# How do I allow an MCP app in Google Workspace?

> An admin allows an app in the Admin console under API controls by marking its OAuth client ID Trusted. Steps, the errors you may see, and a note to send.

Updated: 2026-10-03 · Canonical: https://staging.nickbox.io/en/resources/allow-mcp-app-in-google-workspace

An admin allows an app in the Google Admin console, under Security, then Access and data control, then API controls, then Manage Third-Party App Access. They add the app by its OAuth client ID and mark it Trusted. Until then, Gmail permissions for that app fail with an admin policy error.

## Why does my work account show an error when I connect Gmail?

Your admin has a policy that blocks the app or the permission it asked for. Google Workspace lets admins sort third-party apps by OAuth client ID into Trusted, Limited or Blocked. An app that is not trusted cannot request restricted services such as Gmail ([Google Workspace Admin Help](https://support.google.com/a/answer/13152743)).

You may see one of these messages ([Reco's write-up](https://www.reco.ai/hub/error-400-admin-policy-enforced-google-workspace) lists them):

- "Error 400: admin_policy_enforced"
- "Access blocked: Your institution's admin needs to review..."
- "This app is blocked"

All three point to the same fix: your admin must allow the app. You cannot work around it from your side, and you should not try to, because the decision belongs to your organization.

## What does the admin do, step by step?

The admin opens API controls, finds the app by OAuth client ID and sets it to Trusted. The labels in the Admin console change from time to time, so treat this as a map and check Google's current page.

1. Sign in to the Google Admin console as an administrator.
2. Go to Security, then Access and data control, then API controls.
3. Open Manage Third-Party App Access.
4. Choose Configure new app and search by the app's OAuth client ID or app name.
5. Select the organizational units that should be able to use it. Start with one group if you want a pilot.
6. Set the access to Trusted so the app can request Gmail permissions. Limited and Blocked keep restricted services off.
7. Save, then ask the user to connect again.

Use Limited if you want the app to work without the highest-risk permissions; for a Gmail reader, that means it will not work. For Nickbox to read mail, the setting needs to be Trusted for the people who will use it.

## What should the admin know about Nickbox?

The admin should know what the app can do, what it stores and that it is in beta. Here are the facts:

- Nickbox asks for the `gmail.readonly` permission. It can read and search mail. It cannot send, draft, delete or change anything.
- It stores connection metadata and an encrypted refresh token per inbox in Google Cloud Secret Manager. It does not write message contents to its database or logs.
- It is in a limited beta. Nickbox has not finished Google's verification yet, so Google shows the unverified app warning and lets the app connect only 100 Gmail accounts. See [why Google says "unverified app"](/en/resources/google-unverified-app-warning-gmail-mcp).
- Details are on the [security page](/en/security).

An admin may reasonably say no, or wait until verification is done. If the answer is no, a personal Gmail account is not affected by your company's policy, so you can connect that one on its own.

## What note can I send my admin?

Copy this and adjust it:

> Hi, I would like to connect my work Gmail to an AI assistant (Claude, ChatGPT or Gemini) through a read-only MCP service called Nickbox. It uses the gmail.readonly permission only, so it cannot send, delete or change mail, and it does not store message content. To allow it, please set its OAuth client ID to Trusted under Security > Access and data control > API controls > Manage Third-Party App Access, for my organizational unit. The app is in public beta, so Google currently shows an "unverified app" screen. Details: [link to Nickbox security page]. Thanks.

Ask Nickbox support for the OAuth client ID to include in the note, since the admin needs it to find the app.

## Which guide do I read next?

After your admin allows the app, connect your inboxes and then paste the URL into your assistant. The steps are in the guides for [Claude](/en/docs/claude), [ChatGPT](/en/docs/chatgpt), [Gemini](/en/docs/gemini), [Cursor](/en/docs/cursor), [VS Code](/en/docs/vscode) and [Claude Code](/en/docs/claude-code). Plans and price are on the [pricing page](/en/pricing): US$5 a month or US$48 a year.

## FAQ

**Who can allow a third-party app in Google Workspace?**

A Workspace administrator with access to API controls in the Admin console. A regular user cannot override the policy, which is why the app shows an error instead of a consent screen.

**What does 'Error 400: admin_policy_enforced' mean?**

Your organization's admin policy blocks the app or the permission it asked for. The fix is on the admin side, by allowing the app's OAuth client ID.

**Can I use Nickbox with a work Gmail account?**

Yes, if your Workspace admin allows third-party apps to use Gmail data. Nickbox asks for the read-only gmail.readonly permission.

**Does the admin get access to my email by allowing the app?**

No. Allowing the app lets you grant it permission. The permission you grant is read-only and applies to your inbox.

## Sources

- [Google Workspace Admin Help: control which third-party apps access your data](https://support.google.com/a/answer/13152743)
- [Error 400: admin_policy_enforced in Google Workspace (Reco)](https://www.reco.ai/hub/error-400-admin-policy-enforced-google-workspace)
