Skip to content

Do I need Google app verification for Applane?

The OAuth client the extension signs in with is yours: it lives in your GCP project and its consent screen is set to Internal. Google exempts Internal apps from app verification and from the “unverified app” warning, whatever scopes they use. Applane owns no Google client that touches your data, so there is no Applane app in Google’s verification queue and no CASA assessment to renew.

The rest of this page is the detail for a security reviewer.

An OAuth consent screen has a user type. External apps can be used by any Google account and must pass Google’s app verification before they can request sensitive scopes; restricted scopes also need a CASA security assessment by a Google-authorised lab, every year. Internal apps can only be used by accounts in the project’s own Workspace organisation, and Google skips all of that: no review, no assessment, no warning screen, any scope.

Internal is only available when the project belongs to a Workspace organisation, which is exactly your situation. See Prerequisites.

The extension asks for three sensitive scopes and one restricted one (drive.readonly), plus sign-in. Each is explained in the Scopes reference. All of them are granted to your client, under your app name. Your Workspace admin can see and revoke the grant per user in the Admin console under that name.

The Applane admin console signs admins in with Applane’s own Google client. It uses openid, email and profile, which are non-sensitive scopes that need no verification. It reads the admin’s email address and nothing else. See Third-party app access if your API controls block it.

When asked “have you completed Google’s restricted scope verification”, the accurate answer is: “Not applicable. Each customer’s OAuth client is Internal to their own organisation, which Google exempts from verification and CASA. Applane holds no Google client with access to customer data.”

For AI agents: llms.txt, llms-full.txt, or any page with a .md suffix.