Fix Make's Gmail "restricted scopes" / unverified app error with a personal @gmail.com account

Short answer

The error comes from Google, not Make: Gmail's API scopes are "restricted", and Make's shared credentials for the legacy Gmail module and the Email app's "Google Restricted" connection are not allowed for personal @gmail.com accounts. Since Make's new Gmail app (select "V4" on the module), a personal account connects with "Sign in with Google" and no Google Cloud project — the only cost is re-authorising every six months. If you must use a legacy module or the Email app with Google, create your own OAuth client in Google Cloud (steps below) or send through SMTP with a Google App Password.

"Not possible to use restricted scopes with customer @gmail.com accounts" in Make? Switch to the Gmail V4 module, or use your own OAuth client or SMTP.

Disclosure: links marked "paid link" pay us a commission from the vendor if you sign up. Your price is unchanged, and every file here works without them. How we choose tools →

You add a Gmail module in Make, click "Sign in with Google", pick your @gmail.com account — and instead of a mailbox you get a wall of text: "It is not possible to use restricted scopes with customer @gmail.com accounts. For more information on how to connect restricted scopes visit our documentation." Or Google itself stops you: "Access blocked: integromat.com has not completed the Google verification process." This page explains why in two paragraphs, then gives the three working paths in order of effort. Every step was checked against Make's help center and Google's documentation on 29 September 2026.

Why a personal Gmail account is treated differently

Google classifies the Gmail API scopes — https://mail.google.com/, gmail.readonly, gmail.modify, gmail.compose, gmail.insert, gmail.metadata, gmail.settings.basic and gmail.settings.sharing — as "restricted scopes" (Google Cloud Console Help). An app that asks any Google user for these must pass Google's verification, and if it stores the data on its own servers, an annual third-party security assessment. That is the rule that makes the shared credentials behind Make's older Gmail modules unusable for consumer accounts, while a Google Workspace account (an address on your own domain) is governed by its administrator and connects with Make's default credentials.

So the error is not about your password or your plan. It says: the app that is asking Google for your mailbox is not one Google will let a consumer account authorise. There are three ways out. The first is now the normal one.

Path 1 (do this first): use the current Gmail app, "V4"

Make replaced its Gmail app. The help center note "New Gmail app is now available" (updated 19 January 2026) lists among the changes an "Easier setup" that "doesn't require creating a Google Cloud Platform project and OAuth credentials for personal Gmail accounts". In practice: if you see the restricted-scopes error, you are almost always on a legacy Gmail module — an old blueprint, a tutorial from 2023, or a module you added without picking the version.

  1. In the scenario, click "+" and search for "Gmail". When the module list appears, look at the upper-right corner of the panel and select "V4". (A module labelled "Gmail (Legacy)" is the old one.)
  2. Pick the module you need — "Watch Emails" for a trigger, "Send an Email" for sending — and click "Create a connection".
  3. Give the connection a name (your address is a good one). Leave "Additional Scopes" and the advanced settings alone.
  4. Click "Sign in with Google", choose your @gmail.com account and click "Allow" on Google's consent screen.
  5. Back in Make, the connection appears in the field. Click OK, then "Run once" to test.

The one condition, from Make's Gmail documentation: since 3 June 2024, Google limits Gmail access for apps like Make to six months for personal @gmail.com accounts, so "you have to renew permissions and reauthorize the connection every six months". Make shows the date the connection is valid until. When it comes: left menu → Connections → the Gmail connection → "Reauthorize" → choose the account → Allow. Put the date in your calendar; an expired connection stops the scenario with an error in the history, not silently.

Both Gmail blueprints on this site were rebuilt on the V4 modules (google-email version 4, checked 29 September 2026), so importing them into a personal account needs no Google Cloud work at all.

Labelled email → task in the log → reminder

Tag an email with one label and it becomes a task with a due date and an alert. One screen for everything that is waiting.

No Make account yet?The file imports only into Make. Signing up through the link gives you one month of Core free, and us a commission. The file works without the link.
Sign up for Make →paid link · we earn a commissionPaid link. If you sign up through it we earn a commission from Make; your price is the same, and the link gives you one month of Core free.

Invoice past due → an automatic, polite reminder

Once a day it finds open invoices past their date and sends a reminder. The client no longer has to remember to chase.

Path 2: a Google Workspace account

If the mailbox is on your own domain (you@yourbusiness.com through Google Workspace), the restriction does not apply: Make's default credentials connect the legacy modules and the Email app's "Google Restricted" connection as well. This is the right answer when a client already has Workspace. It is not a reason to buy Workspace for an automation — Path 1 covers a personal account for free. One known wrinkle from the community (April 2026): some Workspace accounts were being stored as a "google-restricted" connection with the wrong scopes; the fix there was the same — use the V4 module.

Path 3: your own OAuth client in Google Cloud

You need this only in three cases: a legacy Gmail module you cannot replace, the Email app connecting to Gmail with the "Google Restricted" option (IMAP through Google), or a wish to control the permissions yourself. It is about 15 minutes, free, and the procedure below follows Make's help article "Connect to Google services using a custom OAuth client" (updated 25 September 2026) plus the redirect address from the Gmail (Legacy) page. Screens described in words, since Google moves them: everything happens in one browser tab at console.cloud.google.com.

  1. Open https://console.cloud.google.com/ and sign in with the same @gmail.com account you want to connect. At the top, click the project selector → "New project" → name it (e.g. "Make Gmail") → "Create", then select it.
  2. Left menu → "APIs & Services" → "Library". Search "Gmail API" → open it → "Enable".
  3. Left menu → "APIs & Services" → "OAuth consent screen" (Google now calls this area "Google Auth Platform") → "Get started". App name: Make. User support email: your address. Audience / User type: "External". Contact email: your address. Agree to the policy → "Create".
  4. In "Branding", under "Authorized domains", add make.com and integromat.com (Make still uses both). Save.
  5. In "Audience", click "Publish app" so the status is "In production". Do not leave it in "Testing": Google's OAuth documentation says a project in Testing with an external user type "is issued a refresh token expiring in 7 days" — your connection would die weekly. Google may show a "needs verification" notice; you can ignore it for your own use.
  6. In "Data Access", click "Add or remove scopes". Tick, or paste manually, https://mail.google.com/ and https://www.googleapis.com/auth/userinfo.email (the scopes Make's Gmail (Legacy) page lists). "Update" → "Save".
  7. In "Clients", click "+ Create client". Application type: "Web application". Name it. Under "Authorized redirect URIs", add each of these on its own line: https://www.integromat.com/oauth/cb/google-restricted, https://www.make.com/oauth/cb/google-restricted, https://www.integromat.com/oauth/cb/google/, https://www.make.com/oauth/cb/google and https://www.make.com/oauth/cb/google-custom. Click "Create".
  8. Copy the "Client ID" and the "Client secret" somewhere private. The secret is shown once.
  9. In Make: open the Gmail (or Email) module → Connection → "Add". Turn on "Show advanced settings" and paste the Client ID and Client Secret — before clicking sign-in, or Make uses its own credentials and you get the "integromat.com has not completed the Google verification process" error again.
  10. Click "Sign in with Google". Google shows "Google hasn't verified this app": click "Advanced", then "Go to Make (unsafe)", then "Allow". The connection is created.

Why the long list of redirect addresses: "Error 400: redirect_uri_mismatch" is the most common failure in the community threads on this topic, and it means the address Make sent Google back to is not in your list. Adding all five costs nothing. Two other errors map directly: "Error 403: access_denied" means the app is in Testing and your address is not a test user (publish it instead); "Insufficient Permission" means a scope is missing in Data Access — add it, then Connections → "Reauthorize".

What not to do

  • Do not submit the app for Google verification or a security assessment. That process exists for apps serving the public; Google's own page lists "personal use" among the cases that do not need it, and unverified apps work for up to 100 users.
  • Do not paste the Client Secret into a chat, a support ticket or a shared document. Anyone holding it plus a consent from you can read the mailbox.
  • Do not use the Testing status to avoid the "unverified" warning. The warning is a one-time click; a 7-day token expiry is a weekly outage.
  • Do not create the connection first and paste the credentials afterwards. The connection is bound to whichever credentials were present at sign-in; delete it and start again with the advanced settings open.
  • Do not look for "Less secure app access" in your Google account. Google removed it; the SMTP path below uses an App Password instead.

When to use the Email (SMTP) module instead

If all the scenario does is send — a reminder, a confirmation, a report — you do not need the Gmail API at all. Make's Email app can send through Gmail's SMTP server with a password Google issues for exactly this purpose. It cannot watch an inbox, so the email-to-task blueprint still needs the Gmail app; the invoice reminder could run on either.

  1. Turn on 2-Step Verification for the Google account (myaccount.google.com/security). Google issues App Passwords only to accounts that have it.
  2. Open https://myaccount.google.com/apppasswords, type a name such as "Make SMTP" and click "Create". Copy the 16-character password without the spaces. It is shown once.
  3. In Make: Email → "Send an Email" → Connection → "Add". Choose the non-Google option ("Other"), not "Google Restricted". Server: smtp.gmail.com. Port: 465 with the secure (TLS/SSL) option on, or 587 with explicit TLS. User name: your full @gmail.com address. Password: the App Password.
  4. Save and "Run once" with your own address as the recipient.

Two limits, both from Google (checked 29 September 2026): a personal Gmail account can send about 500 emails a day, and Google's help says App Passwords "aren't recommended and are unnecessary in most cases" — meaning use "Sign in with Google" (Path 1) when the app supports it, and SMTP when it does not. App Passwords are also unavailable on accounts with Advanced Protection, or when a Workspace administrator has disabled them.

Still broken? Check these three things

  • The module version. Click the Gmail module; if its name or the panel does not say V4, replace it with the V4 module and map the fields again. The restricted-scopes text only comes from the legacy module or the Email app's Google option.
  • Which credentials the connection used. Left menu → Connections → the Gmail connection. If you built an OAuth client and the sign-in page still said "integromat.com has not completed…", the connection was created with Make's credentials: delete it and re-create it with "Show advanced settings" open.
  • The Google Cloud project, top to bottom: Gmail API enabled; publishing status "In production"; both scopes under Data Access; all five redirect addresses on the Web application client; the same Google account in the console and in the sign-in. Each of the five errors above points at exactly one of these.

New to Make? The free plan is enough to build both Gmail automations on this page and prove them on your own inbox: Sign up (one month of Core free) → paid link · we earn a commissionPaid link. If you sign up through it we earn a commission from Make; your price is the same, and the link gives you one month of Core free.

Do I still need a Google Cloud project to connect a personal Gmail to Make?

Not with the current Gmail app. Make's help center says the new app "doesn't require creating a Google Cloud Platform project and OAuth credentials for personal Gmail accounts" (updated 19 January 2026). Select V4 on the module and sign in. The Google Cloud steps are only for legacy modules or the Email app's Google connection.

Why does my Gmail connection stop working every six months?

Google limits Gmail access for reporting and monitoring apps to six months for personal @gmail.com accounts, since 3 June 2024 (Make Gmail documentation). Connections → Reauthorize renews it. Google Workspace accounts are not subject to this limit.

Is it safe to click "Go to Make (unsafe)" on the unverified app screen?

The screen appears because the OAuth client you created has not been verified by Google — you are the developer and the only user. The token goes to Make's redirect address on your own client. It is the expected step in Make's documentation; the thing to protect is the Client Secret.

What does "redirect_uri_mismatch" mean?

Google was asked to send the sign-in back to an address that is not in your client's "Authorized redirect URIs". Add the make.com and integromat.com addresses listed in Path 3, save, wait a minute and try again.

Can I just use SMTP for everything?

For sending, yes: the Email app with smtp.gmail.com and an App Password sends from a personal account without any API scopes, within Gmail's daily limit of about 500 messages. For reading or watching an inbox you need the Gmail app (V4).

Will Path 3 work for Google Drive too?

Yes — the same custom OAuth client, with the Drive scopes added under Data Access and the Drive API enabled. Google Drive has restricted scopes of its own, which is why the same error appears there for personal accounts on some connection types.

  1. Make Help Center — New Gmail app is now available (V4; no GCP project needed for personal accounts; updated 19 January 2026)
  2. Make Apps Documentation — Gmail (connection steps; six-month reauthorization for personal accounts since 3 June 2024; updated 25 September 2026)
  3. Make Apps Documentation — Gmail (Legacy) (restricted access for @gmail/@googlemail; redirect URI google-restricted; scopes mail.google.com and userinfo.email)
  4. Make Help Center — Connect to Google services using a custom OAuth client (project, consent screen, Testing vs Production, troubleshooting; updated 25 September 2026)
  5. Make Apps Documentation — Email (connection types: Google Restricted, Others IMAP, Microsoft; TLS fields)
  6. Google Cloud Console Help — Restricted scopes (the Gmail scopes list)
  7. Google for Developers — Restricted scope verification (security assessment; personal-use exemption; user cap for unverified apps)
  8. Google for Developers — Using OAuth 2.0 (Testing status: refresh token expires in 7 days)
  9. Google Account Help — Sign in with app passwords (2-Step Verification required; not recommended where "Sign in with Google" exists)
  10. Gmail Help — "You have reached a limit for sending mail" (500 emails a day on personal accounts)
  11. Make Community — "Unable to connect Gmail to Make.com using custom Google OAuth credentials" (May 2026; redirect URIs, production status)
  12. Make Community — "Problems with gmail restricted scope" (February 2025; the exact error text)
  13. Make Community — "Google Restricted Scopes Connection Error: redirect_uri_mismatch" (August 2025)

What will it cost? Make cost calculator →Build your automation plan →