Google OAuth verification live reviewer surface

YAO LifeOS Gmail readonly live review

This public page has no LifeOS login, no Cloudflare Access one-time PIN, no shared password, no phone verification, and no credit-card step. It demonstrates the submitted Gmail readonly scope directly in the browser with the reviewer-signed-in Google account.

Requested scope

This live review flow requests exactly https://www.googleapis.com/auth/gmail.readonly. It uses the access token only in this browser session to fetch one capped Gmail item, derive a sanitized LifeOS source-pointer preview, and display readback metrics. It does not send the token to LifeOS, store the token, store Gmail bodies, or mutate Gmail state.

Loading Google Identity Services...

Live readback

not_run

Reviewer steps

  1. Click Start Gmail readonly OAuth.
  2. Use a Google reviewer account and complete the OAuth consent flow.
  3. When the permission screen is shown, expand the services if needed and confirm that Gmail readonly is visible.
  4. After consent, click Run Gmail readonly readback if it did not run automatically.
  5. Confirm that the page fetches Gmail data and returns only sanitized counts and source-pointer preview metadata.