Set up Google OAuth

This guide separates Google Cloud’s public branding from the MCP server’s Gmail connection. This website never asks for a secret.

Branding fields for the Hypersimple application

Google Cloud field mapping
Google Cloud fieldValue or page
App nameHypermail MCP
Support email and developer contactmateo.tiedra@hypersimple.ch
Application home pageHome — index.html
Privacy policyPrivacy — privacy.html
Terms of ServiceTerms — terms.html

After publishing on your chosen domain, enter the full HTTPS URLs of these pages in Google Cloud, then declare and verify ownership of the domain with Google. No production domain has been chosen yet.

If you create your own OAuth application, use your own contacts and a policy reflecting your deployment. Hypersimple’s pages do not implicitly cover third-party installations.

Gmail checklist

  1. Enable Gmail API in your Google Cloud project.
  2. Configure the application’s audience and test users.
  3. Declare the restricted scope https://www.googleapis.com/auth/gmail.modify.
  4. Create a Desktop OAuth client for local use, or a Web client for a hosted server.

MCP server configuration

Set HYPERMAIL_GMAIL_CLIENT_ID and HYPERMAIL_GMAIL_CLIENT_SECRET if a secret is issued for that client type. Keep these values in the instance’s secure configuration, never in website files.

Locally, the default callback is http://127.0.0.1:33333/callback. For a hosted server, set HYPERMAIL_GMAIL_REDIRECT_URI to that server’s full HTTPS callback URL and register exactly the same URI in the Google Web client. The hosted path is /oauth/gmail/callback.

This callback belongs to the MCP server, not the static website. The HTTP MCP server requires a private network or an authenticating and authorizing proxy; do not publish its port without protection. See the repository’s Gmail guide for connecting an account.

Before Google production use

gmail.modify is a restricted scope. These pages alone do not guarantee compliance, verification or Google approval. Depending on deployment and usage, additional verification or a security assessment may apply. See the requirements for restricted scope verification and OAuth policy compliance.