- Google Workspace already connected, with the same Google Cloud project.
- Permission to create Pub/Sub topics and edit their access in that project.
- A public HTTPS address for your AgentSDR (your
BETTER_AUTH_URL) with a valid certificate. Alocalhostinstall cannot receive pushes. - Ability to schedule one daily call to AgentSDR (Production setup).
- About 15 minutes.
Overview
Gmail does not call you when mail arrives, unless you ask it to. AgentSDR asks Gmail to “watch” each connected mailbox’s inbox and publish to a Pub/Sub topic. A push subscription forwards each notification to AgentSDR, which fetches the new messages, matches them to the lead and moves the conversation along in the CRM. A Gmail watch expires after about seven days. Google’s documentation says to callwatch at least every 7 days and recommends once a day. AgentSDR does this when you call its renewal endpoint, so you schedule that endpoint daily (step 5).
Create a topic
agentsdr-gmail. You can untick Add a default subscription, because you create a push subscription in step 4. Click Create topic.The topic’s full name is projects/<project-id>/topics/<topic-id>, for example projects/my-project/topics/agentsdr-gmail. You can copy it from the topic page.
The full topic name under the field is what AgentSDR asks for.
Let Gmail publish to the topic

When the grant is in place, the topic Permissions panel lists the Gmail push account under Pub/Sub Publisher.
Save the topic name in AgentSDR
projects/my-project/topics/agentsdr-gmail. Leave Private key blank to keep the saved key. Click Save. AgentSDR refuses a value that does not match projects/<project>/topics/<topic>.Create a push subscription
agentsdr-gmail-push), select your topic, and set Delivery type to Push. In Endpoint URL enter:<your-domain> with your public address (the same host as BETTER_AUTH_URL). Google requires a publicly reachable HTTPS endpoint with a certificate from a certificate authority. Leave the other options at their defaults and click Create.There is no secret to add. Pub/Sub push cannot carry one, so the endpoint only acts on addresses that are connected mailboxes in AgentSDR and acknowledges everything else. See Pub/Sub push docs.
Choose Push and paste your AgentSDR gmail-watch endpoint.
Schedule the daily watch renewal and run it once
OUTREACH_TICK_SECRET (sent as the x-tick-secret header or ?secret=). Without it the endpoint answers 401. The reply lists each mailbox with ok: true, or an error. Organizations that have no topic saved are listed under skipped with gmail_watch_topic_not_configured. How to schedule it with cron or your host’s scheduler is in Production setup.Check that it works
- Run the renewal call from step 5 and confirm your mailbox shows
"ok": true. - From a different address, reply to an email sent from that mailbox (or just send it a new message).
- Within a short time the message appears in the CRM under Action required or the Email inbox.
localhost) cannot receive pushes, because Google’s servers cannot reach it. Test this on your deployed instance.Troubleshooting
Gmail pub/sub topic must look like projects/<project>/topics/<topic>
Gmail pub/sub topic must look like projects/<project>/topics/<topic>
skipped: gmail_watch_topic_not_configured
skipped: gmail_watch_topic_not_configured
skipped: google_not_connected
skipped: google_not_connected
Replies worked, then stopped after about a week
Replies worked, then stopped after about a week
Pub/Sub shows delivery errors or a growing backlog
Pub/Sub shows delivery errors or a growing backlog
POST should answer 200. Note that AgentSDR answers 200 even for pushes it ignores, so only unreachable endpoints cause retries.