How do I revoke Gmail access from an AI app?
Remove an AI app's access to Gmail from your Google Account in a few clicks, with the Workspace admin route, token effects and how to disconnect Nickbox.
Open myaccount.google.com/connections, pick the AI app, choose Remove access and confirm. The app loses its permission to read your Gmail. Then remove the connector inside your assistant. Google notes the app may keep data it already collected, so ask it to delete that data too.
How do I revoke Gmail access in my Google Account?
Revoking takes about a minute in your Google Account. The wording of menus changes from time to time, but the path stays the same: Security, then the list of apps with access, then the one you want to remove.
- Go to myaccount.google.com/connections, or open your Google Account and choose Security.
- Find Third-party apps and services and select See all connections.
- Select the AI app or server you want to remove. Google shows the access it has.
- Select Remove access and confirm.
These steps follow Google's guide to managing third-party connections. Repeat them for each Gmail account you connected, since every account has its own list. Sign-in connections ("Sign in with Google") use a different button, Stop using Sign in with Google, and are separate from Gmail access.
What does revoking actually do to the app's tokens?
Revoking cancels the permission that the app's token depends on. Google's developer documentation says a refresh token can be invalidated at any time, for example when the user revokes access, and the app must handle that. After revocation the app cannot get new access tokens.
We could not verify how long an access token issued just before you revoked keeps working, so do not rely on a precise delay. Google also states that the app may keep the data you already shared. For that reason, ask the app to delete any stored data. Nickbox does not store message content, so there is no mail copy to delete there.
What if my Google Workspace admin manages apps?
In a Workspace account, an admin can allow, limit or block third-party apps for the whole domain. You can usually still remove access from your own connections page. Admins can also review and revoke access centrally in the Admin console.
For admins, the controls are:
- Open the Admin console and go to Security, Access and data control, API controls.
- Select Manage Third-Party App Access to see apps with OAuth permissions and their scopes.
- For an app installed from the Marketplace, go to Apps, Google Workspace Marketplace apps, Apps list, open the app and use Revoke access in the Data access section. Google notes you cannot revoke individual scopes, only all of them.
If your admin blocks the app, it cannot reconnect. The guide to allowing an MCP app in Google Workspace covers the other direction. We did not verify the per-user revoke steps for apps outside the Marketplace, so ask your admin if the options above do not match what you see.
How do I disconnect Nickbox?
Disconnect each inbox in the Nickbox dashboard, then remove the connector from your assistant, then check Google. Disconnecting an inbox deletes its connection data and revokes its token with Google, per the privacy policy.
- Open the Nickbox dashboard and go to your inboxes.
- Disconnect each inbox. Reads through Nickbox for that inbox stop.
- Remove the Nickbox connector in your assistant. In Claude, open the connector list and remove it. Guides for ChatGPT, Cursor and Claude Code show the same step there.
- Open myaccount.google.com/connections and confirm Nickbox is gone.
- If you also want your account deleted, write to us. During the beta, deletion is handled by email and completed within 7 days.
Nickbox holds only the read-only Gmail permission (gmail.readonly), so it cannot send, draft or delete mail. The security page lists what is stored.
What should I do if I think an app misbehaved?
Revoke first, then check what happened. Remove the app's access in Google, then review your Google Account's security activity and change your password if anything looks wrong. The safety guide explains how a malicious email can steer an assistant, and why read-only access reduces that risk without removing it.
Removing access does not cancel a subscription. If you pay for Nickbox, cancel from your dashboard. The pricing page explains the plan: US$5 a month or US$48 a year, with a 7-day trial that needs a card.
Questions
Where do I see which apps can read my Gmail?
Open myaccount.google.com/connections, or Google Account, Security, Third-party apps and services, then See all connections. Each app lists the access it holds.
Does revoking delete what the app already collected?
No. Google says an app may keep data you already shared, and you must ask the app to delete it. Nickbox does not store message content, and disconnecting an inbox deletes its connection data.
Should I disconnect in the app or in Google?
Do both. Disconnecting in the app stops it from reading and, for Nickbox, revokes the token with Google. Removing access in Google confirms the permission is gone on Google's side.
My Workspace admin controls apps. Can I still revoke?
You can usually remove access to an app from your own account page. Admins can also block an app or revoke its access for the whole domain in the Admin console.
Sources
- Manage connections between your Google Account and third parties (Google Account Help)
- OAuth 2.0 for web server applications, token revocation (Google for Developers)
- Manage data access for admin-installed Marketplace apps (Google Workspace)
- Get started with custom connectors using remote MCP (Claude Help Center)
