{"id":10845,"date":"2020-01-05T04:41:52","date_gmt":"2020-01-05T04:41:52","guid":{"rendered":"https:\/\/www.gmass.co\/blog\/?p=10845"},"modified":"2020-01-31T01:59:53","modified_gmt":"2020-01-31T01:59:53","slug":"five-annoying-issues-google-oauth-scope-verification","status":"publish","type":"post","link":"https:\/\/www.gmass.co\/blog\/five-annoying-issues-google-oauth-scope-verification\/","title":{"rendered":"Five annoying issues with Google&#8217;s OAuth Scope Verification"},"content":{"rendered":"<p>It&#8217;s 2020, when Google promised to shut off many third-party apps that weren&#8217;t verified by December 31, 2019. While I haven&#8217;t heard any reports of anyone being shut off yet, having been through <a href=\"https:\/\/www.gmass.co\/blog\/live-updates-google-oauth-verification-security\/\">Google&#8217;s OAuth verification process<\/a>, and having run some Unverified Apps, I&#8217;ve learned the ins and outs of the whole process. All of these insights I&#8217;ve concluded on my own, thanks to Google&#8217;s insufficient documentation.<\/p>\n<h3>1. There&#8217;s no hierarchy to the API Scopes, and that&#8217;s just ridiculous<\/h3>\n<p>Let&#8217;s say you&#8217;ve been approved for the almighty <strong>https:\/\/mail.google.com<\/strong> Gmail API scope, which gives you full access to read, write, and delete data in a user&#8217;s Gmail account. Then later, you realize you don&#8217;t need this almighty scope \u2014 you <strong>determine you just need modify-only access<\/strong> to Gmail. You also want the benefit of a less scary warning for your user. You might think that you can just switch your OAuth code to use the less permissive scope, <strong>https:\/\/www.googleapis.com\/auth\/gmail.modify<\/strong>, and you&#8217;ll be good to go. <em>That makes logical sense, after all.<\/em><\/p>\n<p>But you&#8217;ll be shocked to learn that you&#8217;ve just re-entered &#8220;Unverified App&#8221; territory.<\/p>\n<p><a href=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/001-This-app-isnt-verified-25kb.png\" data-rel=\"lightbox-image-0\" data-rl_title=\"\" data-rl_caption=\"\" title=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-11062\" src=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/001-This-app-isnt-verified-25kb.png\" alt=\"\" width=\"538\" height=\"284\" srcset=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/001-This-app-isnt-verified-25kb.png 1152w, https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/001-This-app-isnt-verified-25kb-300x158.png 300w, https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/001-This-app-isnt-verified-25kb-768x405.png 768w, https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/001-This-app-isnt-verified-25kb-1024x540.png 1024w, https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/001-This-app-isnt-verified-25kb-24x13.png 24w, https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/001-This-app-isnt-verified-25kb-36x19.png 36w, https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/001-This-app-isnt-verified-25kb-48x25.png 48w\" sizes=\"auto, (max-width: 538px) 100vw, 538px\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>That&#8217;s right. Internally, Google doesn&#8217;t know that if you&#8217;ve been approved for the mail.google.com scope, which covers everything, you should also be approved for the &#8220;modify&#8221; scope, which grants a subset of permissions of the mail.google.com scope. There&#8217;s no hierarchy to the scopes as far as Google is concerned, which is absolutely ridiculous given that Google&#8217;s main business is to organize the world&#8217;s information. Funny that Google is so good at organizing trillions of web pages but is terrible at organizing a few hundred of its own API scopes.<\/p>\n<h3>2. Where exactly do you designate the scopes you want to use?<\/h3>\n<p>The whole OAuth process might be confusing to you because you&#8217;ve likely noticed that there are three places to specify the API libraries you want access:<\/p>\n<ol>\n<li>In the Cloud Console, under the <strong>API Library<\/strong> section<\/li>\n<li>In the Cloud Console, under your specific OAuth consent screen<\/li>\n<li>In your code where you hit the Google OAuth2 endpoint<\/li>\n<\/ol>\n<p>So which list is most important? Do you have to specify the scopes in the Cloud Console consent screen settings for your code to request access to that scope for a user? <em>No, you don&#8217;t.<\/em><\/p>\n<p>Here&#8217;s an example. In the Cloud Console for my GMass app, here&#8217;s the list of <strong>Enabled APIs<\/strong>:<\/p>\n<p><a href=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/002-Enabled-APIs-on-Cloud-Console-56kb.png\" data-rel=\"lightbox-image-1\" data-rl_title=\"\" data-rl_caption=\"\" title=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-11063\" src=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/002-Enabled-APIs-on-Cloud-Console-56kb.png\" alt=\"\" width=\"694\" height=\"694\" srcset=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/002-Enabled-APIs-on-Cloud-Console-56kb.png 1224w, https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/002-Enabled-APIs-on-Cloud-Console-56kb-150x150.png 150w, https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/002-Enabled-APIs-on-Cloud-Console-56kb-300x300.png 300w, https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/002-Enabled-APIs-on-Cloud-Console-56kb-768x768.png 768w, https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/002-Enabled-APIs-on-Cloud-Console-56kb-1024x1024.png 1024w, https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/002-Enabled-APIs-on-Cloud-Console-56kb-24x24.png 24w, https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/002-Enabled-APIs-on-Cloud-Console-56kb-36x36.png 36w, https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/002-Enabled-APIs-on-Cloud-Console-56kb-48x48.png 48w\" sizes=\"auto, (max-width: 694px) 100vw, 694px\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>My OAuth client consent screen lists these scopes:<\/p>\n<p><a href=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/003-OAuth-scopes-24kb.png\" data-rel=\"lightbox-image-2\" data-rl_title=\"\" data-rl_caption=\"\" title=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-10883\" src=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/003-OAuth-scopes-24kb.png\" alt=\"\" width=\"541\" height=\"422\" srcset=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/003-OAuth-scopes-24kb.png 964w, https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/003-OAuth-scopes-24kb-300x234.png 300w, https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/003-OAuth-scopes-24kb-768x599.png 768w, https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/003-OAuth-scopes-24kb-24x19.png 24w, https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/003-OAuth-scopes-24kb-36x28.png 36w, https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/003-OAuth-scopes-24kb-48x37.png 48w\" sizes=\"auto, (max-width: 541px) 100vw, 541px\" \/><\/a><\/p>\n<p>In code, I can request access to a scope that&#8217;s not listed in either the Dashboard or my OAuth client page, and it might still work, depending on the scope that I add. For example, I can add the <strong>&#8220;https:\/\/www.googleapis.com\/auth\/genomics&#8221;<\/strong> scope, which has nothing to do with my project, and the user can still authenticate but IS presented with the Unverified App screen.<\/p>\n<pre class=\"brush: csharp; title: ; notranslate\" title=\"\">\r\n        private static readonly string[] GMass_Scopes = new[] {\r\n        &quot;https:\/\/mail.google.com&quot;,\r\n        &quot;https:\/\/www.googleapis.com\/auth\/userinfo.email&quot;,\r\n        &quot;https:\/\/spreadsheets.google.com\/feeds&quot;,\r\n        &quot;https:\/\/www.googleapis.com\/auth\/genomics&quot;\r\n        };\r\n\r\n        public ActionResult Login(string redir = null, bool connect = false, string emailaddress = &quot;&quot;, string source = &quot;extension&quot;)\r\n        {\r\n            OAuthState state = new OAuthState\r\n            {\r\n                Connect = connect,\r\n                Redir = redir,\r\n                Source = source\r\n            };\r\n\r\n            UriBuilder uri = new UriBuilder();\r\n            uri.Scheme = &quot;https:&quot;;\r\n            uri.Host = &quot;accounts.google.com&quot;;\r\n            uri.Path = &quot;\/o\/oauth2\/auth&quot;;\r\n\r\n            var qs = HttpUtility.ParseQueryString(&quot;&quot;);\r\n            if (emailaddress != &quot;&quot;)\r\n            {\r\n                qs[&quot;login_hint&quot;] = emailaddress;\r\n            }\r\n            qs[&quot;access_type&quot;] = &quot;offline&quot;;\r\n            qs[&quot;response_type&quot;] = &quot;code&quot;;\r\n            qs[&quot;approval_prompt&quot;] = &quot;force&quot;;\r\n            qs[&quot;client_id&quot;] = OAuthHelper.ClientSecrets.ClientId;\r\n            qs[&quot;redirect_uri&quot;] = &quot;https:\/\/extension.gmass.co\/OAuth\/AuthCallback&quot;;\r\n            qs[&quot;scope&quot;] = string.Join(&quot; &quot;, GMass_Scopes);\r\n            qs[&quot;state&quot;] = JsonConvert.SerializeObject(state);\r\n            uri.Query = qs.ToString();\r\n\r\n            return Redirect(uri.ToString());\r\n        }\r\n<\/pre>\n<p>But, if I add the <strong>&#8220;https:\/\/www.googleapis.com\/auth\/drive.file&#8221;<\/strong> scope, also which is <strong>not enabled in Cloud Console&#8217;s API Library<\/strong> and <strong>not listed as part of my OAuth consent screen<\/strong>, then the user sails right through when logging in, and does not see the <strong>Unverified App<\/strong> screen. The &#8220;genomics&#8221; API isn&#8217;t documented as sensitive or restricted, so this difference doesn&#8217;t really make sense.<\/p>\n<p>The rules are as follows:<\/p>\n<ul>\n<li>An API scope only needs to be listed as part of your OAuth consent screen if it requires verification to be used. And to even get it to appear on this settings page, the API Library for that scope needs to be enabled.<\/li>\n<li>If an OAuth scope does not require verification, or you choose to go Unverified, then the scope does not need to be listed on the Consent Screen settings, and your code can still request use of the scope, as I requested the use of the genomics scope in my code sample above.<\/li>\n<li>If your code doesn&#8217;t request access to a scope, and then attempts to use the API for that scope, you&#8217;ll get this error from Google:\n<pre class=\"brush: csharp; title: ; notranslate\" title=\"\">Google.Apis.Requests.RequestError\\r\\nInsufficient Permissions: Request had insufficient authentication scopes.<\/pre>\n<\/li>\n<li>If your code does request access to a scope, is granted access by the user, and then attempts to call an API for that scope, you will get an error if the API Library isn&#8217;t enabled in the Cloud Console.<\/li>\n<\/ul>\n<p>The conclusion is that the scope need not be listed on your consent screen settings in order for you to request it, but the API Library does need to be enabled in order for your code to use the API once consent is granted by the user.<\/p>\n<p><span style=\"color: #0000ff;\"><strong>Bonus: What happens if your app has been verified and you need to add a scope later?<\/strong><\/span><\/p>\n<p>I contacted the Google OAuth team and asked them this very question. Here is the answer:<\/p>\n<p><a href=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/015-scope-approval-inquiry-145kb.png\" data-rel=\"lightbox-image-3\" data-rl_title=\"\" data-rl_caption=\"\" title=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-11044\" src=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/015-scope-approval-inquiry-145kb.png\" alt=\"\" width=\"794\" height=\"1461\" srcset=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/015-scope-approval-inquiry-145kb.png 1208w, https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/015-scope-approval-inquiry-145kb-163x300.png 163w, https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/015-scope-approval-inquiry-145kb-768x1414.png 768w, https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/015-scope-approval-inquiry-145kb-556x1024.png 556w, https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/015-scope-approval-inquiry-145kb-13x24.png 13w, https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/015-scope-approval-inquiry-145kb-20x36.png 20w, https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/015-scope-approval-inquiry-145kb-26x48.png 26w\" sizes=\"auto, (max-width: 794px) 100vw, 794px\" \/><\/a><\/p>\n<p>The steps to add a scope later are:<\/p>\n<ol>\n<li>Add the scope to your OAuth consent screen, and hit either &#8220;Save&#8221; or &#8220;Submit for Verification&#8221; if it&#8217;s a sensitive or restricted scope.<\/li>\n<li>The scope will now appear with the yellow warning sign.<\/li>\n<li>Do not modify your production code to use the scope. As long as your production code only requests the scopes that have been approved, your users won&#8217;t see the <strong>Unverified<\/strong> app screen. So, just the act of adding a scope to your consent screen doesn&#8217;t alter what your user sees when going through the OAuth flow.<\/li>\n<li>You&#8217;ll likely be contacted by the OAuth team <strong>requesting a YouTube video<\/strong> demonstrating the necessity for the new scope.<\/li>\n<li>After you answer their questions and are approved for the new scope, then it will show up as green in the consent screen settings, and only then should you add the scope to your production code OAuth flow.<\/li>\n<\/ol>\n<h3>3. Sensitive Scope? Restricted Scope? Google&#8217;s documentation is god-awful.<\/h3>\n<p>In the <a href=\"https:\/\/support.google.com\/cloud\/answer\/9110914?hl=en\">OAuth Verification FAQ<\/a>, Google discusses sensitive scopes vs. restricted scopes. Yet while the genius who wrote this listed the <strong>restricted scopes<\/strong>, he did not list the <strong>sensitive scopes<\/strong>. In response to the question <strong>&#8220;What are sensitive API scopes?&#8221;<\/strong>, the page says:<\/p>\n<blockquote><p>Sensitive scopes allow access to Google User Data. If an app uses sensitive scopes, it must comply with the\u00a0<a href=\"https:\/\/developers.google.com\/terms\/api-services-user-data-policy\">Google API User Data Policy<\/a>\u00a0and have its OAuth consent screen configuration verified by Google.<\/p>\n<p>The app verification process can take anywhere from 3 to 5 business days.<\/p><\/blockquote>\n<p>To add to the confusion, in the Cloud Console, you might see this for your project under the &#8220;OAuth consent screen&#8221; settings:<\/p>\n<p><a href=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/004-OAuth-consent-screen-v2-64kb.png\" data-rel=\"lightbox-image-4\" data-rl_title=\"\" data-rl_caption=\"\" title=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-10899 size-full\" src=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/004-OAuth-consent-screen-v2-64kb.png\" alt=\"\" width=\"524\" height=\"1220\" srcset=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/004-OAuth-consent-screen-v2-64kb.png 524w, https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/004-OAuth-consent-screen-v2-64kb-129x300.png 129w, https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/004-OAuth-consent-screen-v2-64kb-440x1024.png 440w, https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/004-OAuth-consent-screen-v2-64kb-10x24.png 10w, https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/004-OAuth-consent-screen-v2-64kb-15x36.png 15w, https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/004-OAuth-consent-screen-v2-64kb-21x48.png 21w\" sizes=\"auto, (max-width: 524px) 100vw, 524px\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>Notice Google&#8217;s mistake here? They&#8217;ve flagged the <strong>gmail.insert<\/strong> and <strong>gmail.readonly<\/strong> scopes as &#8220;sensitive scopes,&#8221; except that they&#8217;re <em>not actually sensitive scopes<\/em>. They are <strong>&#8220;restricted scopes,&#8221;<\/strong> according to the FAQ. If that&#8217;s not enough, in Google&#8217;s own <a href=\"https:\/\/developers.google.com\/identity\/protocols\/googlescopes\">master scope documentation<\/a>, where all the Gmail API scopes are listed, there&#8217;s not a single mention of some of them being <strong>sensitive<\/strong> or <strong>restricted<\/strong>.<\/p>\n<p><a href=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/005-Google-Scope-List-169kb.png\" data-rel=\"lightbox-image-5\" data-rl_title=\"\" data-rl_caption=\"\" title=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-10885\" src=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/005-Google-Scope-List-169kb.png\" alt=\"\" width=\"666\" height=\"886\" srcset=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/005-Google-Scope-List-169kb.png 908w, https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/005-Google-Scope-List-169kb-225x300.png 225w, https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/005-Google-Scope-List-169kb-768x1022.png 768w, https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/005-Google-Scope-List-169kb-770x1024.png 770w, https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/005-Google-Scope-List-169kb-18x24.png 18w, https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/005-Google-Scope-List-169kb-27x36.png 27w, https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/005-Google-Scope-List-169kb-36x48.png 36w\" sizes=\"auto, (max-width: 666px) 100vw, 666px\" \/><\/a><\/p>\n<p>You might think the main scope list would be the perfect place to specify what&#8217;s sensitive, restricted, or neither, but you&#8217;d be wrong.<\/p>\n<p>There is one place where you can definitely tell whether a scope is sensitive or restricted, and it&#8217;s <a href=\"https:\/\/developers.google.com\/gmail\/api\/auth\/scopes\">here<\/a>. All other Google pages fail to tell you, or they give you incorrect information.<\/p>\n<h3>4. Want to mark your app as &#8220;Internal Only?&#8221; There&#8217;s a bug in the Cloud Console.<\/h3>\n<p>The docs say that an owner of a Cloud Console project can mark it &#8220;Internal Only,&#8221; but I haven&#8217;t found that to be the case. In one of my currently Unverified Apps, SearchMyEmail.com, the ability to set the project INTERNAL is disabled, telling me that I can&#8217;t mark it INTERNAL because I&#8217;m not a G Suite user.<\/p>\n<p><a href=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/006-Internal-Only-User-Type-95kb.png\" data-rel=\"lightbox-image-6\" data-rl_title=\"\" data-rl_caption=\"\" title=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-10887\" src=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/006-Internal-Only-User-Type-95kb.png\" alt=\"\" width=\"536\" height=\"679\" srcset=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/006-Internal-Only-User-Type-95kb.png 960w, https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/006-Internal-Only-User-Type-95kb-237x300.png 237w, https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/006-Internal-Only-User-Type-95kb-768x973.png 768w, https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/006-Internal-Only-User-Type-95kb-808x1024.png 808w, https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/006-Internal-Only-User-Type-95kb-19x24.png 19w, https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/006-Internal-Only-User-Type-95kb-28x36.png 28w, https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/006-Internal-Only-User-Type-95kb-38x48.png 38w\" sizes=\"auto, (max-width: 536px) 100vw, 536px\" \/><\/a><\/p>\n<p>Except that I am. I&#8217;m logged in with my ajay@wordzen.com G Suite account, which is an OWNER of this Cloud Console project. I suspect there&#8217;s a bug here that only allows the CREATOR of the Cloud project to mark the project &#8220;INTERNAL.&#8221; In my case, I created the project with an @gmail.com account. For now, that means I&#8217;m stuck in circular logic. If I login to the creator account, which is a gmail.com account, I can&#8217;t mark the project INTERNAL because I&#8217;m not a G Suite account. If I log in to my G Suite account to mark the project INTERNAL, I can&#8217;t because I&#8217;m only the owner, not the creator.<a name=\"unverified\"><\/a><\/p>\n<h3>5. Comfortable with being Unverified? It&#8217;s not as easy as it sounds.<\/h3>\n<p>You may choose to <strong>forego the whole verification process<\/strong> for a number of reasons. Perhaps you don&#8217;t want to pay for the security assessment. Perhaps your app is just for internal use. Perhaps you are under the 100-user threshold for requiring verification. You may choose to go Unverified thinking your users just won&#8217;t care whether you&#8217;re Verified or Unverified because they <em>trust<\/em> you. That&#8217;s all well and good, but if you choose to go <strong>Unverified<\/strong>, there are <strong>two things to know<\/strong>:<\/p>\n<p><strong>First<\/strong>, Google intentionally makes it difficult for a user to bypass the &#8220;Unverified App&#8221; screen. Here&#8217;s the standard Unverified App screen that users see:<\/p>\n<p><a href=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/007-Standard-Unverified-App-screen-26kb.png\" data-rel=\"lightbox-image-7\" data-rl_title=\"\" data-rl_caption=\"\" title=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-10889\" src=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/007-Standard-Unverified-App-screen-26kb.png\" alt=\"\" width=\"539\" height=\"294\" srcset=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/007-Standard-Unverified-App-screen-26kb.png 1064w, https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/007-Standard-Unverified-App-screen-26kb-300x164.png 300w, https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/007-Standard-Unverified-App-screen-26kb-768x419.png 768w, https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/007-Standard-Unverified-App-screen-26kb-1024x558.png 1024w, https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/007-Standard-Unverified-App-screen-26kb-24x13.png 24w, https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/007-Standard-Unverified-App-screen-26kb-36x20.png 36w, https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/007-Standard-Unverified-App-screen-26kb-48x26.png 48w\" sizes=\"auto, (max-width: 539px) 100vw, 539px\" \/><\/a><\/p>\n<p>It informs the user that if they trust the app, they can &#8220;proceed.&#8221; But just how does one proceed? The word &#8220;proceed&#8221; isn&#8217;t linked. There&#8217;s no button that says &#8220;proceed.&#8221; Instead, the user has to click &#8220;Advanced,&#8221; and only then is the user given the option to proceed, after noting in parentheses that doing so is unsafe. Holy moly. Talk about scaring a user unnecessarily. Or should I say, scaring a developer into <a href=\"https:\/\/www.gmass.co\/blog\/google-oauth-verification-security-assessment\/\">paying $15,000 &#8211; $75,000<\/a>.<\/p>\n<p><a href=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/008-Advanced-Unverified-App-screen-42kb.png\" data-rel=\"lightbox-image-8\" data-rl_title=\"\" data-rl_caption=\"\" title=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-10890\" src=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/008-Advanced-Unverified-App-screen-42kb.png\" alt=\"\" width=\"542\" height=\"459\" srcset=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/008-Advanced-Unverified-App-screen-42kb.png 916w, https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/008-Advanced-Unverified-App-screen-42kb-300x254.png 300w, https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/008-Advanced-Unverified-App-screen-42kb-768x651.png 768w, https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/008-Advanced-Unverified-App-screen-42kb-24x20.png 24w, https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/008-Advanced-Unverified-App-screen-42kb-36x30.png 36w, https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/008-Advanced-Unverified-App-screen-42kb-48x41.png 48w\" sizes=\"auto, (max-width: 542px) 100vw, 542px\" \/><\/a><\/p>\n<p>Here&#8217;s my recommended approach. On my app SearchMyEmail.com, which I&#8217;ve decided to let remain &#8220;Unverified,&#8221; we&#8217;ve built an animation showing the user exactly how to bypass the &#8220;unverified&#8221; nonsense.<\/p>\n<p><video autoplay=\"autoplay\" loop=\"loop\" muted=\"\" width=\"100%\" height=\"100%\"><source src=\"\/assets\/videos\/google-unverified-app-animation.mp4\" type=\"video\/mp4\" \/><\/video><\/p>\n<p>Feel free to <strong>copy this technique<\/strong>. Just go to <a href=\"https:\/\/www.searchmyemail.com\/\">SearchMyEmail.com<\/a>, choose to sign up as a &#8220;boss,&#8221; and then <strong>view the source<\/strong> for the interstitial page that has this animation.<\/p>\n<p>Secondly, everything with Google OAuth is inconsistent. I should say, the only consistency with their OAuth rules is their inconsistency.<\/p>\n<p>Check this out:<\/p>\n<p>Sometimes, and it&#8217;s unclear when, being Unverified results in a user being unable to connect, regardless of what they do. In my SearchMyEmail.com app, two supposedly equivalent Gmail accounts, ajaygoel999@gmail.com and ag998877z@gmail.com behave entirely differently when authenticating into SME.<\/p>\n<p>Since SME is Unverified, and since these are both @gmail.com accounts, they&#8217;re both likely to be shown extra warnings. This is what happens when ag998877z@gmail.com\u00a0authenticates:<\/p>\n<p><a href=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/009-when-ag998877z-authenticates-16kb.png\" data-rel=\"lightbox-image-9\" data-rl_title=\"\" data-rl_caption=\"\" title=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-10891\" src=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/009-when-ag998877z-authenticates-16kb.png\" alt=\"\" width=\"544\" height=\"316\" srcset=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/009-when-ag998877z-authenticates-16kb.png 764w, https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/009-when-ag998877z-authenticates-16kb-300x174.png 300w, https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/009-when-ag998877z-authenticates-16kb-24x14.png 24w, https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/009-when-ag998877z-authenticates-16kb-36x21.png 36w, https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/009-when-ag998877z-authenticates-16kb-48x28.png 48w\" sizes=\"auto, (max-width: 544px) 100vw, 544px\" \/><\/a><\/p>\n<p>I&#8217;m told the app is unverified but given the option to continue.<\/p>\n<p>But this is what happens when ajaygoel999@gmail.com authenticates:<\/p>\n<p><a href=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/010-when-ajaygoel999-authenticates-24kb.png\" data-rel=\"lightbox-image-10\" data-rl_title=\"\" data-rl_caption=\"\" title=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-10892\" src=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/010-when-ajaygoel999-authenticates-24kb.png\" alt=\"\" width=\"542\" height=\"213\" srcset=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/010-when-ajaygoel999-authenticates-24kb.png 1008w, https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/010-when-ajaygoel999-authenticates-24kb-300x118.png 300w, https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/010-when-ajaygoel999-authenticates-24kb-768x302.png 768w, https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/010-when-ajaygoel999-authenticates-24kb-24x9.png 24w, https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/010-when-ajaygoel999-authenticates-24kb-36x14.png 36w, https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/010-when-ajaygoel999-authenticates-24kb-48x19.png 48w\" sizes=\"auto, (max-width: 542px) 100vw, 542px\" \/><\/a><\/p>\n<p>I&#8217;m told the app is unverified but NOT given the option to continue.<\/p>\n<p><em>What&#8217;s the difference between the two @gmail.com accounts?<\/em> The only one I can think of is that ajaygoel999@gmail.com was created <strong>10 years ago<\/strong>, and ag998877z@gmail.com was created <strong>10 hours ago<\/strong>, but <strong>nowhere in Google&#8217;s OAuth docs is it stated that account age makes a difference<\/strong>.<\/p>\n<p>Even weirder, I have two apps that I&#8217;ve decided to leave Unverified, Wordzen and SearchMyEmail. Here are the Cloud Console config screens from each:<\/p>\n<p>SearchMyEmail&#8217;s Consent Screen<\/p>\n<p><a href=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/011-Search-My-Email-consent-screen-54kb.png\" data-rel=\"lightbox-image-11\" data-rl_title=\"\" data-rl_caption=\"\" title=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-10893\" src=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/011-Search-My-Email-consent-screen-54kb.png\" alt=\"\" width=\"544\" height=\"838\" srcset=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/011-Search-My-Email-consent-screen-54kb.png 776w, https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/011-Search-My-Email-consent-screen-54kb-195x300.png 195w, https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/011-Search-My-Email-consent-screen-54kb-768x1184.png 768w, https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/011-Search-My-Email-consent-screen-54kb-664x1024.png 664w, https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/011-Search-My-Email-consent-screen-54kb-16x24.png 16w, https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/011-Search-My-Email-consent-screen-54kb-23x36.png 23w, https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/011-Search-My-Email-consent-screen-54kb-31x48.png 31w\" sizes=\"auto, (max-width: 544px) 100vw, 544px\" \/><\/a><\/p>\n<p>SearchMyEmail&#8217;s Scopes<\/p>\n<p><a href=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/012-Search-My-Email-scopes-30kb.png\" data-rel=\"lightbox-image-12\" data-rl_title=\"\" data-rl_caption=\"\" title=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-10894\" src=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/012-Search-My-Email-scopes-30kb.png\" alt=\"\" width=\"544\" height=\"463\" srcset=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/012-Search-My-Email-scopes-30kb.png 972w, https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/012-Search-My-Email-scopes-30kb-300x256.png 300w, https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/012-Search-My-Email-scopes-30kb-768x654.png 768w, https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/012-Search-My-Email-scopes-30kb-24x20.png 24w, https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/012-Search-My-Email-scopes-30kb-36x31.png 36w, https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/012-Search-My-Email-scopes-30kb-48x41.png 48w\" sizes=\"auto, (max-width: 544px) 100vw, 544px\" \/><\/a><\/p>\n<p>Wordzen&#8217;s Consent Screen<\/p>\n<p><a href=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/013B-Wordzen-consent-screen-46kb.png\" data-rel=\"lightbox-image-13\" data-rl_title=\"\" data-rl_caption=\"\" title=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-10908\" src=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/013B-Wordzen-consent-screen-46kb.png\" alt=\"\" width=\"543\" height=\"972\" srcset=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/013B-Wordzen-consent-screen-46kb.png 684w, https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/013B-Wordzen-consent-screen-46kb-168x300.png 168w, https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/013B-Wordzen-consent-screen-46kb-572x1024.png 572w, https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/013B-Wordzen-consent-screen-46kb-13x24.png 13w, https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/013B-Wordzen-consent-screen-46kb-20x36.png 20w, https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/013B-Wordzen-consent-screen-46kb-27x48.png 27w\" sizes=\"auto, (max-width: 543px) 100vw, 543px\" \/><\/a><\/p>\n<p>Both show the status as &#8220;pending security assessment.&#8221; BUT, when you go into the App Details:<\/p>\n<figure id=\"attachment_10897\" aria-describedby=\"caption-attachment-10897\" style=\"width: 544px\" class=\"wp-caption alignnone\"><a href=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/014-Wordzen-scope-approved-26kb.png\" data-rel=\"lightbox-image-14\" data-rl_title=\"\" data-rl_caption=\"\" title=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-10897\" src=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/014-Wordzen-scope-approved-26kb.png\" alt=\"\" width=\"544\" height=\"391\" srcset=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/014-Wordzen-scope-approved-26kb.png 968w, https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/014-Wordzen-scope-approved-26kb-300x216.png 300w, https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/014-Wordzen-scope-approved-26kb-768x552.png 768w, https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/014-Wordzen-scope-approved-26kb-24x17.png 24w, https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/014-Wordzen-scope-approved-26kb-36x26.png 36w, https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/014-Wordzen-scope-approved-26kb-48x35.png 48w\" sizes=\"auto, (max-width: 544px) 100vw, 544px\" \/><\/a><figcaption id=\"caption-attachment-10897\" class=\"wp-caption-text\">It says &#8220;mail.google.com&#8221; behind the tooltip.<\/figcaption><\/figure>\n<p>Well, look at that! The full <strong>https:\/\/mail.google.com<\/strong> scope is approved and granted. Yet the app is still labeled &#8220;pending security assessment.&#8221; I promise you <strong>Wordzen did not undergo the Security Assessment<\/strong> required by restricted scope apps. How did that happen? A Google miracle, perhaps. <span style=\"color: #ff0000;\">Update update update!<\/span> It&#8217;s now <strong>January 25, 2020<\/strong>, and <em>I spoke too soon<\/em>. As I detailed on my <a href=\"https:\/\/www.gmass.co\/blog\/live-updates-google-oauth-verification-security\/\">live updates page<\/a>, on <strong>January 13<\/strong>, I received notice from Google that Wordzen missed the deadline and use of the <strong>https:\/\/mail.google.com<\/strong> scope is now considered &#8220;unverified&#8221;.<\/p>\n<p><em>Please, Google, fix this giant mess. But leave Wordzen&#8217;s awesome unfettered access alone <span style=\"color: #ff0000;\">(Never mind, they removed this access)<\/span>.<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>It&#8217;s 2020, when Google promised to shut off many third-party apps that weren&#8217;t verified by December 31, 2019. While I haven&#8217;t heard any reports of anyone being shut\u2026<\/p>\n","protected":false},"author":2,"featured_media":10901,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[5301],"tags":[],"class_list":["post-10845","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-google-oauth"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\r\n<title>Five annoying issues with Google&#039;s OAuth Scope Verification<\/title>\r\n<meta name=\"description\" content=\"Here are some of the problems you&#039;ll likely run into when working with Google OAuth and its verification process. Hint: it&#039;s not fun.\" \/>\r\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\r\n<link rel=\"canonical\" href=\"https:\/\/www.gmass.co\/blog\/five-annoying-issues-google-oauth-scope-verification\/\" \/>\r\n<meta property=\"og:locale\" content=\"en_US\" \/>\r\n<meta property=\"og:type\" content=\"article\" \/>\r\n<meta property=\"og:title\" content=\"Five annoying issues with Google&#039;s OAuth Scope Verification\" \/>\r\n<meta property=\"og:description\" content=\"Here are some of the problems you&#039;ll likely run into when working with Google OAuth and its verification process. Hint: it&#039;s not fun.\" \/>\r\n<meta property=\"og:url\" content=\"https:\/\/www.gmass.co\/blog\/five-annoying-issues-google-oauth-scope-verification\/\" \/>\r\n<meta property=\"og:site_name\" content=\"GMass Blog\" \/>\r\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/GmailMailMerge\/\" \/>\r\n<meta property=\"article:published_time\" content=\"2020-01-05T04:41:52+00:00\" \/>\r\n<meta property=\"article:modified_time\" content=\"2020-01-31T01:59:53+00:00\" \/>\r\n<meta property=\"og:image\" content=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/featured-image-five-annoying-Google-OAuth-74kb.png\" \/>\r\n\t<meta property=\"og:image:width\" content=\"1001\" \/>\r\n\t<meta property=\"og:image:height\" content=\"467\" \/>\r\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\r\n<meta name=\"author\" content=\"Ajay Goel\" \/>\r\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\r\n<meta name=\"twitter:creator\" content=\"@PartTimeSnob\" \/>\r\n<meta name=\"twitter:site\" content=\"@GMassForGmail\" \/>\r\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Ajay Goel\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"11 minutes\" \/>\r\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.gmass.co\\\/blog\\\/five-annoying-issues-google-oauth-scope-verification\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.gmass.co\\\/blog\\\/five-annoying-issues-google-oauth-scope-verification\\\/\"},\"author\":{\"name\":\"Ajay Goel\",\"@id\":\"https:\\\/\\\/www.gmass.co\\\/blog\\\/#\\\/schema\\\/person\\\/b5fa74f8765b860701158fd77162fff8\"},\"headline\":\"Five annoying issues with Google&#8217;s OAuth Scope Verification\",\"datePublished\":\"2020-01-05T04:41:52+00:00\",\"dateModified\":\"2020-01-31T01:59:53+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.gmass.co\\\/blog\\\/five-annoying-issues-google-oauth-scope-verification\\\/\"},\"wordCount\":2257,\"commentCount\":11,\"image\":{\"@id\":\"https:\\\/\\\/www.gmass.co\\\/blog\\\/five-annoying-issues-google-oauth-scope-verification\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.gmass.co\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/01\\\/featured-image-five-annoying-Google-OAuth-74kb.png\",\"articleSection\":[\"Google OAuth\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.gmass.co\\\/blog\\\/five-annoying-issues-google-oauth-scope-verification\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.gmass.co\\\/blog\\\/five-annoying-issues-google-oauth-scope-verification\\\/\",\"url\":\"https:\\\/\\\/www.gmass.co\\\/blog\\\/five-annoying-issues-google-oauth-scope-verification\\\/\",\"name\":\"Five annoying issues with Google's OAuth Scope Verification\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.gmass.co\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.gmass.co\\\/blog\\\/five-annoying-issues-google-oauth-scope-verification\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.gmass.co\\\/blog\\\/five-annoying-issues-google-oauth-scope-verification\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.gmass.co\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/01\\\/featured-image-five-annoying-Google-OAuth-74kb.png\",\"datePublished\":\"2020-01-05T04:41:52+00:00\",\"dateModified\":\"2020-01-31T01:59:53+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/www.gmass.co\\\/blog\\\/#\\\/schema\\\/person\\\/b5fa74f8765b860701158fd77162fff8\"},\"description\":\"Here are some of the problems you'll likely run into when working with Google OAuth and its verification process. Hint: it's not fun.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.gmass.co\\\/blog\\\/five-annoying-issues-google-oauth-scope-verification\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.gmass.co\\\/blog\\\/five-annoying-issues-google-oauth-scope-verification\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.gmass.co\\\/blog\\\/five-annoying-issues-google-oauth-scope-verification\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.gmass.co\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/01\\\/featured-image-five-annoying-Google-OAuth-74kb.png\",\"contentUrl\":\"https:\\\/\\\/www.gmass.co\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/01\\\/featured-image-five-annoying-Google-OAuth-74kb.png\",\"width\":1001,\"height\":467},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.gmass.co\\\/blog\\\/five-annoying-issues-google-oauth-scope-verification\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.gmass.co\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Five annoying issues with Google&#8217;s OAuth Scope Verification\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.gmass.co\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.gmass.co\\\/blog\\\/\",\"name\":\"GMass Blog\",\"description\":\"Tips and tricks for sending mail merge and mass email campaigns directly from Gmail\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.gmass.co\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.gmass.co\\\/blog\\\/#\\\/schema\\\/person\\\/b5fa74f8765b860701158fd77162fff8\",\"name\":\"Ajay Goel\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f3a70af05bbabe47925150d5a1320540e801b78055a74da20658fc97cd0706a2?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f3a70af05bbabe47925150d5a1320540e801b78055a74da20658fc97cd0706a2?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f3a70af05bbabe47925150d5a1320540e801b78055a74da20658fc97cd0706a2?s=96&d=mm&r=g\",\"caption\":\"Ajay Goel\"},\"description\":\"Ajay is the founder of GMass and has been developing email sending software for 20 years.\",\"sameAs\":[\"https:\\\/\\\/twitter.com\\\/PartTimeSnob\",\"https:\\\/\\\/x.com\\\/PartTimeSnob\"],\"url\":\"https:\\\/\\\/www.gmass.co\\\/blog\\\/author\\\/ajay-goel\\\/\"}]}<\/script>\r\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Five annoying issues with Google's OAuth Scope Verification","description":"Here are some of the problems you'll likely run into when working with Google OAuth and its verification process. Hint: it's not fun.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.gmass.co\/blog\/five-annoying-issues-google-oauth-scope-verification\/","og_locale":"en_US","og_type":"article","og_title":"Five annoying issues with Google's OAuth Scope Verification","og_description":"Here are some of the problems you'll likely run into when working with Google OAuth and its verification process. Hint: it's not fun.","og_url":"https:\/\/www.gmass.co\/blog\/five-annoying-issues-google-oauth-scope-verification\/","og_site_name":"GMass Blog","article_publisher":"https:\/\/www.facebook.com\/GmailMailMerge\/","article_published_time":"2020-01-05T04:41:52+00:00","article_modified_time":"2020-01-31T01:59:53+00:00","og_image":[{"width":1001,"height":467,"url":"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/featured-image-five-annoying-Google-OAuth-74kb.png","type":"image\/png"}],"author":"Ajay Goel","twitter_card":"summary_large_image","twitter_creator":"@PartTimeSnob","twitter_site":"@GMassForGmail","twitter_misc":{"Written by":"Ajay Goel","Est. reading time":"11 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.gmass.co\/blog\/five-annoying-issues-google-oauth-scope-verification\/#article","isPartOf":{"@id":"https:\/\/www.gmass.co\/blog\/five-annoying-issues-google-oauth-scope-verification\/"},"author":{"name":"Ajay Goel","@id":"https:\/\/www.gmass.co\/blog\/#\/schema\/person\/b5fa74f8765b860701158fd77162fff8"},"headline":"Five annoying issues with Google&#8217;s OAuth Scope Verification","datePublished":"2020-01-05T04:41:52+00:00","dateModified":"2020-01-31T01:59:53+00:00","mainEntityOfPage":{"@id":"https:\/\/www.gmass.co\/blog\/five-annoying-issues-google-oauth-scope-verification\/"},"wordCount":2257,"commentCount":11,"image":{"@id":"https:\/\/www.gmass.co\/blog\/five-annoying-issues-google-oauth-scope-verification\/#primaryimage"},"thumbnailUrl":"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/featured-image-five-annoying-Google-OAuth-74kb.png","articleSection":["Google OAuth"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.gmass.co\/blog\/five-annoying-issues-google-oauth-scope-verification\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.gmass.co\/blog\/five-annoying-issues-google-oauth-scope-verification\/","url":"https:\/\/www.gmass.co\/blog\/five-annoying-issues-google-oauth-scope-verification\/","name":"Five annoying issues with Google's OAuth Scope Verification","isPartOf":{"@id":"https:\/\/www.gmass.co\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.gmass.co\/blog\/five-annoying-issues-google-oauth-scope-verification\/#primaryimage"},"image":{"@id":"https:\/\/www.gmass.co\/blog\/five-annoying-issues-google-oauth-scope-verification\/#primaryimage"},"thumbnailUrl":"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/featured-image-five-annoying-Google-OAuth-74kb.png","datePublished":"2020-01-05T04:41:52+00:00","dateModified":"2020-01-31T01:59:53+00:00","author":{"@id":"https:\/\/www.gmass.co\/blog\/#\/schema\/person\/b5fa74f8765b860701158fd77162fff8"},"description":"Here are some of the problems you'll likely run into when working with Google OAuth and its verification process. Hint: it's not fun.","breadcrumb":{"@id":"https:\/\/www.gmass.co\/blog\/five-annoying-issues-google-oauth-scope-verification\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.gmass.co\/blog\/five-annoying-issues-google-oauth-scope-verification\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.gmass.co\/blog\/five-annoying-issues-google-oauth-scope-verification\/#primaryimage","url":"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/featured-image-five-annoying-Google-OAuth-74kb.png","contentUrl":"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2020\/01\/featured-image-five-annoying-Google-OAuth-74kb.png","width":1001,"height":467},{"@type":"BreadcrumbList","@id":"https:\/\/www.gmass.co\/blog\/five-annoying-issues-google-oauth-scope-verification\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.gmass.co\/blog\/"},{"@type":"ListItem","position":2,"name":"Five annoying issues with Google&#8217;s OAuth Scope Verification"}]},{"@type":"WebSite","@id":"https:\/\/www.gmass.co\/blog\/#website","url":"https:\/\/www.gmass.co\/blog\/","name":"GMass Blog","description":"Tips and tricks for sending mail merge and mass email campaigns directly from Gmail","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.gmass.co\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/www.gmass.co\/blog\/#\/schema\/person\/b5fa74f8765b860701158fd77162fff8","name":"Ajay Goel","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/f3a70af05bbabe47925150d5a1320540e801b78055a74da20658fc97cd0706a2?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/f3a70af05bbabe47925150d5a1320540e801b78055a74da20658fc97cd0706a2?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f3a70af05bbabe47925150d5a1320540e801b78055a74da20658fc97cd0706a2?s=96&d=mm&r=g","caption":"Ajay Goel"},"description":"Ajay is the founder of GMass and has been developing email sending software for 20 years.","sameAs":["https:\/\/twitter.com\/PartTimeSnob","https:\/\/x.com\/PartTimeSnob"],"url":"https:\/\/www.gmass.co\/blog\/author\/ajay-goel\/"}]}},"_links":{"self":[{"href":"https:\/\/www.gmass.co\/blog\/wp-json\/wp\/v2\/posts\/10845","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.gmass.co\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.gmass.co\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.gmass.co\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.gmass.co\/blog\/wp-json\/wp\/v2\/comments?post=10845"}],"version-history":[{"count":46,"href":"https:\/\/www.gmass.co\/blog\/wp-json\/wp\/v2\/posts\/10845\/revisions"}],"predecessor-version":[{"id":11064,"href":"https:\/\/www.gmass.co\/blog\/wp-json\/wp\/v2\/posts\/10845\/revisions\/11064"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.gmass.co\/blog\/wp-json\/wp\/v2\/media\/10901"}],"wp:attachment":[{"href":"https:\/\/www.gmass.co\/blog\/wp-json\/wp\/v2\/media?parent=10845"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.gmass.co\/blog\/wp-json\/wp\/v2\/categories?post=10845"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.gmass.co\/blog\/wp-json\/wp\/v2\/tags?post=10845"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}