OAuth PreflightRun Free Check

OAuth verification preflight

Example Calendar Assistant

A prioritized view of website, scope, branding, domain, and demo-material readiness.

Report summary

2
Critical findings
2
High findings
2
Medium findings
3
Passed checks

Findings

6 prioritized issues

Privacy policy link is missing from server-rendered homepage HTML

Critical

Why it matters

Automated reviewers may not detect links inserted only after JavaScript executes.

Recommended fix

Render the link in the initial HTML response and confirm it is visible to anonymous visitors.

Related verification area

Homepage requirements

Gmail read-only scope is not connected to a visible product feature

Critical

Why it matters

Google requires a clear explanation of why each sensitive or restricted scope is necessary.

Recommended fix

Map the scope to a specific user action and demonstrate that action in the verification video.

Related verification area

Scope justification

App name differs between the consent screen and homepage title

High

Why it matters

Branding inconsistencies can make it difficult to verify that the website represents the OAuth application.

Recommended fix

Use one consistent product name across the consent screen, title metadata, page heading, and policies.

Related verification area

Brand verification

Demo video is not accessible without authentication

High

Why it matters

Reviewers need to access the complete consent and feature flow without requesting additional permissions.

Recommended fix

Use an unlisted or public video URL and test it in a signed-out browser session.

Related verification area

Demo video

Terms of Service is hosted on an unrelated third-party domain

Medium

Why it matters

External domains can create ownership and authorized-domain questions.

Recommended fix

Host the terms page on a domain owned and verified by the application publisher.

Related verification area

Domain ownership

Developer contact email uses a different product domain

Medium

Why it matters

Inconsistent contact information can complicate reviewer communication.

Recommended fix

Use a monitored email address associated with the primary product or company domain.

Related verification area

Developer contact information

Passed checks

Homepage returns a successful HTTPS response
Privacy policy is publicly accessible
OAuth scopes are listed in the submitted configuration

Check your own application

Preview the same finding format with your public app details.

Run Your Free Check