Google Workspace admin: trust Muin once
One-time Workspace admin setup at admin.google.com so your team can connect Gmail mailboxes to Muin without unverified-app warnings. About five minutes.
This guide is for Google Workspace super-admins whose teammates want to connect their Workspace Gmail to Muin. It’s a one-time setup — once you trust Muin’s OAuth client at the org level, every member of your organization can connect without seeing “unverified app” warnings.
Audience and prerequisites
- You are a Google Workspace super-admin (Business Standard or higher).
- A teammate has asked you to trust Muin so they can connect their mailbox.
- You have your Workspace admin sign-in handy.
If you’re not sure whether you have super-admin access: admin.google.com shows the Apps menu only to super-admins. If that menu is missing, ask whoever set up your Workspace.
Step-by-step (≤5 minutes)
- Sign in to admin.google.com with your super-admin account.
- Go to Apps → Web and mobile apps → Manage Third-Party App Access.
- Click Add app → OAuth App Name Or Client ID.
- Enter Muin’s Client ID. Your teammate can copy it from the Muin in-app setup screen at Settings → Communications → Connected mailboxes → Connect Google Workspace, or you can find it in the email they sent you via the Send admin instructions button.
- Click Search, then select Muin from the results. Click Continue.
- On the access setting screen, choose Trusted: Can access all Google services.
- Confirm the requested scopes when prompted — Muin requests these three:
https://www.googleapis.com/auth/gmail.readonlyemailopenid
- Click Configure to save.
That’s it. Your teammates can now connect their Workspace Gmail at Settings → Communications → Connected mailboxes in Muin without warnings.
What changed
After trusting Muin once at the org level:
- Members of your Workspace can authorize Muin against their personal mailboxes via the standard OAuth flow without seeing “unverified app” warnings or being blocked.
- Each member’s Muin connection grants only their own mailbox — Muin cannot see colleagues’ mailboxes through one user’s connection.
- You can revoke Muin’s trust any time from the same Manage Third-Party
App Access screen. Revocation immediately blocks any new connections
and ends sync on existing connections (Muin marks them
revoked).
What Muin does and does not access
| Scope | What we use it for |
|---|---|
gmail.readonly | Read your teammate’s mail in the labels they select (default INBOX). |
email, openid | Identify which mailbox connected. |
The integration is read-only. We do not request gmail.send —
Muin never sends from a teammate’s Gmail address, so we don’t ask for
permission to.
We do not request Drive, Calendar, Contacts, Chat, Meet, Sites, or any other Workspace service. Muin’s request is mailbox-only.
Common questions
Does each member need their own consent after I trust the app? Yes — trust at the org level dismisses the warning, but each individual still goes through the standard “Allow Muin to access your Gmail?” flow. Their consent stays with their account, and they can revoke any time from their personal Google account.
Can colleagues see each other’s mail through Muin? No. Each connection is per-user; Muin only stores tokens for the user who authorized them. The admin-only team-mailbox view in Muin shows connection metadata (who connected, when, last sync) — not message content.
What if I deny access later?
Removing Muin from Manage Third-Party App Access revokes all existing
connections from your org. Muin flags them revoked and stops syncing.
Your teammates can re-connect once trust is restored.
Need help?
If you’re stuck on any step, your teammate can click Get help on the
in-app Workspace admin trust screen. That opens a tagged support ticket
that gets worked on the
email-mailbox-workspace-admin-trust-help
runbook within 1 business day.
Next steps
- Have your teammate open Settings → Communications → Connected mailboxes in Muin and complete their connection.
- Connect a Google Workspace mailbox — the user-facing guide.