Why use custom application registration?
By default, Mail Attachment Downloader signs in to Gmail / Google Workspace using OAuth (sometimes called modern authentication) through Gearmage's built-in Google app. Some Google Workspace organizations restrict or block third-party apps, or apply policies that revoke access to apps they don't own. This can show up as repeated sign-in prompts, lost credentials, or errors such as "Sign in with Google temporarily disabled for this app" or "This app is blocked". This matters most when the program runs unattended as a service (e.g. PRO Server).
A custom application registration lets you use your organization's own Google OAuth client instead. Because the app belongs to your Google Workspace, your administrator controls it, it can be marked Internal (no Google verification needed), and it isn't affected by changes to the built-in app.
When you click on Settings (gear icon) for a given account in the program, you will get the server settings popup. In that popup you should see a Custom App Registration tab. For Google you need two things (there is no Tenant ID for Google):
The user still signs in once through the browser, just like with the built-in app, but the sign-in goes through your own app. If the user's password is changed, Google revokes the existing Gmail access and the user will need to sign in again. That's Google's standard behavior for all apps.
imap.gmail.com) with Use OAuth2 (modern auth) checked. Custom app registrations are not available for POP3.| Scope | Used for |
|---|---|
https://mail.google.com/ | Reading, moving and deleting email over IMAP |
https://www.googleapis.com/auth/userinfo.email | Confirming which account signed in |
https://www.googleapis.com/auth/gmail.send | Only if the program sends email (e.g. forwarding or notifications over SMTP) |
redirect_uri_mismatch error. No redirect URI needs to be entered.Google may only show the full client secret once, when the client is created. Save it somewhere safe. If you lose it, add a new secret to the client (or create a new client) and update it in the program.
Depending on your organization's policies, a Google Workspace administrator may need to do the following in the Google Admin console:
To confirm which app the account is using, click Connection Diagnostics in the server settings popup. It shows whether the custom or built-in app registration is in use, and if a custom app you entered is not being used, it explains why (for example: incomplete entries, POP3, or the Free edition).
| Error or symptom | What to do |
|---|---|
Error 400: redirect_uri_mismatch | The OAuth client isn't a Desktop app. Create a new client with application type Desktop app and use its ID and secret. |
Error 401: invalid_client or deleted_client | The Client ID or Secret is wrong, or the client or secret was deleted. Re-copy them from Google Cloud Console. |
Error 403: org_internal | The app is Internal but the account signing in isn't in your Workspace organization. Sign in with an account from the organization, or use an External app. |
Error 400: admin_policy_enforced / "This app is blocked" | Your Workspace admin needs to mark the app as Trusted (see Allow the app in the Google Workspace Admin console). |
access_denied / "has not completed the Google verification process" | The app is External and in Testing, and the account isn't listed as a test user. Add it under Audience → Test users, or switch the app to Internal. |
| Must sign in again every 7 days | The app is External in Testing status. Switch it to Internal (Workspace accounts) or publish it. |
| IMAP login fails after a successful sign-in | Check that IMAP access is enabled for the user in the Admin console, and that the https://mail.google.com/ scope was added. |
| Custom App Registration tab is disabled | The account uses POP3, OAuth2 is unchecked, or the server isn't Gmail / Google. Switch to IMAP with OAuth2. |
If this continues to fail, try temporarily disabling any antivirus or firewall to rule out connection issues, then send us the details from Connection Diagnostics.