Someone posted a Gmail automation tutorial on Hacker News last week, and I made the mistake of following along. Step 1: create a Google Cloud project. Step 2: enable the Gmail API. Step 3: configure the OAuth consent screen. By step 14 you had a working script that could read your inbox and draft a reply. The top comment nailed it: “I spent longer on the OAuth setup than I would have spent just answering the emails.”

That pretty much captures where Gmail AI productivity sits in 2026. Every tutorial, every tool, every “hack” assumes you’re willing to either grant a third-party app deep access to your email through OAuth or manually copy-paste threads into ChatGPT like it is 2023.

What OAuth actually costs you

The people building Gmail AI tools have no incentive to talk about security, so nobody does. When you authorize an app via OAuth, you typically grant permissions that go well beyond what it actually needs. Most request gmail.modify or gmail.readonly scopes, and that means the app can read every email in your account, not just the threads you wanted help with.

Google published an update to their API abuse policy in January 2026 after discovering that several popular Gmail productivity extensions were storing email content on their own servers for “model improvement.” Your private correspondence, silently repurposed as training data, because you clicked through a permissions dialog without reading it. And even when the developer is acting in good faith, the OAuth token itself becomes a target. If their infrastructure gets breached, your Gmail access goes with it.

Martin Fowler wrote about the lethal trifecta of agentic email last month: untrusted content, sensitive information, external communication. OAuth-based Gmail tools hit all three.

Your tab is already logged in

Your browser tab is authenticated right now. You logged into Gmail this morning and probably did not think about it because your session persists across restarts. So a Chrome extension that reads the active tab can access your inbox without touching Google’s API, without requesting OAuth scopes, without storing a single token anywhere.

Dassi works exactly like this. It sits in Chrome’s side panel and interacts with Gmail through the page DOM, inheriting your existing session, seeing what you see. No cloud browser spinning up a fresh instance, no credential relay bouncing your data through someone else’s infrastructure.

What this looks like for replying to a thread

I had a client thread last week with six back-and-forth messages about a project timeline, and I wanted to test both approaches side by side. The copy-paste route meant selecting the thread, pasting it into ChatGPT, writing a prompt asking for a polite reply confirming the new deadline, copying the output, switching back to Gmail, pasting it into compose, and then editing it because ChatGPT botched my tone without the earlier context. Maybe ten minutes total, counting all the tab-switching and cleanup.

With the browser agent I just opened the sidebar, typed “draft a reply confirming we can meet the March 31 deadline and ask about the deliverables format,” and it read the full thread right there in the tab. Draft appeared in the compose field with context intact. One sentence adjusted, sent. Forty seconds.

The boring stuff saves more time

Drafting replies gets all the attention. But the real time sink is the unsexy triage work: skimming 30 newsletters to find three worth reading, pulling tracking numbers from shipping confirmations into a spreadsheet, labeling a week of client emails by project name.

OAuth tools handle these through batch API calls. Powerful, sure, but that requires the whole setup dance and the ongoing security exposure. A browser agent does them through the UI one at a time, which is slower per individual operation but needs zero configuration. For someone doing email triage once or twice a day, that per-operation speed difference is damn near irrelevant.

Same models, less plumbing

The AI doing the actual work is identical either way. If you use your ChatGPT subscription through a browser agent or connect your own Claude API key, you get the same GPT-5.2 or Sonnet output any OAuth tool would produce.

So the difference comes down to plumbing. OAuth means API tokens, server-side storage, third-party data handling, and a permissions model designed for developer integrations. Browser-agent plumbing means your local tab, your local extension, a direct call to whatever LLM provider you already trust. Bring your own key, keep your own data. And maybe spend those 14 setup steps on something that actually needs your attention.