Gmail plugin: create_filter / list_filters fail with 403 — OAuth missing gmail.settings.basic
Los mantenedores suelen responder en 1 día
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 3/5
- Tiempo estimado
- 1-2 días
- Aptitud para principiantes
- 68/100
- Tipo de issue
- Error
- Claridad
- Bastante claro
- Estado de actividad
- Activo
- Stack tecnológico
- google-cloud, typescript
- Área
- api, authentication
Línea de trabajo
Localiza la configuración del cliente OAuth y del consent-scope del plugin de Gmail y, a continuación, rastrea el punto de entrada de upscoping utilizado por create_filter y list_filters. Confirma que se solicita el scope settings y que está documentado el consentimiento renovado de los usuarios existentes; se considera hecho cuando las herramientas de filtros ya no fallan con el 403 indicado después de la autorización.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
Summary
The Gmail connector exposes create_filter, list_filters (and related filter tools), but calling them fails with 403 after trying upscoping. Google Account → Linked Apps shows the Cursor/Grok app only has “See (but not change) your email settings”, so filter create/list cannot work. Re-auth does not help: Google never requests a settings-write scope during consent.
Environment
- Product: Grok Bot / Cursor Gmail MCP connector
- Plugin id (from install):
45893410 - MCP server id:
user-Gmail--shark5060-gmail-com - Account: personal Gmail (example:
[email protected]) - Other Gmail tools work:
list_labels,search_threads, label apply, etc.
Steps to reproduce
- Install/connect the Gmail plugin and complete OAuth.
- Confirm mail tools work (e.g.
list_labels,search_threads). - Call
list_filtersorcreate_filter(e.g. criteriafrom: youtube.com, action add a user label + removeINBOX). - Optionally force re-auth (
AuthenticateMcpServerwithforce_reauth) and approve all consent screens again. - Retry
create_filter/list_filters.
Expected
- Filter tools succeed, or
- OAuth consent requests
https://www.googleapis.com/auth/gmail.settings.basicso Linked Apps shows edit/create/change settings & filters, then tools work after re-consent.
Actual
- Tool call error (approx.):
HTTP MCP tool execution failed: … Server returned 403 after trying upscoping - Google Linked Apps for the Cursor app under Gmail includes wording like:
- See (but not change) your email settings
- View your settings (e.g., filters and labels)
- There is no Linked Apps toggle to grant settings write; only delete connection.
- Label create/update and message labeling still work (consistent with
gmail.modify, not settings write).
Why this matters
Without users.settings.filters.*, agents cannot install durable server-side routing (skip Inbox + apply label) and must re-label mail after arrival. The tools being present implies filter management is intended.
API / scope note
Per Gmail API users.settings.filters.create, create requires:
https://www.googleapis.com/auth/gmail.settings.basic
(Gmail scopes: that scope is “See, edit, create, or change your email settings and filters in Gmail.”)
gmail.modify covers labels/messages but not filter settings write — matching the Linked Apps “see but not change” text.
Suggested fix
- Add
gmail.settings.basicto the Gmail plugin OAuth client / consent scope list. - Document that existing users must re-consent after the scope is added.
- Ensure upscoping actually requests that scope (current “403 after trying upscoping” suggests upscope does not obtain write settings).
Workaround
Create filters manually (or via browser automation) in Gmail Settings → Filters and Blocked Addresses until the connector requests the correct scope.
Related (third-party, not Cursor)
Other Gmail MCP projects have discussed the same scope requirement, e.g. needing gmail.settings.basic for filter tools — same underlying Google API constraint.
- Lenguaje dominante
- TypeScript
- Estrellas
- 8.8k
- Forks
- 819
- Merge medio
- 14 h 37 min
- PR fusionados (30 d)
- 66
Preparar el entorno
Este proyecto no incluye contenedor de desarrollo, Dockerfile ni guía de contribución, así que la configuración corre por tu cuenta: empieza por su README y consulta nuestra guía para la primera contribución para los pasos generales.
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de cursor/plugins
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 88/100
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 76/100
Los mantenedores suelen responder en 1 día
-
Dificultad 1/5 Menos de una hora Aptitud para principiantes 88/100
Los mantenedores suelen responder en 1 día
-
Dificultad 1/5 Menos de una hora Aptitud para principiantes 92/100
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 Medio día Aptitud para principiantes 84/100
Los mantenedores suelen responder en 1 día
Todos los issues de cursor/plugins
Issues similares
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 88/100
Los mantenedores suelen responder en 1 día
-
external-issue to-triage
Dificultad 1/5 Menos de una hora Aptitud para principiantes 90/100
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 85/100
diegosouzapw/OmniRoute#15401 ·
Los mantenedores suelen responder en 2 días
-
Sign the pledgeAbierto
Dificultad 1/5 Menos de una hora Aptitud para principiantes 95/100
input-output-hk/devx-updates#163 ·
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 86/100
code-yeongyu/oh-my-openagent#9454 ·
Los mantenedores suelen responder en 1 día