{"id":9167,"date":"2019-05-01T03:08:51","date_gmt":"2019-05-01T03:08:51","guid":{"rendered":"https:\/\/www.gmass.co\/blog\/?p=4167"},"modified":"2020-02-06T08:10:13","modified_gmt":"2020-02-06T08:10:13","slug":"google-oauth-verification-security-assessment","status":"publish","type":"post","link":"https:\/\/www.gmass.co\/blog\/google-oauth-verification-security-assessment\/","title":{"rendered":"My feelings on Google&#8217;s $15,000-$75,000 OAuth verification process and security assessment"},"content":{"rendered":"<p>Last October, <a href=\"https:\/\/cloud.google.com\/blog\/products\/g-suite\/elevating-user-trust-in-our-api-ecosystems\">Google announced that it would start being more stringent<\/a> with software vendors <strong>building apps on top of the Gmail API<\/strong>. Specifically,\u00a0developers using a &#8220;restricted&#8221; or &#8220;sensitive&#8221; Gmail API scope would be subject to additional scrutiny and have to pay a fee of $15,000 &#8211; $75,000 <em>or more<\/em> to have a third party security assessment done. GMass leverages the power of the Gmail API to perform its magic, and so GMass has been subject to these measures.<\/p>\n<p>Since Google&#8217;s announcement, the web\u00a0has become rife with stories of frustration amongst smaller companies and independent developers who simply cannot afford the fee.\u00a0This\u00a0new policy stands to kill innovation, be the obstacle to side projects, and overall, make Gmail less useful. One of the primary reasons Gmail has been the email platform of choice for startups and tech companies is that it&#8217;s been extensible. There are\u00a0<a href=\"https:\/\/www.producthunt.com\/e\/apps-for-gmail-email\">hundreds, if not thousands,\u00a0of extensions\u00a0for Gmail<\/a>, one of which is GMass, that\u00a0add functionality and make\u00a0Gmail more useful than the base product. <em>Most of these applications\u00a0will disappear.<\/em> Unless a product has reached the point of business sustainability, it won&#8217;t be worth it for most developers to pay the fee and go through the security process (which by the way, will likely cost more than the fee paid, because of development time necessary for remediation).<\/p>\n<p>Well known extensions and Gmail apps like Boomerang, Yesware, Mixmax, and Mailtrack will likely pay the fee and succumb to the new governance, but smaller players like <a href=\"https:\/\/blog.context.io\/context-io-deprecation-notice-ce8b77e6e477\">Context.io<\/a> and <a href=\"https:\/\/www.voice2biz.com\/oauth-2-0-for-google-apis-3rd-party-audit-costs-require-emailmonkey-to-shutdown\/\">EmailMonkey have already announced their plans to shut down<\/a>. I&#8217;ve also decided to shut down my other Gmail extension, Wordzen, because the fee is too high to be worth it for Wordzen.<\/p>\n<p>This <a href=\"https:\/\/www.theregister.co.uk\/2019\/02\/11\/google_gmail_developer\/\">article from The Register<\/a>\u00a0profiles two makers of Gmail apps, Leave Me Alone and Clean Email,\u00a0and their frustrations with the new requirements.<\/p>\n<p>Even a popular service like <a href=\"https:\/\/help.ifttt.com\/hc\/en-us\/articles\/360020249393-Important-update-about-Gmail-on-IFTTT\">IFTTT\u00a0is caving and reducing\u00a0its Gmail functionality<\/a>.<\/p>\n<h3>My stance<\/h3>\n<ol>\n<li>I&#8217;m not happy about it, but given the substantial GMass user base, we&#8217;re beginning the process of the security audit. You can follow my <a href=\"https:\/\/www.gmass.co\/blog\/live-updates-google-oauth-verification-security\/\">live updates of the OAuth verification process<\/a>.<\/li>\n<li>I&#8217;m\u00a0a proponent\u00a0for greater security and protection of user data, but asking software developers to pay the security fee is ludicrous. Google should pay the fee on behalf of its developers (explanation below).<\/li>\n<li>The opportunity is rife for a new email platform to make a dent in Gmail&#8217;s marketshare.<\/li>\n<li>Prices for all Gmail apps, including GMass, will rise to cover the cost of the annual security assessment.<\/li>\n<li>Google is grasping for straws when justifying making the developers pay. In response to the question &#8220;<b>Why is Google asking apps to pay for the security assessment?&#8221; <\/b>they state, &#8220;As we\u2019ve pre-selected industry leading assessors, <strong>the letter of assessment your app will receive can be used for other certifications or customer engagements<\/strong> where a security assessment is needed.&#8221; <em>Gee thanks, Google, for\u00a0making it easier for us to get more customer engagements.<\/em><\/li>\n<li>Google&#8217;s support for developers who build Gmail apps has been poor, and\u00a0the manner in which\u00a0this issue is being handled is being done callously. Questions to the OAuth verification team go unanswered for long periods of time. Stack Overflow is <a href=\"https:\/\/stackoverflow.com\/questions\/tagged\/gmail-api\">littered with questions about the Gmail API<\/a>, mostly which go unanswered, <a href=\"https:\/\/developers.google.com\/gmail\/api\/support\">despite Google pointing developers to this area<\/a>. Google has been playing favorites with<a href=\"https:\/\/gsuite.google.com\/marketplace\/category\/works-with-gmail\"> Gmail Add-ons<\/a>, allowing only some to work on iOS while <a href=\"https:\/\/developers.google.com\/gsuite\/add-ons\/guides\/restrictions\">claiming that iOS isn&#8217;t supported<\/a>, and not providing any context for its decisions. Additionally, Chrome extensions for Gmail have never been officially sanctioned,\u00a0although when Gmail launched its new UI last year, it did inform all extension makers of the upcoming changes and provided test accounts. It&#8217;s clear that it&#8217;s up to developers to solve their own issues and work around Google&#8217;s platform shortcomings.<\/li>\n<\/ol>\n<h3>Conflict and Confusion<\/h3>\n<p>There is also conflict and confusion amongst the information released by Google.<\/p>\n<p><strong>Does this process only affect you if your users include gmail.com accounts, or do you have to go through the process even if you just take on G Suite users?<\/strong><\/p>\n<p>The language in the announcements seem to indicate that\u00a0this only affects gmail.com consumer accounts wanting access to an app.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-4179\" style=\"border: 3px solid #eeeeee;\" src=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2019\/04\/Screenshot-2019-04-30-17.32.31.png\" alt=\"\" width=\"1356\" height=\"234\" \/>The\u00a0use of the word &#8220;my&#8221;, however, in the question is confusing. It makes the question seem to apply to internal accounts only, those that are owned by the developer of the app. But then the answer references how G Suite administrators can control access, which implies that all external G Suite accounts are included in the group that are not impacted.<\/p>\n<p>In the\u00a0detailed FAQ about who can skip the review process, one would hope that for consistency with the above that it would say &#8220;Those apps that only service G Suite accounts and not consumer gmail.com accounts&#8221;\u00a0but it doesn&#8217;t. Hmm.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-4180\" style=\"border: 3px solid #eeeeee;\" src=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2019\/04\/Screenshot-2019-04-30-17.34.49.png\" alt=\"\" width=\"1568\" height=\"658\" \/><\/p>\n<p>Further in the FAQ, we find:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-4194\" style=\"border: 3px solid #eeeeee;\" src=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2019\/05\/Screenshot-2019-05-01-01.36.05.png\" alt=\"\" width=\"1358\" height=\"294\" \/>The first paragraph references &#8220;Google Accounts outside of your organization&#8221; which I interpret to include G Suite accounts outside of your organization. But then the second paragraph says that if you don&#8217;t verify, &#8220;access for new users will be disabled&#8221; and &#8220;existing grants for consumer accounts will be revoked&#8221;. I interpret that to mean that no new G Suite nor gmail.com users will be able to OAuth connect to your app, but existing G Suite users will still be able to.<\/p>\n<p>Lastly, there&#8217;s this bit:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-4195\" style=\"border: 3px solid #eeeeee;\" src=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2019\/05\/Screenshot-2019-05-01-01.37.35.png\" alt=\"\" width=\"1522\" height=\"342\" \/>I&#8217;m thoroughly confused at this point.<\/p>\n<p><strong>What happens if you choose to not go through the process? Will your app just show &#8220;Unverified&#8221; on the OAuth consent screen, or will it not have access to certain Gmail API scopes altogether?<\/strong><\/p>\n<p>The documentation is also unclear on this issue. In the User Data Policy, we find:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-4198\" src=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2019\/05\/Screenshot-2019-05-01-01.46.43.png\" alt=\"\" width=\"1828\" height=\"478\" \/><\/p>\n<p>but this seems to conflict with what&#8217;s shown above:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-4194\" style=\"border: 3px solid #eeeeee;\" src=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2019\/05\/Screenshot-2019-05-01-01.36.05.png\" alt=\"\" width=\"1358\" height=\"294\" \/><\/p>\n<p>Finally this text under the &#8220;Sensitive Scope Verification&#8221; section seems to indicate that the only consequence of not having your app verified is that users will see that it&#8217;s Unverified.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-4199\" src=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2019\/05\/Screenshot-2019-05-01-01.49.53.png\" alt=\"\" width=\"1458\" height=\"488\" \/><\/p>\n<p>However, there&#8217;s no equivalent question under the &#8220;Restricted Scope Verification&#8221; section:<\/p>\n<figure id=\"attachment_4202\" aria-describedby=\"caption-attachment-4202\" style=\"width: 1534px\" class=\"wp-caption alignnone\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-4202 size-full\" src=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2019\/05\/Screenshot-2019-05-01-01.56.27.png\" alt=\"\" width=\"1534\" height=\"1282\" \/><figcaption id=\"caption-attachment-4202\" class=\"wp-caption-text\">They really should include the question: &#8220;What happens if I don&#8217;t verify my app?&#8221;<\/figcaption><\/figure>\n<p>It would\u00a0be preferable for the entire developer community if the only consequence of not verifying a sensitive scope app is that users see the &#8220;Unverified&#8221; designation when connecting their accounts because it allows users to still use their apps. Personally I\u00a0wouldn&#8217;t mind if GMass users go to connect their accounts and see that the app is &#8220;unverified&#8221;,\u00a0if it weren&#8217;t for the <a href=\"https:\/\/www.dropbox.com\/s\/v2ipv5oot4qqtwc\/Screenshot%202019-05-01%2001.54.43.png?dl=0\" data-rel=\"lightbox-image-0\" data-rl_title=\"\" data-rl_caption=\"\" title=\"\">100 user cap that is imposed on Unverified Apps<\/a>. But again, this is only clear for sensitive scope apps and not restricted scope apps.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-4201\" src=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2019\/05\/Screenshot-2019-05-01-01.54.43.png\" alt=\"\" width=\"1568\" height=\"614\" \/><\/p>\n<h3>The scope of the security audit<\/h3>\n<p>In the <a href=\"https:\/\/support.google.com\/cloud\/answer\/9110914\">FAQ<\/a>, Google states &#8220;we are requiring apps that store data on non-Google servers to demonstrate a minimum level of capability in handling data securely and deleting user data upon user request.&#8221; But deeper in the FAQ, the\u00a0audit also includes developer&#8217;s code deployment practices, which seems to go beyond a minimal level in capability in handling data securely.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-4184\" style=\"border: 3px solid #eeeeee;\" src=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2019\/05\/google-oauth-security-audit-web.png\" alt=\"\" width=\"518\" height=\"1371\" \/><br \/>\n<em>Google is in a position of power over its third party developers.<\/em> After all, where are the developers going to go? We&#8217;ve all invested substantially into building our products, many of us make a living off of what we&#8217;ve built, so we if we don&#8217;t play by the new rules, it would mark an end to our careers. We could go and build on Outlook.com&#8217;s API instead, but with just two players &#8212; Google and Microsoft &#8212; dominating the email ecosystem, there&#8217;s no guarantee that Microsoft won&#8217;t implement the same policies. Such is the risk of building a product on top of someone else&#8217;s.<\/p>\n<h3>Why Google\u00a0should pay the fee instead<\/h3>\n<p>They can afford to, and it offers a checks and balances between the security firms and Google that doesn&#8217;t exist right now. While developers benefit from building software on top of Gmail, Google too derives benefit from attracting customers to a product that has been made better by all of its third party developers. There are users of Gmail and G Suite that would NOT be users if it weren&#8217;t for their loyalty to a particular third party app. I know for certain that in GMass&#8217;s case, we&#8217;ve\u00a0brought users to G Suite because they wanted to use GMass.<\/p>\n<h3>Resources on\u00a0the new Google OAuth scope policy<\/h3>\n<p>Google&#8217;s <a href=\"https:\/\/cloud.google.com\/blog\/products\/g-suite\/elevating-user-trust-in-our-api-ecosystems\">original announcement<\/a> <span style=\"color: #800080;\">(cloud.google.com)<\/span>.<\/p>\n<p>The <a href=\"https:\/\/developers.google.com\/terms\/api-services-user-data-policy\">user data policy<\/a> <span style=\"color: #800080;\">(developers.google.com)<\/span>.<\/p>\n<p>Detailed <a href=\"https:\/\/support.google.com\/cloud\/answer\/9110914?hl=en&amp;ref_topic=3473162\">FAQ<\/a> on the verification process and the security assessment <span style=\"color: #800080;\">(support.google.com)<\/span>.<\/p>\n<p>Indie Hackers <a href=\"https:\/\/www.indiehackers.com\/forum\/psa-new-google-policy-creates-15k-barrier-to-entry-for-apps-using-the-gmail-api-08070e6e4c\">discussion<\/a> of the issue <span style=\"color: #800080;\">(indiehackers.com)<\/span>.<\/p>\n<p><a href=\"https:\/\/groups.google.com\/forum\/#!topic\/inboxsdk\/6NLvQL-5bic\">Inbox SDK discussion<\/a> on the issue <span style=\"color: #800080;\">(groups.google.com)<\/span>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Last October, Google announced that it would start being more stringent with software vendors building apps on top of the Gmail API. Specifically,\u00a0developers using a &#8220;restricted&#8221; or &#8220;sensitive&#8221;\u2026<\/p>\n","protected":false},"author":2,"featured_media":9229,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[3770,3461,5301],"tags":[],"class_list":["post-9167","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-chrome-extensions","category-gmail-add-ons","category-google-oauth"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\r\n<title>My feelings on Google&#039;s $15,000-$75,000 OAuth verification process and security assessment<\/title>\r\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\r\n<link rel=\"canonical\" href=\"https:\/\/www.gmass.co\/blog\/google-oauth-verification-security-assessment\/\" \/>\r\n<meta property=\"og:locale\" content=\"en_US\" \/>\r\n<meta property=\"og:type\" content=\"article\" \/>\r\n<meta property=\"og:title\" content=\"My feelings on Google&#039;s $15,000-$75,000 OAuth verification process and security assessment\" \/>\r\n<meta property=\"og:description\" content=\"Last October, Google announced that it would start being more stringent with software vendors building apps on top of the Gmail API. Specifically,\u00a0developers using a &#8220;restricted&#8221; or &#8220;sensitive&#8221;\u2026\" \/>\r\n<meta property=\"og:url\" content=\"https:\/\/www.gmass.co\/blog\/google-oauth-verification-security-assessment\/\" \/>\r\n<meta property=\"og:site_name\" content=\"GMass Blog\" \/>\r\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/GmailMailMerge\/\" \/>\r\n<meta property=\"article:published_time\" content=\"2019-05-01T03:08:51+00:00\" \/>\r\n<meta property=\"article:modified_time\" content=\"2020-02-06T08:10:13+00:00\" \/>\r\n<meta property=\"og:image\" content=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2019\/05\/gmass-google-assessment.png\" \/>\r\n\t<meta property=\"og:image:width\" content=\"2002\" \/>\r\n\t<meta property=\"og:image:height\" content=\"934\" \/>\r\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\r\n<meta name=\"author\" content=\"Ajay Goel\" \/>\r\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\r\n<meta name=\"twitter:creator\" content=\"@PartTimeSnob\" \/>\r\n<meta name=\"twitter:site\" content=\"@GMassForGmail\" \/>\r\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Ajay Goel\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"7 minutes\" \/>\r\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.gmass.co\\\/blog\\\/google-oauth-verification-security-assessment\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.gmass.co\\\/blog\\\/google-oauth-verification-security-assessment\\\/\"},\"author\":{\"name\":\"Ajay Goel\",\"@id\":\"https:\\\/\\\/www.gmass.co\\\/blog\\\/#\\\/schema\\\/person\\\/b5fa74f8765b860701158fd77162fff8\"},\"headline\":\"My feelings on Google&#8217;s $15,000-$75,000 OAuth verification process and security assessment\",\"datePublished\":\"2019-05-01T03:08:51+00:00\",\"dateModified\":\"2020-02-06T08:10:13+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.gmass.co\\\/blog\\\/google-oauth-verification-security-assessment\\\/\"},\"wordCount\":1487,\"commentCount\":27,\"image\":{\"@id\":\"https:\\\/\\\/www.gmass.co\\\/blog\\\/google-oauth-verification-security-assessment\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.gmass.co\\\/blog\\\/wp-content\\\/uploads\\\/2019\\\/05\\\/gmass-google-assessment.png\",\"articleSection\":[\"Chrome Extensions\",\"Gmail Add-ons\",\"Google OAuth\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.gmass.co\\\/blog\\\/google-oauth-verification-security-assessment\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.gmass.co\\\/blog\\\/google-oauth-verification-security-assessment\\\/\",\"url\":\"https:\\\/\\\/www.gmass.co\\\/blog\\\/google-oauth-verification-security-assessment\\\/\",\"name\":\"My feelings on Google's $15,000-$75,000 OAuth verification process and security assessment\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.gmass.co\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.gmass.co\\\/blog\\\/google-oauth-verification-security-assessment\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.gmass.co\\\/blog\\\/google-oauth-verification-security-assessment\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.gmass.co\\\/blog\\\/wp-content\\\/uploads\\\/2019\\\/05\\\/gmass-google-assessment.png\",\"datePublished\":\"2019-05-01T03:08:51+00:00\",\"dateModified\":\"2020-02-06T08:10:13+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/www.gmass.co\\\/blog\\\/#\\\/schema\\\/person\\\/b5fa74f8765b860701158fd77162fff8\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.gmass.co\\\/blog\\\/google-oauth-verification-security-assessment\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.gmass.co\\\/blog\\\/google-oauth-verification-security-assessment\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.gmass.co\\\/blog\\\/google-oauth-verification-security-assessment\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.gmass.co\\\/blog\\\/wp-content\\\/uploads\\\/2019\\\/05\\\/gmass-google-assessment.png\",\"contentUrl\":\"https:\\\/\\\/www.gmass.co\\\/blog\\\/wp-content\\\/uploads\\\/2019\\\/05\\\/gmass-google-assessment.png\",\"width\":2002,\"height\":934},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.gmass.co\\\/blog\\\/google-oauth-verification-security-assessment\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.gmass.co\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"My feelings on Google&#8217;s $15,000-$75,000 OAuth verification process and security assessment\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.gmass.co\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.gmass.co\\\/blog\\\/\",\"name\":\"GMass Blog\",\"description\":\"Tips and tricks for sending mail merge and mass email campaigns directly from Gmail\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.gmass.co\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.gmass.co\\\/blog\\\/#\\\/schema\\\/person\\\/b5fa74f8765b860701158fd77162fff8\",\"name\":\"Ajay Goel\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f3a70af05bbabe47925150d5a1320540e801b78055a74da20658fc97cd0706a2?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f3a70af05bbabe47925150d5a1320540e801b78055a74da20658fc97cd0706a2?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f3a70af05bbabe47925150d5a1320540e801b78055a74da20658fc97cd0706a2?s=96&d=mm&r=g\",\"caption\":\"Ajay Goel\"},\"description\":\"Ajay is the founder of GMass and has been developing email sending software for 20 years.\",\"sameAs\":[\"https:\\\/\\\/twitter.com\\\/PartTimeSnob\",\"https:\\\/\\\/x.com\\\/PartTimeSnob\"],\"url\":\"https:\\\/\\\/www.gmass.co\\\/blog\\\/author\\\/ajay-goel\\\/\"}]}<\/script>\r\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"My feelings on Google's $15,000-$75,000 OAuth verification process and security assessment","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.gmass.co\/blog\/google-oauth-verification-security-assessment\/","og_locale":"en_US","og_type":"article","og_title":"My feelings on Google's $15,000-$75,000 OAuth verification process and security assessment","og_description":"Last October, Google announced that it would start being more stringent with software vendors building apps on top of the Gmail API. Specifically,\u00a0developers using a &#8220;restricted&#8221; or &#8220;sensitive&#8221;\u2026","og_url":"https:\/\/www.gmass.co\/blog\/google-oauth-verification-security-assessment\/","og_site_name":"GMass Blog","article_publisher":"https:\/\/www.facebook.com\/GmailMailMerge\/","article_published_time":"2019-05-01T03:08:51+00:00","article_modified_time":"2020-02-06T08:10:13+00:00","og_image":[{"width":2002,"height":934,"url":"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2019\/05\/gmass-google-assessment.png","type":"image\/png"}],"author":"Ajay Goel","twitter_card":"summary_large_image","twitter_creator":"@PartTimeSnob","twitter_site":"@GMassForGmail","twitter_misc":{"Written by":"Ajay Goel","Est. reading time":"7 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.gmass.co\/blog\/google-oauth-verification-security-assessment\/#article","isPartOf":{"@id":"https:\/\/www.gmass.co\/blog\/google-oauth-verification-security-assessment\/"},"author":{"name":"Ajay Goel","@id":"https:\/\/www.gmass.co\/blog\/#\/schema\/person\/b5fa74f8765b860701158fd77162fff8"},"headline":"My feelings on Google&#8217;s $15,000-$75,000 OAuth verification process and security assessment","datePublished":"2019-05-01T03:08:51+00:00","dateModified":"2020-02-06T08:10:13+00:00","mainEntityOfPage":{"@id":"https:\/\/www.gmass.co\/blog\/google-oauth-verification-security-assessment\/"},"wordCount":1487,"commentCount":27,"image":{"@id":"https:\/\/www.gmass.co\/blog\/google-oauth-verification-security-assessment\/#primaryimage"},"thumbnailUrl":"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2019\/05\/gmass-google-assessment.png","articleSection":["Chrome Extensions","Gmail Add-ons","Google OAuth"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.gmass.co\/blog\/google-oauth-verification-security-assessment\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.gmass.co\/blog\/google-oauth-verification-security-assessment\/","url":"https:\/\/www.gmass.co\/blog\/google-oauth-verification-security-assessment\/","name":"My feelings on Google's $15,000-$75,000 OAuth verification process and security assessment","isPartOf":{"@id":"https:\/\/www.gmass.co\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.gmass.co\/blog\/google-oauth-verification-security-assessment\/#primaryimage"},"image":{"@id":"https:\/\/www.gmass.co\/blog\/google-oauth-verification-security-assessment\/#primaryimage"},"thumbnailUrl":"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2019\/05\/gmass-google-assessment.png","datePublished":"2019-05-01T03:08:51+00:00","dateModified":"2020-02-06T08:10:13+00:00","author":{"@id":"https:\/\/www.gmass.co\/blog\/#\/schema\/person\/b5fa74f8765b860701158fd77162fff8"},"breadcrumb":{"@id":"https:\/\/www.gmass.co\/blog\/google-oauth-verification-security-assessment\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.gmass.co\/blog\/google-oauth-verification-security-assessment\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.gmass.co\/blog\/google-oauth-verification-security-assessment\/#primaryimage","url":"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2019\/05\/gmass-google-assessment.png","contentUrl":"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2019\/05\/gmass-google-assessment.png","width":2002,"height":934},{"@type":"BreadcrumbList","@id":"https:\/\/www.gmass.co\/blog\/google-oauth-verification-security-assessment\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.gmass.co\/blog\/"},{"@type":"ListItem","position":2,"name":"My feelings on Google&#8217;s $15,000-$75,000 OAuth verification process and security assessment"}]},{"@type":"WebSite","@id":"https:\/\/www.gmass.co\/blog\/#website","url":"https:\/\/www.gmass.co\/blog\/","name":"GMass Blog","description":"Tips and tricks for sending mail merge and mass email campaigns directly from Gmail","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.gmass.co\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/www.gmass.co\/blog\/#\/schema\/person\/b5fa74f8765b860701158fd77162fff8","name":"Ajay Goel","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/f3a70af05bbabe47925150d5a1320540e801b78055a74da20658fc97cd0706a2?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/f3a70af05bbabe47925150d5a1320540e801b78055a74da20658fc97cd0706a2?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f3a70af05bbabe47925150d5a1320540e801b78055a74da20658fc97cd0706a2?s=96&d=mm&r=g","caption":"Ajay Goel"},"description":"Ajay is the founder of GMass and has been developing email sending software for 20 years.","sameAs":["https:\/\/twitter.com\/PartTimeSnob","https:\/\/x.com\/PartTimeSnob"],"url":"https:\/\/www.gmass.co\/blog\/author\/ajay-goel\/"}]}},"_links":{"self":[{"href":"https:\/\/www.gmass.co\/blog\/wp-json\/wp\/v2\/posts\/9167","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.gmass.co\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.gmass.co\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.gmass.co\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.gmass.co\/blog\/wp-json\/wp\/v2\/comments?post=9167"}],"version-history":[{"count":3,"href":"https:\/\/www.gmass.co\/blog\/wp-json\/wp\/v2\/posts\/9167\/revisions"}],"predecessor-version":[{"id":11132,"href":"https:\/\/www.gmass.co\/blog\/wp-json\/wp\/v2\/posts\/9167\/revisions\/11132"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.gmass.co\/blog\/wp-json\/wp\/v2\/media\/9229"}],"wp:attachment":[{"href":"https:\/\/www.gmass.co\/blog\/wp-json\/wp\/v2\/media?parent=9167"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.gmass.co\/blog\/wp-json\/wp\/v2\/categories?post=9167"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.gmass.co\/blog\/wp-json\/wp\/v2\/tags?post=9167"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}