OAuth verification stuck — no Trust & Safety email received (PII Removed by Staff)

Hi Google team,

Our OAuth verification is stuck at “Pending developer action”. The
Verification Center instructs us to reply to the Trust and Safety email
thread, but no such email was ever received.

Project: (PII Removed by Staff)
App name: Medly
Client ID: (URL Removed by Staff)
Homepage: (URL Removed by Staff)
Privacy policy: (URL Removed by Staff)
Sensitive scopes: calendar.readonly, contacts.readonly
Submitted: Jul 23, 2026

Verification status: 4 of 5 checks passed — Homepage requirements, Privacy
policy requirements, Branding guidelines, and Request minimum scopes. Only
“App functionality” was flagged, on Jul 24, 2026, with three issues:

  1. “Your demo video does not show the OAuth consent flow.”
  2. “The Trust and Safety team require authorized login credentials to
    access the application.”
  3. “The Trust and Safety team are unable to access the OAuth consent
    process without first providing additional information.”

Issues 2 and 3 both instruct us to reply to an email from the Trust and
Safety team. We have searched all three developer contact addresses,
including spam and trash folders, and no email from Google regarding this
verification has been received. All three addresses are in active daily
use. We have no thread to reply to.

Regarding issue 1: we have re-checked the demo video. It is unlisted,
accessible in a logged-out incognito session, and contains both consent
screens — calendar.readonly at 1:27 and contacts.readonly at 2:46 — in
English, with the OAuth Client ID visible in the address bar. The link in
the Data Access page points to this video and loads correctly.

One point that may be relevant to how issue 1 was assessed: Medly uses
incremental authorization, as Google recommends. Basic sign-in scopes are
granted when the user signs in to the application, and each sensitive scope
is requested separately, only when the user enables that specific feature.
As a result, both consent screens read “Medly wants additional access” and
display an “already has some access” summary rather than a full scope list.

Medly is a B2B clinic management platform with no public self-signup, which
is why a reviewer cannot register an account independently. We can prepare
a dedicated demo environment with synthetic data only, plus step-by-step
instructions for reaching both consent screens, and provide these as soon
as a communication channel is available.

Could you please either resend the Trust and Safety email thread to our
developer contact addresses, or advise how we can deliver test credentials
securely? We would prefer not to post credentials publicly.

Thank you,
Evgeni G
CEO, Medly Systems Ltd.

1 Like