CommSyncdocs
Open app
Channels

Gmail sign-in guide

What Sign in with Google needs from a Gmail or Google Workspace account, what a Workspace admin can allow, and what to do when Google blocks the sign-in.


Sign in with Google connects a Gmail or Google Workspace mailbox without an app password. You sign in on the page of Google, and CommSync never sees your password.

Sign in with Google comes to workspaces in stages. Until it reaches your workspace, the Gmail card connects with an app password. That path works as before. See Email accounts.

What CommSync asks Google for

Google shows one consent screen. CommSync asks for these scopes:

ScopeWhy CommSync needs it
https://mail.google.com/CommSync reads the mailbox over IMAP and sends your mail. Google offers no smaller scope for IMAP and SMTP.
openid, email, profileCommSync reads the address of the account that signed in.

Before Google shows its consent screen, CommSync shows what it will do with the mailbox. CommSync uses the data only to show and send your mail in CommSync. It never uses your mail to train AI models. The Privacy Policy has the full statement of how CommSync uses data from Google.

Check that IMAP is on

CommSync syncs over IMAP.

  • A personal Gmail account has IMAP on. You do not need to change a setting.
  • A Google Workspace account uses the IMAP setting of its organization. A Workspace admin can turn IMAP off for everyone.

A Workspace admin checks the setting in the Google Admin console:

Open the Gmail settings

Sign in to admin.google.com. Open Apps → Google Workspace → Gmail → End User Access.

Check POP and IMAP access

Open POP and IMAP access. Make sure that Enable IMAP access for all users is on for the organizational unit of the user.

Check the mail client rule

If the setting limits IMAP to some mail clients, add the OAuth client ID of CommSync to the list. Email [email protected] for the client ID.

Allow CommSync in Google Workspace

A Workspace admin can block third-party apps that ask for Gmail data. Google then refuses the sign-in, and CommSync shows that a policy of your organization blocks it. The admin can allow CommSync:

Open app access

In the Google Admin console, open Security → Access and data control → API controls. Click Manage Third-Party App Access.

Add CommSync

Click Configure new app. Search by the OAuth client ID of CommSync. Email [email protected] for the client ID.

Pick the scope of the rule

Pick the organizational units that can use CommSync.

Set the access

Set the access to Trusted. Save the rule.

The user then clicks Try again in CommSync.

Advanced Protection

The Google Advanced Protection Program limits which apps can read the mail of an enrolled account. Sign in with Google can fail for an Advanced Protection account. CommSync then shows the link Use an app password instead at once.

CommSync keeps you on Sign in with Google when it can work. It shows Use an app password instead below the sign-in button in these cases:

  • Two sign-ins with Google failed in the last 24 hours. A declined consent does not count.
  • Google blocked the sign-in by a policy of your organization, or because of Advanced Protection.
  • Google does not let your account sign in to CommSync yet.

The app-password path is the same form as before Sign in with Google. A Google Workspace admin can turn off app passwords too. Then only Sign in with Google can connect the mailbox.

Remove CommSync from your Google account

When you remove the mailbox in Settings → Email accounts, CommSync asks Google to revoke its access and deletes its tokens. You can also remove CommSync yourself:

Open your Google account

Go to myaccount.google.com/permissions.

Remove CommSync

Select CommSync. Remove the access of CommSync.

After this, the mailbox shows Action required in CommSync. The conversations that CommSync already synced stay in your workspace. To ask CommSync to delete that mail, email [email protected].