To connect a Google Workspace mailbox to Instantly, use Instantly's Google OAuth option, authorize its OAuth client in the Google Workspace Admin console, then sign in and consent as the individual mailbox user. An admin can configure app access, but that does not connect every user's mailbox automatically. Instantly says each Google account must be connected separately.
This guide follows Instantly's current connection instructions and Google's app access controls, checked October 1, 2026. It explains the documented workflow; we have not connected a private Workspace account for this article.
Use the right branch: Instantly currently routes Google Workspace accounts through Option 1: OAuth. Its account connection overview routes personal Gmail accounts through Option 2: App password. Microsoft 365 and other IMAP/SMTP providers have different connection paths.
Before you open either dashboard
You need an Instantly workspace where you can add sending accounts, a live Google Workspace mailbox that can sign in to Google, and a Google administrator with the Security settings privilege. Google says that privilege is required to manage app access in the Admin console. If you do not administer the Google tenant, send the admin the Instantly help link and the client ID shown in your current Instantly connection flow; do not ask for the admin password.
The admin should also know which organizational unit contains the mailbox and whether the tenant's policy permits this third-party access. Instantly's walkthrough shows an All users scope and Trusted access. Google also supports selecting specific organizational units. Its definition of Trusted is broad: the app may request access to all Google Workspace services, including restricted services. The Google sign-in consent screen still asks the individual user to grant the permissions requested for that mailbox. Have the admin review the client ID, requested scopes, affected users and organization policy before changing access. If a narrower scope is required, test it with the admin; do not silently broaden access to the whole tenant to get past a block.
OAuth approval is an access decision, not a deliverability check. Connecting a mailbox does not configure its domain's SPF, DKIM or DMARC, validate a prospect list, or establish that messages reach the inbox. Google's sender guidelines still apply. Our SPF, DKIM and DMARC explainer covers the separate authentication job.
Step 1: Start the Google OAuth connection in Instantly
- Open Email Accounts in Instantly and select Add New.
- Choose Connect existing accounts, then Google.
- Select Option 1: OAuth for a Google Workspace mailbox.
- Copy the Client ID shown in that connection flow. Keep the page open while the Workspace admin configures access.
Instantly's July 2026 OAuth article publishes a client ID and says searching for the word “Instantly” is insufficient. Copying the ID from the live flow also lets the admin compare what they are authorizing with the provider's current instructions. A client ID identifies an app; it is not a mailbox password or an authorization token.
Step 2: Have the Workspace admin configure app access
In the Google Workspace Admin console, the admin goes to Security → Access and data control → API controls → Manage App Access → Configure new app. Search for the OAuth Client ID, select the Instantly result, then review its scope and access setting. Instantly says the result is named Instantly OAuth Email v1. Confirm the displayed client ID matches before proceeding.
Instantly's documented path chooses All users and Trusted, then Finish. Google's controls allow the admin to select organizational units when configuring an app, and Instantly's own blocked-app troubleshooting tells admins to check that the mailbox's organizational unit has Trusted access. The correct scope is an administrator policy choice. A mailbox outside the selected unit can remain blocked even when the app appears in the configured-app list.
| Admin check | Why it matters |
|---|---|
| OAuth client ID matches the Instantly flow | App names alone can be ambiguous; Instantly instructs admins to search by ID. |
| Mailbox's organizational unit is included | An app configured for another unit does not necessarily unblock this user. |
| Access type and requested Google scopes are approved | Google's Trusted setting permits requests to restricted services; this deserves a deliberate review. |
| App appears in Configured apps | Confirms the policy was saved before the user retries sign-in. |
Google may show more current labels or controls than Instantly's screenshots. Follow the live Admin console and Google's own app access documentation when a label differs.
Step 3: Connect each mailbox as its Google user
Return to Instantly → Email Accounts → Add New → Connect existing accounts → Google → Option 1: OAuth. Select Login, choose the Google account that owns the sending mailbox, review the requested permissions and select Allow if they match your approved policy. Confirm that the intended address appears in Instantly's Email Accounts list and inspect its connection status there. This is an account-level confirmation, not proof that a campaign can send or that a recipient will receive mail.
For the next mailbox, repeat the Instantly connection flow. If Google's account chooser only displays the admin or a previously signed-in user, select Use another account and sign in as the intended mailbox user. Instantly also suggests an incognito window to avoid stale Google sessions. Do not treat the admin's authorization of the OAuth app as blanket consent for other users' mailboxes.
Fix the specific connection failure
| What you see | First checks | Next action |
|---|---|---|
| “This app is blocked” during Google sign-in | Is the user in this Workspace? Is Instantly OAuth Email v1 configured? Does the selected organizational unit include the user? | Have the admin review app access and the current consent scopes; then retry the OAuth flow. Instantly's blocked-app guide walks through these checks. |
| The right Google account is missing from the chooser | Which Google account is already signed in to the browser? | Select Use another account or retry in an incognito window. Connect each mailbox individually. |
| Account already added in Instantly | Is the address already in this workspace, another workspace you manage, or a previous/expired workspace? | Find the existing connection first. Use Instantly's account-removal guidance or support rather than attempting duplicate connections. |
| The mailbox connects, then shows an error or pause | Is the account status in error, or has the Instantly outreach plan expired? | Follow Instantly's disconnected-account troubleshooting. If a campaign is idle, use the separate campaign-not-sending guide. |
If the organization prohibits the requested access, stop there and involve its administrator. The app-password route in Instantly's current overview is for personal Gmail; it is not an automatic workaround for a Workspace policy decision. Avoid sharing user passwords or bypassing organizational controls.
After the mailbox appears in Instantly
Check three separate layers before launching outreach:
- Connection: The intended mailbox appears in Email Accounts, is active, and has no provider error. Assign it to the intended campaign rather than assuming connection assigns it automatically.
- Sending domain: Confirm domain authentication and policy using Google's sender guidelines. Our email deliverability readiness test checks public signals, with its stated limits; it cannot prove inbox placement.
- Campaign readiness: Confirm the campaign's sending schedule, account-level and campaign-level limits, eligible leads and sequence timing. See why an Instantly campaign may not send for the diagnostic order.
The point of this sequence is to locate the failed layer. Repeating OAuth authorization will not fix a full daily limit or a lead queue with no eligible recipients.
Frequently asked questions
Does a Workspace admin need to connect every inbox?
The admin configures app access. Instantly says each Google account is then connected individually through the OAuth sign-in flow. The user must select the intended Google account and grant the requested access.
Should I paste the client ID from an old tutorial?
Use the client ID displayed in your live Instantly flow and compare it with Instantly's current help article. The admin should verify the selected app and requested scopes before trusting it.
Does connecting through OAuth mean emails will reach the inbox?
No. OAuth authorizes an app to access the account. Sender authentication, Google policy, list quality, campaign settings and recipient systems remain separate variables. No third-party connection can guarantee inbox placement.
OutboundXYZ has a commercial relationship with Instantly. This guide documents setup from current provider and Google instructions; it does not claim a recent private-account test. For the broader purchase decision, read our Instantly.ai review.

