I found our Google App's OAuth permissions were decertified today after seeing some users receiving permissions errors. Google did this without so much as an email to us. Upon digging in further, I discovered that they changed their policy on February 7th, effectively revoking our existing app permissions, and requiring anyone requesting those permissions go through a 3rd party security audit (3P) at the cost of (in their estimation) $15,000 to $75,000 before getting permissions back. They also state this process will take 4-6 weeks. This is not specific to us, as noted in the post below:<p>https://support.google.com/cloud/answer/9110914?authuser=2<p>As of now, we are limited to 100 users connecting accounts before we will no longer be able to accept additional users. Maybe we'll get a helpful response from Google, but considering the lack of notice, I doubt it.<p>This is why you can't build on a platform like Google; you never know when they will suddenly change policy (or shutdown) without notice and shut you down. No company can stop accepting users for 4-6 weeks while a security audit goes on and stay in business.
This was announced last year: <a href="https://www.theregister.co.uk/2019/02/11/google_gmail_developer/" rel="nofollow">https://www.theregister.co.uk/2019/02/11/google_gmail_develo...</a><p>It was a reaction to apps & extensions abusing access to users’ email.