5.6 KiBLFS
Google Cloud OAuth Setup Guide
Complete guide to setting up Google Cloud credentials for Gmail API access.
Prerequisites
- Google account (Gmail)
- Web browser
- Terminal access
Step-by-Step Setup
1. Create Google Cloud Project
- Go to Google Cloud Console
- Sign in with your Google account
- Click the project dropdown at the top
- Click "New Project"
- Enter project name (e.g., "Claude Gmail Integration")
- Click "Create"
- Wait for project creation (you'll see a notification)
- Select your new project from the dropdown
2. Enable Gmail API
- In the Google Cloud Console, click the hamburger menu (☰)
- Navigate to "APIs & Services" → "Library"
- Search for "Gmail API"
- Click on "Gmail API"
- Click the "Enable" button
- Wait for API to be enabled
3. Configure OAuth Consent Screen
- In the left sidebar, click "OAuth consent screen"
- Select "External" user type
- Click "Create"
Fill in App Information:
- App name:
Claude Gmail Skill(or your preferred name) - User support email: Your email address
- Developer contact email: Your email address
- Click "Save and Continue"
Scopes:
5. Click "Add or Remove Scopes"
6. Search for gmail in the filter
7. Select: https://www.googleapis.com/auth/gmail.modify
- This scope allows read, send, and modify (but not delete) emails
- Click "Update"
- Click "Save and Continue"
Test Users: 10. Click "Add Users" 11. Add your Gmail address 12. Click "Add" 13. Click "Save and Continue"
Summary: 14. Review the information 15. Click "Back to Dashboard"
4. Create OAuth Credentials
- In the left sidebar, click "Credentials"
- Click "+ Create Credentials" at the top
- Select "OAuth client ID"
Configure OAuth Client:
4. Application type: Select "Desktop app"
5. Name: Claude Gmail Client (or your preferred name)
6. Click "Create"
Download Credentials:
7. A dialog will appear with your Client ID and Secret
8. Click "Download JSON"
9. Save the file as credentials.json
5. Save Credentials to Skill
- Move the downloaded file to the skill's auth directory:
mv ~/Downloads/credentials.json ~/.claude/skills/gmail-skill/scripts/auth/credentials.json
- Verify the file is in the correct location:
ls -la ~/.claude/skills/gmail-skill/scripts/auth/credentials.json
You should see the file listed.
6. Install Dependencies
cd ~/.claude/skills/gmail-skill
npm install
7. Run OAuth Setup
npm run setup
This will:
- Open your browser automatically
- Ask you to sign in to Google
- Show a consent screen asking for Gmail permissions
- Redirect to localhost (you'll see a success message)
- Save the OAuth token to
scripts/auth/token.json
Important Security Notes:
- Click "Continue" when you see the "App isn't verified" warning (this is expected for personal projects)
- Review the permissions carefully - you're granting access to your Gmail
- The token is stored locally on your machine only
8. Verify Setup
Test that everything works:
cd ~/.claude/skills/gmail-skill/scripts
node gmail-search.js --query "is:inbox" --limit 1
You should see JSON output with one email from your inbox.
Troubleshooting
"App isn't verified" Warning
Problem: Google shows a warning that the app isn't verified.
Solution: This is normal for personal projects. Click "Advanced" → "Go to [App Name] (unsafe)" → "Continue".
"Access blocked: This app's request is invalid"
Problem: OAuth consent screen not configured correctly.
Solution:
- Go to OAuth consent screen
- Ensure you added your email as a test user
- Ensure Gmail API scope is added
- Try authentication again
"Token not found" Error
Problem: OAuth setup didn't complete successfully.
Solution:
- Check that
credentials.jsonexists inscripts/auth/ - Run
npm run setupagain - Complete the browser authentication flow
- Verify
token.jsonwas created inscripts/auth/
"The user has not granted the app" Error
Problem: Gmail API scope wasn't granted during OAuth flow.
Solution:
- Delete
scripts/auth/token.json - Run
npm run setupagain - Carefully review permissions and click "Allow"
"Invalid client" Error
Problem: credentials.json is corrupted or incorrect.
Solution:
- Go back to Google Cloud Console
- Download credentials again
- Replace
scripts/auth/credentials.json - Run
npm run setupagain
Security Best Practices
-
Never commit credentials:
credentials.jsonandtoken.jsonare in.gitignore- Never share these files publicly
-
Token refresh:
- Tokens expire periodically
- Refresh by running
npm run setupagain
-
Revoke access:
- Go to Google Account Security
- Find your app and click "Remove Access"
-
Limit scope:
- The skill uses
gmail.modifyscope (read/send/modify) - This does NOT allow permanent email deletion
- This is the minimum scope needed for full functionality
- The skill uses
Additional Resources
Next Steps
Once setup is complete:
- Read the main
README.mdfor usage examples - Try sending a test email
- Explore the search functionality
- Set up labels and drafts as needed
The skill is now ready to use with Claude Code!