Before you submit
Google OAuth verification checklist
Review your public website and prepare your submission details.
Run a free homepage preflight, then complete the manual checks.
Public homepage and app purpose
- What to check
- Open your homepage without signing in. Explain what the app does and how users benefit, so a reviewer can understand the product beyond its login screen.
- A common issue
- The homepage is inaccessible, shows only a sign-in form, or never explains the app’s purpose.
- Whether the free scan covers it
- Partial — the free scan checks public accessibility and initial HTML. It does not run JavaScript or judge whether your app’s purpose is clear. Review the rendered page and its wording yourself.
App name, branding and domains
- What to check
- Compare your website’s app name and branding with your Google Cloud Console submission. Confirm authorized domains and domain ownership in Google’s tools.
- A common issue
- A renamed app still has an old page title, or a submitted policy link points to an unexpected origin.
- Whether the free scan covers it
- Partial — the free scan can flag obvious app-name, metadata, and origin differences. It cannot access Console, compare logos, or verify domain ownership. A different origin is a prompt to investigate, not proof of a Google requirement violation.
Privacy policy and optional Terms
- What to check
- Make the privacy policy easy to find from your homepage and confirm it matches the URL in Console. Read the policy to check that it explains your app’s use of Google user data. Check Terms if your app provides them; Terms are not a universal requirement for every app.
- A common issue
- The submitted privacy URL differs from the homepage link, or the policy wording no longer reflects the app’s data use.
- Whether the free scan covers it
- Partial — the free scan compares submitted Privacy and optional Terms URLs with links in the homepage’s initial HTML. It does not fetch policy pages or review their wording, and it cannot read the URLs configured in Console.
OAuth scopes
- What to check
- Confirm each scope’s current classification in Google Cloud Console. Choose the minimum permissions needed for implemented features and prepare scope justifications explaining why narrower access will not work.
- A common issue
- A submission requests broad access for a future feature or gives no reason for needing it.
- Whether the free scan covers it
- Partial — the free scan provides basic scope categories only. Google API scopes are not all sensitive or restricted. Console classification, minimum-permission selection, and scope justification need manual confirmation.
Demo video and reviewer instructions
- What to check
- When required for your submission, prepare a short walkthrough showing the OAuth consent flow and the features that use each requested scope. Use the submitted app’s branding, show the consent screen in English, and provide clear steps for a reviewer to follow.
- A common issue
- The video omits the consent flow, or the reviewer cannot reproduce the feature that needs a requested scope.
- Whether the free scan covers it
- No — prepare and test these materials manually. The free scan does not inspect demo videos, test steps, or submission evidence, and it does not generate them.
What this preflight cannot fix
- What to check
- Review your status in Google’s Branding page and Verification Center. Keep project contacts current and follow Google’s instructions for reviewer questions or re-review.
- A common issue
- A review is waiting for a response, a review email is missing, or a Console setting needs attention.
- Whether the free scan covers it
- No — the free scan cannot change Google’s internal review queue, recover missing review emails, handle re-review, or fix internal Console configuration. OAuth Preflight cannot accelerate review or guarantee approval.
Start with your public website
Run the free scan, review its findings, and return to the manual checks before submitting.
Run Free Website Preflight