-
-
Notifications
You must be signed in to change notification settings - Fork 336
Description
We are writing to inform you that OAuth out-of-band (OOB) flow will be
deprecated on October 3, 2022, to protect users from phishing and app
impersonation attacks.What do I need to know?
Starting October 3, 2022, we will block OOB requests to Google's OAuth 2.0
authorization endpoint for existing clients. Apps using OOB in testing mode
will not be affected. However, we strongly recommend you to migrate them to
safer methods as these apps will be immediately blocked when switching to
in production status.Note: New OOB usage has already been disallowed since February 28, 2022.
Below are key dates for compliance
September 5, 2022: A user-facing warning message may be displayed to
non-compliant OAuth requests
October 3, 2022: The OOB flow is blocked for all clients and users will see
the error page.