Gmail Configuration¶
Configure Gmail for email delivery using OAuth authentication.
Gmail can be used for sending emails via Kensium Point-of-Sale. This guide covers both personal Gmail accounts and Google Workspace business accounts. OAuth authentication is secure -your password is never stored.
Navigation: Settings → Email → Gmail (after selecting Gmail as provider)
Prerequisites¶
Before configuring Gmail, you need:
- Gmail account (personal or Google Workspace)
- Access to Google Cloud Console
- Ability to create OAuth credentials
- Admin access to enable Gmail API
Gmail vs Google Workspace¶
Personal Gmail¶
- Email: your-email@gmail.com
- Setup: Simpler, fewer steps
- Limits: 500 emails/day
- Best for: Testing, small deployments
Google Workspace (Business)¶
- Email: email@yourdomain.com
- Setup: Requires Google Workspace admin
- Limits: Higher (depends on plan)
- Best for: Business deployments, professional use
Setting Up Gmail OAuth¶
Step 1: Create Google Cloud Project¶
- Go to Google Cloud Console
- Click Select a Project (top-left)
- Click NEW PROJECT
- Enter project name: "Kensium Point-of-Sale"
- Click CREATE
- Wait for project to be created
Step 2: Enable Gmail API¶
- In Google Cloud Console
- Search for "Gmail API"
- Click Gmail API from results
- Click ENABLE
- Wait for enablement to complete
Step 3: Create OAuth Credentials¶
- Go to APIs & Services → Credentials
- Click + CREATE CREDENTIALS
- Select OAuth 2.0 Client ID
- Choose Web application (not Desktop)
- Configure Authorized redirect URIs:
- Add:
https://your-pos-url/email/gmail/callback - Replace
your-pos-urlwith actual URL - Click CREATE
- Copy the displayed:
- Client ID
- Client Secret
- Save these securely
Step 4: Configure Scopes¶
- Go to APIs & Services → OAuth consent screen
- Choose External or Internal (if Workspace)
- Fill in required fields:
- App name: "Kensium Point-of-Sale"
- User support email: Your email
- Developer contact: Your email
- Click SAVE AND CONTINUE
- Add scopes:
- Search for "Gmail API"
- Add scope:
https://www.googleapis.com/auth/gmail.send - Click SAVE AND CONTINUE
- Review and finish
Configuring in Kensium Point-of-Sale¶
Step 1: Enter Credentials¶
- Settings → Email → Email Settings
- Select Gmail as provider
- Save
- Settings → Email → Gmail Configuration
Step 2: Enter Gmail Details¶
- Client ID
- Paste from Google Cloud Console
-
Example:
123456789-abc123def456.apps.googleusercontent.com -
Client Secret
- Paste from Google Cloud Console
-
Example:
GOCSPX-abc123def456xyz789... -
Default Sender Email
- Your Gmail address
- Example:
noreply@company.com(if using Workspace) -
Example:
yourname@gmail.com(if personal account) -
Save
Step 3: Authorize Gmail¶
- Click Authorize Gmail Account
- Browser opens Google login screen
- Sign in with your Gmail account
- Grant permission (Kensium Point-of-Sale requests access)
- Browser redirects back to POS
- Authorization complete
Test Connection¶
- Click Send Test Email
- Enter recipient email
- Click Send
- Verify email arrives
Gmail App Passwords (Alternative)¶
If you prefer SMTP over OAuth:
For Personal Gmail¶
- Enable 2-Factor Authentication on Gmail
- Go to App passwords
- Select:
- Windows Computer (or your device)
- Click Generate
- Copy password shown
- Use in SMTP configuration:
- Server:
smtp.gmail.com - Port: 587
- Username: Your Gmail address
- Password: App password generated above
For Google Workspace¶
- Admin manages app passwords
- Contact Google Workspace admin
- Generate app password
- Use in SMTP configuration (same as above)
Using Multiple Gmail Accounts¶
For Multiple Stores¶
If you need different email sender per store:
- Create separate Gmail projects (optional)
- Configure each with its own Client ID/Secret
- Each project maintains own authentication
Switching Accounts¶
- Go to Gmail Configuration
- Clear Refresh Token
- Enter new credentials
- Authorize new account
- Save
This switches to new Gmail account for all emails.
Troubleshooting Gmail¶
"Authorization Failed"¶
Check: - Client ID is correct - Client Secret is correct - Gmail API is enabled - Redirect URI matches exactly - Account has Gmail access
Try: - Redo authorization process - Clear and re-enter credentials - Create new OAuth credentials
"Permission Denied"¶
Check:
- Account has Gmail access
- Scopes include gmail.send
- Account isn't restricted
- OAuth consent configured
Try: - Re-authorize account - Contact Google Workspace admin (if business account)
"Emails Not Sending"¶
Check: - Authorization token is valid (refresh if needed) - Sender email is correct - Email queue shows specific error - Test email works
Try: - Send test email - Reauthorize account - Review Gmail logs
"Quota Exceeded"¶
Gmail has sending limits:
- Personal: 500 emails/24 hours
- Google Workspace: Varies by plan
Solutions: - Wait for quota reset (24 hours) - Use retry policy for queued emails - Upgrade plan for higher limits - Batch emails during off-peak times
Gmail Settings & Policies¶
Default Sender Address¶
- Should be Gmail account used for OAuth
- Can use custom domain if Workspace
- Shown as "From" in emails
Labels & Organization¶
- Emails sent from POS appear in Sent folder
- Can create label for POS emails
- Use filters to organize
Forwarding¶
- Gmail forwarding rules apply
- Can auto-forward POS emails
- Good for archiving/backup
Security Considerations¶
OAuth Advantages¶
- ✅ Password never stored
- ✅ Can revoke access anytime
- ✅ Limited to specific permissions
- ✅ No password reset needed
- ✅ Works across devices
Protecting Credentials¶
- ✅ Keep Client Secret confidential
- ✅ Don't share credentials
- ✅ Use different project per deployment
- ✅ Monitor OAuth app permissions
- ✅ Revoke if compromised
Revoking Access¶
To disconnect Gmail:
- Go to Connected apps
- Find "Kensium Point-of-Sale"
- Click it
- Click REMOVE ACCESS
- Also remove OAuth app from Google Cloud (optional)
Gmail Best Practices¶
- ✅ Use Google Workspace for business (not personal Gmail)
- ✅ Use OAuth (not app password) when available
- ✅ Test configuration immediately
- ✅ Monitor sending quota
- ✅ Keep credentials secure
- ✅ Use descriptive app name in Google Cloud
- ✅ Enable 2FA on Gmail account
- ✅ Monitor email queue for failures
- ✅ Review Gmail spam folder periodically
- ✅ Document configuration for support
Alternatives¶
- SMTP: Use Gmail via SMTP (see SMTP guide)
- Office 365: If using Microsoft 365
- Custom Server: SMTP to your own server