Google OAuth: Google hasn't verified this app / This app isn't verified
The OAuth app requests sensitive or restricted scopes and hasn’t passed Google’s verification, so users see a warning screen.
Seen on:
REST API
Meaning
Users can proceed via Advanced → Go to app (unsafe) for limited user counts, but production apps with sensitive scopes (Gmail, Drive) must complete verification (and possibly a security assessment).
Common causes
- Sensitive/restricted scopes without verification
- Brand/domain not verified
- App recently changed scopes
⚡ Quick fix
- Submit the app for verification
- Use narrower, non-sensitive scopes (e.g. drive.file)
- Verify your domain in Search Console
Detailed fix by platform
Google Cloud
# APIs & Services → OAuth consent screen → Data access: review scopes; Verification center → Prepare for verification
How to diagnose
- Scopes — Which are sensitive?
- Status — Verification status
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
Similar errors
- Access blocked: has not completed the Google verification process Google OAuth: Error 403: access_denied — The developer hasn't given you access to this app / has not completed the Google verification process
- auth/popup-closed-by-user Firebase Auth: auth/popup-closed-by-user / auth/popup-blocked / auth/cancelled-popup-request
- auth/unauthorized-domain Firebase Auth: auth/unauthorized-domain — This domain is not authorized for OAuth operations for your Firebase project
Most viewed in Authentication
Other ways to find it
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 7 Oct 2026