Skip to main content

google-oauth-verification-preflight

PyPI

Check your OAuth consent screen configuration before submitting for verification, so you are not declined on something mechanical.

Standard library only — no runtime dependencies at all.

pip install google-oauth-verification-preflight      # from PyPI, Python 3.9+
google-oauth-verification-preflight consent.json

# or straight from a clone, no install:
git clone https://github.com/duke5am/google-oauth-verification-preflight
cd google-oauth-verification-preflight
python3 check_consent.py consent.json

The clone and the installed package run the same code: check_consent.py is a thin wrapper around google_oauth_verification_preflight/cli.py.

  ERROR   homepage_url points at localhost - the reviewer cannot reach it, and
          this is an immediate rejection
  ERROR   authorized_domains contains a placeholder (example.com)
  ERROR   redirect_uri host 'otherapp.com' is not covered by any authorized_domains
          entry ['example.com']
  WARN    2 scope(s) need their classification confirmed against Google's current
          list BEFORE submitting: gmail.readonly, drive. This tool does not guess
          classifications - marking a restricted scope as sensitive (or the reverse)
          can cost weeks.
  WARN    no scope_justification written for gmail.readonly - this is the field most
          submissions are declined on

What it catches

  • localhost or non-https homepage / privacy policy — the reviewer cannot reach it, and it is an immediate rejection
  • placeholder authorized domains (example.com, yourdomain)
  • a redirect URI whose host is not covered by an authorized domain
  • an app name too long for the consent screen
  • scopes with no written justification — the field most submissions are declined on
  • sensitive/restricted scopes present but no demo video

What it refuses to do

It does not guess scope classifications. Scope sensitivity changes and getting it wrong cuts both ways, so the tool marks anything non-obvious as needing lookup against Google's current published list rather than asserting a classification. Only openid, email and profile are stated as non-sensitive.

Exit codes: 0 clean · 1 warnings only · 2 errors.

Templates

templates/ has fillable versions of what the submission actually asks for:

  • app-description.md
  • scope-justification.mdone block per scope, which is where submissions fail
  • demo-video-script.md — shot by shot, including what gets a video rejected
  • homepage-requirements.md — what the reviewer checks on your homepage
  • privacy-policy-template.md — the disclosures Google requires for OAuth apps
  • rebuttal-responses.md — replies to "we need more information"

COMMON-REJECTIONS.md lists symptom → cause → fix. PRE-SUBMISSION-CHECKLIST.md is ordered cheapest-fix-first.

Read this first

Not affiliated with Google and not an official Google document.

Requirements change. Verify against Google's current published documentation, especially scope classifications — the highest-risk item here.

Not legal advice. The privacy policy needs review for your jurisdiction and your actual data practices; it is a drafting aid, not a substitute for that review.

Google's Limited Use requirements govern how you may use data obtained through Google APIs.

A restricted-scope security assessment has a cost and is not instant — do not budget from any number here; get current published terms.

No timeline is given, deliberately. Nobody outside Google can promise a review duration.

No approval rate or rejection rate is claimed, because no reliable public figure exists. The rejection patterns here are recurring observations, not statistics.

The full pack

Adds the scope decision guide (how to avoid verification entirely — often cheaper than the security assessment), the process walkthrough, and the complete rejection catalogue.

  • spf-dkim-dmarc-audit — Audit SPF, DKIM and DMARC against live DNS, with recursive SPF lookup counting and the exact record to publish. Tested against 124 real domains. (if you were searching for "spf dkim dmarc check")

All 28 tools in this set, grouped by what they check: dev-tools-index

If you arrived here searching for one of these, this is the tool: google oauth verification rejected · sensitive scopes verification · oauth consent screen requirements · casa security assessment

→ More developer tooling like this: duke5am.gumroad.com

Release files for google-oauth-verification-preflight 0.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for google-oauth-verification-preflight 0.1.0
File Size Uploaded
google_oauth_verification_preflight-0.1.0.tar.gz 62.0 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for google-oauth-verification-preflight 0.1.0
File Interpreter ABI Platform
google_oauth_verification_preflight-0.1.0-py3-none-any.whl Python 3 none any Details

Total release size: 73.9 kB

Release files / google_oauth_verification_preflight-0.1.0.tar.gz

Download URL google_oauth_verification_preflight-0.1.0.tar.gz
Size 62.0 kB
Tags Source
SHA-256 checksum
How to use checksums
1b3a4176dd835f24d1b56e26e2dc402f65acca8f45319540df3f5c9180521617
BLAKE2b-256 checksum
How to use checksums
75a7242465773b2f9e053da72f88ff5528db213c58be3ec9005934af58253d57
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.5

Release files / google_oauth_verification_preflight-0.1.0-py3-none-any.whl

Download URL google_oauth_verification_preflight-0.1.0-py3-none-any.whl
Size 11.8 kB
Tags Python 3
SHA-256 checksum
How to use checksums
3935912528f63e8e2a91bbea009e83ac4505fd773ff5d1711a3eda64549721af
BLAKE2b-256 checksum
How to use checksums
8442864605fa831a4323284c2ac62f02ce15a88e677ca16ad71eb2253cdf8ea2
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.5

Release history Release notifications | RSS feed

This release

0.1.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page