Docs/Lanes Link/Providers/Gmail (Google MCP)

Gmail (Google MCP)

Connect Gmail (Google MCP) to your agents with Lanes Link. Google's own MCP server. Developer Preview only.

Read and compose mail via Google's official Gmail MCP server. Requires Workspace Developer Preview enrolment; use "gmail" otherwise.

Connect it

console
$ lanes link connect gmail_mcp --profile personal --workspace local

Gmail (Google MCP) does not offer dynamic registration, so this needs an OAuth application of your own: you register it once in their console, and Lanes Link uses those values from then on. Run lanes link setup plan gmail_mcp for the exact steps, the values it wants, and the command that finishes the job.

What your agent can do

The tool list comes from Gmail (Google MCP)'s own MCP server and is discovered when you connect, so the capabilities are theirs rather than ours.

To see exactly what your agents are handed right now:

console
$ lanes link tools --profile personal --workspace local

The scopes it asks for

Each provider asks for the narrowest set that makes its capabilities work, because a scope on a consent screen that no tool can spend is a grant asked for and never noticed.

ScopeWhat it allows
https://www.googleapis.com/auth/gmail.readonlyread mail and settings
https://www.googleapis.com/auth/gmail.composecreate and send drafts

How to narrow or widen any of this is on Scopes and permissions.

What is recorded

Every call is recorded, allowed or refused. Because the capabilities are Gmail (Google MCP)'s rather than ours, redaction has no authored list to key on, and the default withholds every argument value: you get the call, not what was in it.

That is the right default when we did not write the capability and cannot know what is sensitive. It does mean this connection gives you a thinner record than a provider with a vendored specification does.

What an entry holds and how to read one is on the audit log.

Narrowing what it may do

Connecting grants the read bundle. Tightening it happens on your machine and takes effect at once:

console
$ lanes link policy deny 'gmail_mcp.*' --connection gmail_mcp.main --profile personal --workspace local

A deny always beats an allow, whatever the order in the file. See Scopes and permissions for widening, and for what can and cannot be set per connection.


Next: every provider, or Connections for what a connection is and the methods behind one.