3.1k Downloads
Overview
Guide and helper scripts to perform a headless-friendly OAuth flow for Gmail API access using the `gog` CLI, including Google Cloud setup, credential configuration, and token exchange/renewal.
Key Advantages
1.End-to-end walkthrough from Google Cloud project creation to working `gog gmail` commands
2.Explicitly designed for headless/server environments via file-based keyring and manual code exchange
3.Clear, opinionated defaults (Desktop OAuth client, http://localhost redirect, gmail.modify scope) that match current Google OAuth constraints
4.Rich troubleshooting section covering common OAuth/Gmail pitfalls (testing mode, verification warnings, redirect_uri_mismatch, oob deprecation, token expiry)
5.Focus on least-privilege usage with scope recommendations and explanations of each scope’s access level
Use Cases
- Initial setup of Gmail API access for automation using the `gog` CLI
- Renewing or recreating expired/invalid Gmail OAuth tokens for existing `gog` installations
- Configuring Gmail OAuth on headless servers or CI environments where browser-based flows are awkward
- Troubleshooting OAuth-related errors such as `invalid_grant`, `redirect_uri_mismatch`, or short-lived tokens due to testing-mode apps
- Migrating from deprecated out-of-band (oob) OAuth flows to localhost-based redirect flows for new Google Cloud projects
Evaluation Scores
7.9
/ 10
Reliability
7.5
Functionality
8.7
Usability
8.5
Safety
7.0
Performance
8.0
Compatibility
7.5
Based on 1 evaluation · Latest: 3/19/2026
Download Trend
Loading...
Evaluation History (1)
7.9/103/19/2026▼
OS: darwin-x64LLM: z-ai/glm-5
**Judgement:** This skill is a strong, practical guide for setting up Gmail OAuth with the `gog` CLI, especially on headless servers. It’s well-structured, covers the full lifecycle from project setup to verification, and includes detailed troubleshooting for real-world Google OAuth quirks.
**Key strengths:**
- End-to-end, actionable steps with a dedicated helper script (`scripts/gmail-auth.sh`).
- Tailored for headless and automation scenarios using file-based keyrings.
- Comprehensive troubleshooting of common Google Cloud/OAuth issues (testing vs published app, verification warnings, redirect mismatches, token expiry, mobile redirects).
- Sensible defaults around scopes (e.g., `gmail.modify`) and redirect URIs (`http://localhost`).
**Risks & limitations:**
- Relies on the `gog` CLI and Google Cloud Console; users must be comfortable with both.
- OAuth flow is still manual and time-sensitive (auth codes expiring in minutes), so human error can cause frustration.
- File-based keyring plus storing the keyring password in shell config has security implications if the system is compromised.
- Instructions are Gmail- and `gog`-specific; not a general-purpose OAuth abstraction.
**Recommended scenarios:**
- You’re setting up Gmail access for automation scripts or tools that use `gog`, particularly on servers or remote machines.
- Existing Gmail OAuth tokens for `gog` have expired or broken and you need a reliable recovery path.
- You repeatedly hit Google OAuth issues (7-day tokens, verification warnings, redirect errors) and want a documented, battle-tested flow.
- You need a minimal-scope, personal-use Gmail integration without going through full Google app verification.
Comments (0)
No comments yet. Be the first!