How to Connect Gmail / Google Workspace to Front
Front is built to run email as a shared, collaborative inbox instead of a pile of siloed personal accounts, and Gmail or Google Workspace is the most common source it pulls from. The connection itself takes a few minutes, but the part that trips teams up isn't the setup — it's understanding what the "two-way sync" actually keeps in step and what it quietly does not. This guide walks the native OAuth connect flow step by step, compares it with the older forwarding approach, explains the sync mechanics in plain terms, names the five everyday actions that will not sync between Gmail and Front, and covers the one habit — working the same account in both places at once — that causes the most confusion. Everything below is verified against Front's own help center.
Native OAuth connect vs forwarding
Front gives you two ways to get Gmail into an inbox, and they are not equal. The native Google connection uses OAuth: you authorize Front against your Google account once, and Front reads and sends on your behalf with a proper two-way link. The older forwarding approach simply auto-forwards a copy of incoming mail from Gmail into a Front address — it's a firehose in one direction, with no send-from-your-address and no bidirectional state.
For any real support, sales, or ops team, the native OAuth connection is the right call. Forwarding is a fallback for accounts you genuinely can't OAuth (some locked-down aliases or distribution addresses). If you want the wider picture of how Front models email alongside SMS, chat and social, Front channels explained covers the channel model this fits into.
| Native Google (OAuth) | Forwarding | |
|---|---|---|
| Direction | Two-way (with caveats below) | One-way in |
| Send as your address | Yes | No (replies come from Front) |
| History import | Up to 50K messages | None |
| Gmail labels → Front tags | Yes | No |
| Best for | Real shared/individual inboxes | Aliases you can't OAuth |
Connecting Gmail with OAuth, step by step
Per Front's guide to adding a Gmail account, the native flow lives in your workspace or personal settings under Channels. Here's the full path:
- Open Settings (the gear icon) and choose the workspace (shared) or personal scope.
- Go to Inboxes and create the shared or individual inbox this channel will feed — or open an existing one.
- Click Channels, then Connect channel.
- Choose Google from the channel menu, then pick your account type: Gmail Account (a standard mailbox), Google Group, or Gmail Alias. Click Continue.
- Click Sign in with Google and authenticate. Front requests full Read and Write access — the consent screen reads "Read, compose, send, and permanently delete all your email in Gmail," plus calendar access. Click Allow.
- Choose whether to attach this to an individual or shared inbox, and optionally import history.
Two things worth knowing before you click Allow. First, those broad permissions look alarming, but Front is explicit that it "actually does not have access to and will not permanently delete your emails in Gmail. Front is only able to permanently delete from our own servers." The scope is standard for any OAuth mail client. Second, if you get an admin_policy_enforced error, your Google Workspace admin has locked third-party access — the fix is on the admin side, below.
Google Workspace admin: whitelisting Front
If you're on Google Workspace (not a personal Gmail), a workspace admin may need to trust Front before the OAuth handoff will complete. Front documents two admin-console options: remove restrictions on Google Services entirely, or — the cleaner route — add Front as a Trusted app. In the Google Admin Console, add the app by OAuth Client ID 754490832836, then select "Trusted: App can request access to all Google data." After that, the admin_policy_enforced block clears and teammates can connect their Google channels.
This is also the moment to decide which accounts become Front channels. A collaborative shared inbox — support@, sales@, orders@ — is the classic Front pattern; Front shared inbox explained covers why that model beats forwarding a group address into personal Gmail.
How the two-way sync actually works
This is the section that saves headaches. When you connect a Gmail inbox natively, Front optionally imports up to 50,000 of your most recent messages, newest to oldest, and that import "may take up to 72 hours to finish," per Front's Gmail history import and sync documentation. Gmail labels convert to Front tags, and threading defaults to Gmail's threading model.
But "two-way sync" is narrower than it sounds. Front is blunt about the scope: only new messages received, spam marked/unmarked, and sent messages sync bidirectionally. Everything else you do in the Gmail web UI stays in Gmail. That's not a bug — Front treats the conversation state (read, assigned, archived, snoozed) as Front's source of truth once the channel is live, because a shared inbox has its own workflow that a single Gmail account can't represent.
The 5 actions that break sync
Here's the concrete list. Per Front's sync documentation, these five actions do not sync between Gmail and Front — do them in one system and the other won't reflect it:
- Read / unread status — marking a message read in Gmail won't mark it read in Front, and vice versa.
- Archived / unarchived status — archiving in one place leaves it untouched in the other.
- Tag / label changes — labels you add in Gmail after connecting don't flow to Front tags (only the initial import converts them).
- Trash actions — deleting in Gmail doesn't delete in Front.
- Snooze actions — snoozing is a per-system state and doesn't cross over.
There's one more gotcha that follows directly from this. If you send an email from Gmail directly after connecting, Front documents that "it will sync into your Front inbox as archived" — so that reply won't surface as a new item in Front's Inbox. Your teammates may never see it. This is the single biggest source of "why did we double-reply?" incidents.
Don't keep the account open in both
Put the sync limits together and the operating rule is simple: pick one place to work each conversation, and make it Front. If half your team triages in the Gmail web app and the other half in Front, the read, archive, snooze and label states will drift apart within a day — because none of those states sync. Someone in Gmail archives a "handled" thread; in Front it still looks open and gets picked up again.
Front's docs don't ban parallel access, but the mechanics make the case on their own. Once a Gmail address is a Front channel, treat Gmail as the plumbing and Front as the workspace. Close the Gmail tab for that mailbox. Reserve direct-in-Gmail sending for the rare case, and know it lands archived. If you're evaluating which accounts and tools to route through Front centrally, best Front integrations is a useful map.
The honest limits — and where an AI layer picks up
The native Google connection is genuinely good: real OAuth, send-as-your-address, a large history import, and a dependable one-way inbound flow. For getting email into a collaborative inbox, it's exactly what you want, and it's the reason Front works as a serious home for team email rather than a forwarding hack.
The limits are worth naming honestly. The two-way part is selective — five common actions don't cross over, and direct Gmail sends land archived, so discipline matters. Calendar and some settings still live in Google. And a synced inbox, however tidy, is still just routing: it gets the email to the right shared inbox, but it doesn't read the customer's actual question or answer it.
That last seam is where an AI agent layer fits — not as a replacement for Front, but as reasoning on top of it. The broader category of AI agents for customer service exists for exactly this. Macha is one such layer: it runs on top of the Front you already use through the live Macha–Front connector — it never replaces your Gmail channel, your inboxes, or your workflow. Your native connection keeps doing what it's good at: getting the right email into the right shared inbox with history and tags intact. Then Macha's agent reads that email, understands intent, and drafts or sends a grounded reply — pulling a real order, shipment, or account status through a custom tool that turns your REST API into something the agent can call. A connection syncs the message; the agent actually resolves it. If you want the mechanics, connecting Front to Macha to route conversations to AI walks through it, and Macha's credits are consumed per AI action, never per resolution.
FAQ
How do I connect Gmail to Front? Go to Settings → Channels → Connect channel, choose Google, pick Gmail Account (or Google Group / Gmail Alias), and click Sign in with Google to authorize via OAuth. Grant the Read and Write access Front requests, then attach the channel to a shared or individual inbox and optionally import history.
Does Front have two-way sync with Gmail? Partially. Only new messages received, spam marked/unmarked, and sent messages sync both ways. Read/unread status, archived status, tag changes, trash, and snooze actions do not sync between Gmail and Front, per Front's documentation.
Why does my Gmail-sent email not show in Front's Inbox? Front documents that emails you send directly from Gmail (not through Front) sync into Front as archived, so they won't appear as new in your Inbox. Send from Front to keep the shared inbox accurate.
I get an admin_policy_enforced error connecting Google Workspace. How do I fix it? A Workspace admin must trust Front. In the Google Admin Console, add Front as a Trusted app using OAuth Client ID 754490832836 and select "Trusted: App can request access to all Google data," or remove restrictions on Google Services.
Can I add AI to my Front Gmail inbox without replacing Front? Yes. An AI agent layer like Macha connects to Front as a live connector on top of your existing Gmail channel and inboxes. Your native connection keeps syncing email; the agent reads each conversation, understands intent, and drafts or sends a grounded reply.
Ready to turn a synced Gmail inbox into one that actually answers? Start a free trial of Macha and connect it to your Front in minutes.
Add AI agents to your Front
Macha reads the conversation, drafts the reply and takes the action, inside the Front you already run.
Shopify
Stripe
Slack
Notion
Google Workspace
Confluence

