Connecting Google to AVCodex
How to connect the Google integrations, including the Workspace super-admin allowlist for "This app is blocked".
AVCodex has seven Google integrations (Drive, Gmail, Calendar, Tasks, Sheets, Meet, and YouTube) and they all share a single OAuth Client ID. This guide covers how to connect them and, if your end users are on Google Workspace and see "This app is blocked", how their super admin fixes it.
Read this before you deploy any Google integration to a corporate client. It is the most common blocker in the field.
If you or your end users sign in with a personal @gmail.com account, there is no setup. Open the Integrations tab in the builder, click Connect on any Google integration, sign in to Google, and authorize the requested scopes. The integration becomes active immediately.
When an end user on Google Workspace clicks Connect, Google checks whether their Workspace administrator has approved the third-party OAuth app. If the admin policy restricts third-party apps and the Client ID is not on the trusted list, Google rejects the consent screen with:
This app is blocked This app tried to access sensitive info in your Google Account. To keep your account safe, Google blocked this access.
This is not an AVCodex fault, and there is no setting in your app that fixes it. The fix is on the customer's side. Their Workspace super admin needs to add the OAuth Client ID to their trusted-apps list.
Note: This is standard Google Workspace policy, not an unusual extra step. Many Workspace tenants restrict third-party OAuth apps by default to prevent shadow IT. AVCodex is no different from Notion, Zapier, or any other SaaS that integrates with Google. Each one needs to be allowlisted once by the Workspace admin.
When you click Connect on a Google integration in the builder, a "Heads up" notice surfaces the exact Client ID with a Copy button. It looks like:
123456789012-abcdefghijklmnopqrstuvwxyz123456.apps.googleusercontent.com
Forward this Client ID and the steps below to your customer's Google Workspace administrator.
The administrator does this once per Workspace tenant. The same allowlist entry covers all seven Google integrations, since they share one Client ID.
- Sign in to the Google Admin Console with super-admin permissions. A regular Workspace user account cannot make this change.
- Go to Security > Access and data control > API controls.
- Open the third-party app access manager.
- Add the Client ID as a configured, trusted app.
- Save. The change generally takes effect within a few minutes.
Do not discover this on go-live day. Two things to do up front:
- Ask during discovery whether the client's Workspace restricts third-party OAuth apps. Most enterprise tenants do. If the answer is yes or unknown, get the super admin's name into the project plan early.
- Send the Client ID and the five steps above as a single pre-written email to the client's IT contact. The change takes an admin about two minutes. Waiting on a ticket queue to find out takes about two weeks.
If the client refuses to allowlist third-party OAuth apps at all, which does happen in regulated environments, the fallback is to avoid Google integrations entirely and pull the same data through a custom MCP server on infrastructure the client already trusts. See Building Custom MCP Servers.
*AVCodex · Your AV expertise. Amplified by AI.*