Skip to content

Gmail Configuration

Configure Gmail for email delivery using OAuth authentication.

Gmail can be used for sending emails via Kensium Point-of-Sale. This guide covers both personal Gmail accounts and Google Workspace business accounts. OAuth authentication is secure -your password is never stored.

Navigation: Settings → Email → Gmail (after selecting Gmail as provider)

Prerequisites

Before configuring Gmail, you need:

  • Gmail account (personal or Google Workspace)
  • Access to Google Cloud Console
  • Ability to create OAuth credentials
  • Admin access to enable Gmail API

Gmail vs Google Workspace

Personal Gmail

  • Email: your-email@gmail.com
  • Setup: Simpler, fewer steps
  • Limits: 500 emails/day
  • Best for: Testing, small deployments

Google Workspace (Business)

  • Email: email@yourdomain.com
  • Setup: Requires Google Workspace admin
  • Limits: Higher (depends on plan)
  • Best for: Business deployments, professional use

Setting Up Gmail OAuth

Step 1: Create Google Cloud Project

  1. Go to Google Cloud Console
  2. Click Select a Project (top-left)
  3. Click NEW PROJECT
  4. Enter project name: "Kensium Point-of-Sale"
  5. Click CREATE
  6. Wait for project to be created

Step 2: Enable Gmail API

  1. In Google Cloud Console
  2. Search for "Gmail API"
  3. Click Gmail API from results
  4. Click ENABLE
  5. Wait for enablement to complete

Step 3: Create OAuth Credentials

  1. Go to APIs & Services → Credentials
  2. Click + CREATE CREDENTIALS
  3. Select OAuth 2.0 Client ID
  4. Choose Web application (not Desktop)
  5. Configure Authorized redirect URIs:
  6. Add: https://your-pos-url/email/gmail/callback
  7. Replace your-pos-url with actual URL
  8. Click CREATE
  9. Copy the displayed:
  10. Client ID
  11. Client Secret
  12. Save these securely

Step 4: Configure Scopes

  1. Go to APIs & Services → OAuth consent screen
  2. Choose External or Internal (if Workspace)
  3. Fill in required fields:
  4. App name: "Kensium Point-of-Sale"
  5. User support email: Your email
  6. Developer contact: Your email
  7. Click SAVE AND CONTINUE
  8. Add scopes:
  9. Search for "Gmail API"
  10. Add scope: https://www.googleapis.com/auth/gmail.send
  11. Click SAVE AND CONTINUE
  12. Review and finish

Configuring in Kensium Point-of-Sale

Step 1: Enter Credentials

  1. Settings → Email → Email Settings
  2. Select Gmail as provider
  3. Save
  4. Settings → Email → Gmail Configuration

Step 2: Enter Gmail Details

  1. Client ID
  2. Paste from Google Cloud Console
  3. Example: 123456789-abc123def456.apps.googleusercontent.com

  4. Client Secret

  5. Paste from Google Cloud Console
  6. Example: GOCSPX-abc123def456xyz789...

  7. Default Sender Email

  8. Your Gmail address
  9. Example: noreply@company.com (if using Workspace)
  10. Example: yourname@gmail.com (if personal account)

  11. Save

Step 3: Authorize Gmail

  1. Click Authorize Gmail Account
  2. Browser opens Google login screen
  3. Sign in with your Gmail account
  4. Grant permission (Kensium Point-of-Sale requests access)
  5. Browser redirects back to POS
  6. Authorization complete

Test Connection

  1. Click Send Test Email
  2. Enter recipient email
  3. Click Send
  4. Verify email arrives

Gmail App Passwords (Alternative)

If you prefer SMTP over OAuth:

For Personal Gmail

  1. Enable 2-Factor Authentication on Gmail
  2. Go to App passwords
  3. Select:
  4. Mail
  5. Windows Computer (or your device)
  6. Click Generate
  7. Copy password shown
  8. Use in SMTP configuration:
  9. Server: smtp.gmail.com
  10. Port: 587
  11. Username: Your Gmail address
  12. Password: App password generated above

For Google Workspace

  1. Admin manages app passwords
  2. Contact Google Workspace admin
  3. Generate app password
  4. Use in SMTP configuration (same as above)

Using Multiple Gmail Accounts

For Multiple Stores

If you need different email sender per store:

  1. Create separate Gmail projects (optional)
  2. Configure each with its own Client ID/Secret
  3. Each project maintains own authentication

Switching Accounts

  1. Go to Gmail Configuration
  2. Clear Refresh Token
  3. Enter new credentials
  4. Authorize new account
  5. Save

This switches to new Gmail account for all emails.

Troubleshooting Gmail

"Authorization Failed"

Check: - Client ID is correct - Client Secret is correct - Gmail API is enabled - Redirect URI matches exactly - Account has Gmail access

Try: - Redo authorization process - Clear and re-enter credentials - Create new OAuth credentials

"Permission Denied"

Check: - Account has Gmail access - Scopes include gmail.send - Account isn't restricted - OAuth consent configured

Try: - Re-authorize account - Contact Google Workspace admin (if business account)

"Emails Not Sending"

Check: - Authorization token is valid (refresh if needed) - Sender email is correct - Email queue shows specific error - Test email works

Try: - Send test email - Reauthorize account - Review Gmail logs

"Quota Exceeded"

Gmail has sending limits:

  • Personal: 500 emails/24 hours
  • Google Workspace: Varies by plan

Solutions: - Wait for quota reset (24 hours) - Use retry policy for queued emails - Upgrade plan for higher limits - Batch emails during off-peak times

Gmail Settings & Policies

Default Sender Address

  • Should be Gmail account used for OAuth
  • Can use custom domain if Workspace
  • Shown as "From" in emails

Labels & Organization

  • Emails sent from POS appear in Sent folder
  • Can create label for POS emails
  • Use filters to organize

Forwarding

  • Gmail forwarding rules apply
  • Can auto-forward POS emails
  • Good for archiving/backup

Security Considerations

OAuth Advantages

  • ✅ Password never stored
  • ✅ Can revoke access anytime
  • ✅ Limited to specific permissions
  • ✅ No password reset needed
  • ✅ Works across devices

Protecting Credentials

  • ✅ Keep Client Secret confidential
  • ✅ Don't share credentials
  • ✅ Use different project per deployment
  • ✅ Monitor OAuth app permissions
  • ✅ Revoke if compromised

Revoking Access

To disconnect Gmail:

  1. Go to Connected apps
  2. Find "Kensium Point-of-Sale"
  3. Click it
  4. Click REMOVE ACCESS
  5. Also remove OAuth app from Google Cloud (optional)

Gmail Best Practices

  • ✅ Use Google Workspace for business (not personal Gmail)
  • ✅ Use OAuth (not app password) when available
  • ✅ Test configuration immediately
  • ✅ Monitor sending quota
  • ✅ Keep credentials secure
  • ✅ Use descriptive app name in Google Cloud
  • ✅ Enable 2FA on Gmail account
  • ✅ Monitor email queue for failures
  • ✅ Review Gmail spam folder periodically
  • ✅ Document configuration for support

Alternatives

  • SMTP: Use Gmail via SMTP (see SMTP guide)
  • Office 365: If using Microsoft 365
  • Custom Server: SMTP to your own server