← Back to the Muse connector directory

Gmail + Meta Muse: What the Connector Can See and Do

The Gmail connector gets more use than almost any other connector in Muse. It also makes people the most nervous. Fair enough: your inbox holds password resets, receipts, legal documents, twenty years of your life. This page lays out what the connector touches and what stays off limits.

What it does

Linking Gmail hands Muse your inbox. Then you can ask it to triage ("show me what matters today"), draft replies, dig up old receipts, or summarize a thread that's gotten out of hand. Muse suggests Gmail first during setup. You can also add it later from Settings, or just type "Connect my Gmail" into chat.

What Muse may do with your inbox comes down to the scope you grant: read-only, or read plus send. You pick at setup. You can change your mind later.

What it can see

Read access opens message bodies, subjects, senders, labels, and attachments in the account you authorize. Triage, receipt-finding, thread summaries: all of that runs on read access.

Add the send scope and Muse can compose and send email as you. Meta's docs treat read and write as separate grants. Read access never quietly becomes send access; where the service supports it, Muse keeps the two apart.

Meta says the email connector filters out one-time codes and password-reset links. The agent can't use them to log in as you anywhere else. Muse also checks with you before sending, by default. Under the hood, the connector code runs outside the agent's own runtime with tightly scoped credential access. Your Google password and OAuth tokens sit in Muse's Secure Credentials Store, where the model can't touch them.

What it can't do

Your Google password stays out of reach. The connection runs on OAuth. After one Google sign-in, Muse holds a scoped token, and the credential itself never reaches the agent.

Mail doesn't go out quietly. Sending needs the send scope, and even then Muse's approval step stands in the way unless you deliberately switched approvals off.

Only the account you authorized is in play. The connector has no line into your other inboxes or Google accounts.

3 questions people ask

Can Muse read all my emails? Only as far as you allow. Grant read access and yes, it reads the inbox; triage and search need that. You pick read-only or read-plus-send at setup, and you can pull the plug whenever you want. Unsure? Start read-only. Send access can wait until you've watched it work.

Will Muse send emails without asking me? No. Muse asks before sending, by default. You can tighten this in Settings → Permissions by switching Muse to "always ask." The horror stories come from people pre-approving whole categories of action. Leave approvals on and that failure mode stays shut.

Is it safe to connect my Gmail to an AI agent? The plumbing holds up. You sign in through OAuth, and no password changes hands. Read and write arrive as separate grants. One-time codes get filtered out. Everything the agent does lands in an audit trail. The risk that remains lives in aggregation: one agent holding email, calendar, bank, and messages makes a richer target than any single app. Review the full connector list now and then.

How to limit it

  • Grant read-only at setup. You get triage, search, summaries, and drafts without ever granting send access.
  • Set approvals to "always ask." Settings → Permissions. Then nothing goes out without your explicit tap.
  • Review the access summary. Muse shows what the connector can see and do when you connect. It's short. Read it.
  • Disconnect anytime. Settings → Connectors → Gmail → disconnect. The token dies and new data stops flowing.

See how Gmail compares against the other 40 confirmed connectors in the full Meta Muse connector directory.

← Back to the Muse connector directory