and the Primary Admin Email.
- Connectors & Indexing explains document sets and index attempts.