Before launching an application that requests user credentials for the Data Manager API to external users, your Google Cloud project must undergo Google OAuth app verification.
This guide covers the recommended Audience configuration transitions during development and the steps to complete Google OAuth app verification.
App audience phases
Depending on your stage of development, configure the Audience page in the Google Cloud Console with different User type and Publishing status settings. Follow these phases for a smooth transition from initial testing to production launch.
Phase 1: Initial development (Testing)
When starting development and testing basic API requests:
- Publishing status: Set to Testing.
User type:
If your Google Cloud project belongs to a Google Workspace organization and only users in your organization use the app, select Internal.
Otherwise, select External.
Test users: If you set User type to External, click Add users to manually add the Google Accounts you use to generate credentials. Only the listed Google Accounts can authorize the app, and testing limits and token expiration rules apply.
Verification: Not required during testing. If you use External, test users see a warning screen confirming they have test access to an unverified app before proceeding to the consent screen.
Phase 2: Near launch (Verification submission)
When your integration is complete, your user interface is built, and you plan to launch within the next month:
- Publishing status: Transition to In production.
- User type: Set to External if your app serves customers outside your organization, such as advertiser clients.
- Action: Submit your app for verification. The Google OAuth app verification process can take several weeks, so submit as early as possible once your UI is ready.
- Handling early testers: During the verification review, your app remains
unverified for external users. If you need to onboard early beta testers:
- Inform them that they will encounter the unverified app screen.
- Instruct them to proceed by clicking Advanced and then Go to APP_NAME (unsafe).
App verification requirements
To submit your app for verification in the Verification Center, configure your Google Auth Platform settings and prepare the required verification materials.
Verification scopes
On the Data Access page, request only the scopes your application requires. The Data Manager API uses sensitive scopes:
https://www.googleapis.com/auth/datamanager(Primary scope)https://www.googleapis.com/auth/datamanager.partnerlink(For partner links)
Contact information
The Google OAuth verification team sends all communication to the project owners and project editors configured in your Google Cloud project. Keep these contact details up to date in the Google Cloud Console so you don't miss requests for information.
Demonstration video
Provide a link to a publicly accessible demonstration video (such as an unlisted YouTube video or a public Google Drive link) showing how your application uses the requested scopes.
Make sure the video meets the App functionality demonstration video requirements.
Phase 3: Ready to launch (Verified)
Once the Google OAuth verification team notifies you that they have approved your app verification request, no action is required. Your app is now verified, and external users can authorize it without encountering the unverified app warning screen.