Skip to content

Gemini CLI Workspace Extension wants additional access to your Google Account #86

Description

@AndreSand

Is there a way to skip Gemini CLI Workspace Extension auth after I already gave access to 3 services?

Steps.

  1. $gemini
  2. opens auth Gemini CLI Workspace Extension auth screen
  3. I already gave access to 3 services

Gemini CLI Workspace Extension wants additional access to your Google Account
Image

Activity

  1. allenhutchison commented on Dec 12, 2025

    @allenhutchison
    Contributor

    I'll have to do some research to see if there is a reasonable way to do this. It's happening because these are the scopes requested by the extension for oauth.

  2. jclicky commented on Dec 13, 2025

    @jclicky

    No I don’t believe there’s any way to do this since Google philosophically is encouraging more user-friction structurally in order to surface / enable end-users to selectively whitelist specific scopes. This is also a cya for the developer because it forces anyone running the code to affirmatively authorize specific scopes if malicious code is introduced via any of the granular oath scopes:
    https://workspaceupdates.googleblog.com/2025/01/granular-oauth-consent-in-google-apps-script.html

    So if anything, we can expect more interruptions like this for all apps to re-authorize more discrete scopes beyond those which were authorized previously.

  3. allenhutchison commented on Dec 16, 2025

    @allenhutchison
    Contributor

    @jclicky it's not so much that we are expanding the scopes. In this case, the user has only granted a small number of the requested scopes, and so the next time the application runs it checks to see if it has access to the other scopes it's requesting. I need to find a way to communicate this back to the extension and shut down the the tools that don't have granted scopes.

    I'm sure that we can do this with a configuration in the gemini-extension.json, but I want to look at a few other ways to do this as well.

  4. AndreSand commented on Jan 26, 2026

    @AndreSand
    Author
  5. allenhutchison commented on Mar 3, 2026

    @allenhutchison
    Contributor

    I'm moving forward with a feature that will enable users to control exactly what scopes the extension requests. See #255 for the discussion. I'm closing this issue to centralize the discussion on the proposed solution.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions