by langgenius · v0.1.1
Gmail push notifications trigger provider for Dify.
This community listing does not yet include every recommended support, privacy, pricing, and permission disclosure. Review the available package permissions before installing.
Available inside your emploidai workspace after installation.
Available inside your emploidai workspace after installation.
Gmail Trigger (Push + History)
Overview
gmail_message_added (new messages)gmail_message_deleted (deleted messages)gmail_label_added (labels added to messages)gmail_label_removed (labels removed from messages)Prerequisites
Step-by-step Setup
.difypkg, import it in Dify’s Plugin Center (Plugins → Import).pyproject.toml / uv.lock first (for example, uv sync --project .) so the runtime uses the locked dependencies.Create or select the Google Cloud project that will host your Pub/Sub resources. Make sure the following APIs are enabled (APIs & Services → Library):
Create a dedicated service account and grant Pub/Sub permissions:
Go to IAM & Admin → Service Accounts → Create Service Account.
Console URL: https://console.cloud.google.com/iam-admin/serviceaccounts
Screenshot:
Assign the roles/pubsub.admin role to this service account or select "Pub/Sub Admin" role which already includes the necessary permissions (required so the plugin can create topics, subscriptions, and update IAM policies automatically).
Create a JSON key for this service account and download it securely. Screenshot:
Note your Google Cloud Project ID (displayed on the project dashboard or IAM page).
In Google Cloud Console → APIs & Services → Credentials → Create Credentials → OAuth client ID.
Console URL: https://console.cloud.google.com/apis/credentials
Screenshot:
https://<your-dify-host>/console/api/plugin/oauth/callback)Capture the generated Client ID and Client Secret for later use.
client_id: The OAuth client ID created above.client_secret: The corresponding client secret.gcp_project_id: The Google Cloud project ID with Pub/Sub enabled.gcp_service_account_json: Paste the full JSON key created for the service account (keep it private).label_ids (optional): Scope to specific labels (INBOX, UNREAD, etc.)
require_oidc: Enforce OIDC bearer verificationoidc_audience: Webhook endpoint URL (auto-filled)oidc_service_account_email: Service account used for Push subscriptionWhat happens automatically:
users.watch API to start monitoringWhere To Get OIDC Values
oidc_audience
https://<your-dify-host>/triggers/plugin/<subscription-id>audience claim: see the OIDC token reference.oidc_service_account_email
--push-auth-service-account).gcloud iam service-accounts list --format='value(email)'How It Works
message.data to get historyId/emailAddressusers.history.list(startHistoryId=...) once to gather deltasgmail_message_added fetches full message metadata (headers, attachments meta)output_schemaEvent Outputs (high-level)
gmail_message_added
history_id: stringmessages[]: id, threadId, internalDate, snippet, sizeEstimate, labelIds, headers{From,To,Subject,Date,Message-Id}, has_attachments, attachments[]gmail_message_deleted
history_id: stringmessages[]: id, threadIdgmail_label_added / gmail_label_removed
history_id: stringchanges[]: id, threadId, labelIdsAttachment Handling
attachmentId or inline content), skipping individual files larger than 5 MiB.attachments[].file_url is the only externally exposed download address; attachments[].file_source identifies its origin (gmail for original links or dify_storage for Dify mirror).upload_file_id and original_url (Gmail/Drive original address) are returned; if not mirrored, original_url is omitted.file_url, determining whether to access Gmail/Drive directly or go through Dify storage based on file_source.Lifecycle & Refresh
users.watch with topicName and optional labelIdsusers.watch is called again before expiry (Gmail watch is time-limited, ~7 days)users.stop and cleans up the Push subscriptionTesting
gmail_message_addedgmail_message_deletedTroubleshooting
historyId out of date: Plugin resets checkpoint to the latest notification and skips the batchReferences