I’ve configured an oauth app for simple SSO with google accounts. That’s all it does, the standard sign-in with google button.
When I go to the configuration about what scopes it’s configured for this is what I see (note that sensitive and restricted are empty)
From everything I read and have seen this should exclude me from the more cumbersome validation methods. (I really don’t want to make a youtube video explaining that I’m using the Oauth stuff for sso…)
However I keep getting this pop up when I hit the publish app button
Anyone have any ideas on what is going on here or if there are things outside of just the scopes that determine if you need the more intense validation?
Thanks (had to stick a label on none of them really fit, let me know if I’m in the wrong place but really not sure where else I would go)

