<img height="1" width="1" style="display:none" src="https://www.facebook.com/tr?id=1822615684631785&amp;ev=PageView&amp;noscript=1"/>

Live Updates on the Google OAuth verification process and security audit

Live Updates Google O-Auth

Earlier I wrote about my feelings on Google’s new verification process for sensitive and restricted Gmail API scopes, and here I’ll be posting live updates of GMass’s journey through the process. We’re doing this for the benefit of the thousands of developers that have yet to begin the process, are thinking about the process, or are frustrated with the process.


I finally receive information on the “external alignment” meeting with Leviathan, which will be the first step in the security assessment.

Within minutes I respond and request the first available time slot, which is August 14th at 1 PM PST.


It’s now been 5 days since I sent back the signed contract for Leviathan and haven’t heard anything further, so I follow up.

…and I hear back a few minutes later.


After not hearing back from Leviathan, I followed up on July 23rd, and did receive this response today.

A few minutes later, I received the official proposal. For privacy purposes, I won’t post the proposal here, but suffice it to say, it’s a standard contract with a quote, and there’s nothing specific to the security assessment of GMass in this proposal. The effort is scoped at a 3-day effort at a particular USD rate per day.

I sign and send the contract back on this same day.


After making some substantial security enhancements to our entire infrastructure, I reach out to Leviathan telling them that I’m ready to begin the security assessment.


Bishop Fox updates me again with some more information, including a What to Expect document for the security assessment. This document doesn’t contain any sensitive information, so I’m making it available for download.

I let Bishop Fox know that I’ll be reviewing the information and then letting them know if I want to proceed.


I’m told that the Self Assessment Questionnaire from Bishop Fox has been approved!


My contact at Bishop Fox updates me again on the status of the SAQ approval with Google.

What I find most interesting about this email is the mention of a deadline to have the security assessment scheduled. There’s never been any mention of this in the documentation from Google or my correspondence with the Google OAuth team.


I email Bishop Fox to ask about the approval status of the SAQ (Self Assessment Questionnaire), because it’s been a couple weeks and I haven’t heard anything. If Google approves their use of the SAQ, it lessens my cost of the security assessment.

My contact responds a few hours later.

5/16/19 (update from Google)

Google sent the below email, informing me that if I don’t go through with the security assessment, I’ll lose access to the restricted scopes. It also clarifies one of the prior points of confusion — that if my app is to be used within G Suite domains only, then I don’t have to go through the security assessment. Meaning, if I don’t care about taking on @gmail.com users, then I don’t need to go through with the assessment. The email also asks for confirmation of whether I will be proceeding or not. I have replied confirming my intention to go through with the assessment.

5/9/19 (two quotes arrive from Bishop Fox)

Bishop Fox explains that they are attempting to get approval from Google to satisfy one portion of the requirements via a “Self Assessment Questionnaire” rather than a full deployment review, and policy and procedure review. Of course, I welcome the simpler approach, and I’m waiting to see if this approach is approved.

5/3/19 (later that day)

Bishop Fox acknowledges receipt of the scoping survey.

5/3/19 (I respond to Bishop Fox’s scoping survey)

It took a while to fill out, because of the detailed questions in it.

5/2/19 (Proposal arrives from Leviathan)

I’m impressed with the speed at which Leviathan handles communication. It was just 15 minutes before I got a response to my initial inquiry, and I have a proposal the very next day after our phone call. I’ve been asked not to disclose pricing information, so out of respect for Leviathan, I won’t mention that here.

5/1/19 (Call with Leviathan and follow-up)

I have a short phone call with a rep from Leviathan, where I describe the nature of GMass, its public facing interfaces, and a little about its underlying architecture. Given that GMass does not have an API and is only usable as a Chrome extension, the rep indicates that this will be one of their simpler security assessments and would require 2-3 days of work. After the call, he sends me some information to verify and an NDA, which I send back the next morning.

4/29/19 (several hours later)

Bishop Fox responds within several hours of my email.

4/29/19 (15 minutes later)

Leviathan responds within 15 minutes of my email. We eventually schedule a phone call for mid-next week.

4/29/19 (later in the day)

I reach out to both of the security firms, Leviathan Security and Bishop Fox, that have been approved to conduct the security assessment.

4/29/19 (earlier in the day)

Google denies my request to skip the security assessment.


I respond to the notice asking if I can skip the security assessment if I reduce the Gmail API scopes I’m using for GMass.


I receive a notice from Google that the fun is only now beginning (proceed with security assessment).


(April Fool’s Day — maybe they’ll let me know this has all been a joke?)
I’m told I’m in the final stages of verification.


I respond with my agreement.


Google emails asking me to confirm my agreement with a statement.


I responded with another video.

3/21/19 (a few hours later)

I received an additional request deeming the first video as insufficient.


I receive this request from Google for an additional video.


I respond, letting Google know I’ve made the branding changes they suggested.


After Google presumably watches my video, they respond, asking them to conform to their branding guidelines.

I respond with the requested YouTube video.


Google responds with their request for a YouTube video.

I responded to the ambiguous request from Google.


Received this email with no project ID listed, and given that I manage multiple apps built for Gmail, I didn’t know if this pertained to GMass or not.


I respond to Google’s request for the scope explanation.


Email received from Google asking for an explanation of the need for the full mail.google.com scope

  1. Hi Ajay & team, came across GMass. Looking for information on data security. Per this blog it seems like you are still working through being approved for Google’s new security requirements. If yes, do I need to wait before I use Gmass as there may be a threat to my gmail data if I connect to GMass today?

  2. Great write up! waiting for the next update!
    It’s also not clear how long this assessment is good for, will it be an annual review and what happens when you change the code accessing the gmail api?

  3. This is a wonderful write up, thanks for taking the time to do this.

    Like you, I’ve had to go through the verification process and my heart sank when I first read the obtuse and confusing documentation and came across the 75k fee.

    Fortunately my business falls under the local device only and I managed to get out of the security assessment and only do the video. But I can see how frustrating the whole thing is, you have my sympathies.

  4. I appreciate you taking the time to write this up – it is a frustrating experience to say the least.

    I am curious about the email you received on 4-29. They say “Your callback URL is server (not restricted through users devices ) , and not managed by Google”. That seems to imply if you were using google servers, there would not be a problem.

    And what does the ( not restricted through users devices ) mean? How would a server callback work that was “restricted” and therefor permissible?

    My biggest complaint about this entire new process? Google doesn’t seem to give a fuck. The OAuth board on google is shut down, and you are pushed to stack exchange. Which I guess is fine if you have a code question – but it means you cannot even discuss the security audit or Google’s process – those are all Customer Relations issues. Everytime I’ve tried to discuss the issue there, my posts are closed.

    We pay for gold tier GCP support – who will not answer any OAuth questions, much less provide advice or support on how to navigate this maze. I’m just a bit surprised at how quickly Google just kicked all the indie devs to the curb.

    1. Hey — sorry for the late reply here.

      1. That email on 4/29 — well, I don’t think that means that if I were to be hosted on the Google Cloud, rather than AWS where I am hosted, that I then wouldn’t have to go through the security assessment. I think because of the nature of my application posting OAuth data back to a server outside of the Google environment (for this purpose the Google Cloud is outside of the Google environment), I have to go through the assessment. Perhaps if my app were a Google Apps Script project, that’s what is meant by “managed by Google”.

      2. Yea, I agree. They don’t give a f—. I do find that they do respond to my questions. If you have an email thread going with the OAuth team about the verification and security assessment, and you ask them a question, they will respond in time. Sometimes it takes a week, and sometimes the answer contradicts what you know to be true, so they aren’t putting their smartest people on the front lines.

    1. Hey Mailtrack.io team! Nice to hear from you. See above for the latest updates. I’d love to hear how the process is going for you as well.

  5. Hi,

    Thanks for the post. Do you have an update on this?

    I have been following this post for the past couple of months. Would be great if you can let us know the current status.


  6. Hi Ajay

    Would you be willing to share the steps you took to secure your infrastructure prior to tests/quotes from Leviathan & Bishop Fox?

    We are in the same general boat (AWS & similar gmail scopes used) and I’m looking to get ahead of the situation and make sure we are fully secured to their standards prior to an assessment.

    So far I have modified various ssl & security settings on our webserver and have reached an “A” on a basic external scanning site like:

  7. Hi Ajay,

    I believe one of your inferences in the post on 5/16/19 is wrong – ” , if I don’t care about taking on @gmail.com users, then I don’t need to go through with the assessment. ” . If you uncheck the box corresponding to the the image you attached in that post, then only users of your domain will be able to view and install the application. You will not be able to publish the app to other Gsuite customers as well even if they own their own domain on Gsuite. In our use case, we don’t need to cater to .gmail users. We just want Gsuite users, but it is not possible without assessment. We too are starting the process and your blog is very helpful. Thank you .

    Relatas – Sales Intelligence

Leave a Reply

Your email address will not be published. Required fields are marked *

Try GMass today

It only takes 30 seconds to install it!

Install Now GMass requires Chrome
Share This