App review
People trust the Motaware consent screen. Review lets Motaware check that an app is what it says it is, and that it asks only for the access it needs, before it reaches many people or gets their app data.
Unverified apps
Every new client starts unverified. An unverified app:
- can ask only for the sign-in scopes
openid email profile offline_access; - can be authorized by at most 100 people besides you (people who already authorized it keep working);
- shows an "unverified app" notice on the consent page;
- has its logo hidden; the consent page shows the first letter of the app name instead.
What verification gives you
- The unverified notice goes away and your logo is shown.
- No user limit.
- Any developerapi.motaware.com permissions Motaware approved for the app.
Permissions you can ask for today:
| Scope | People see | Opens |
|---|---|---|
account.read | See your profile, email address and Motaware plan | GET /v1/me, GET /v1/me/plan |
Scopes for Motaware app data (Calendar, Contacts, Tasks, Notes, Drive, Docs) are coming.
Before you send a request
Set these in the client's settings first:
- an https homepage;
- a privacy policy URL;
- a support email;
- proof that you control the homepage's domain. Add a DNS TXT record, then click Check DNS on the Verification page. The console shows your token.
| Record | Value |
|---|---|
| Name | _motaware-verification.<homepage host> |
| Type | TXT |
| Value | motaware-verify=<token> |
For a homepage at https://app.example.com, the record is _motaware-verification.app.example.com. DNS changes can take a while to show up; if the check fails, try again a few minutes later.
How to request a review
- In the console, open the project, then the client, then Verification.
- Pick the permissions you need. This is optional: you can ask for verification only.
- Describe what your app does and why it needs each permission (50 to 4000 characters).
- Optionally add a demo link: a video or page showing your sign-in and how you use the data.
- Click Send for review.
What happens next
- Motaware staff review the request, usually within a few business days. You get an email either way.
- A rejection comes with a reason. Fix what it says and send the app again.
- You can withdraw a pending request at any time.
Changes after verification
The consent screen is what Motaware approved. Changing the app's name, logo, homepage or privacy policy sends it back to review and removes its approved permissions, so people never see an approved app turn into something else. Request a review again once you've made the change.
A verified app that asks for more permissions stays verified, with the permissions it already has, while the new request waits.
Asking for a scope you weren't approved for
If your app asks for a scope it isn't approved for, the authorization fails and Motaware redirects back to you with
error=invalid_scope. Ask only for sign-in scopes plus the permissions shown as approved on the client's Verification page.
Suspension
Motaware can suspend an app or a whole project, or revoke an API key, if it breaks the Developer Terms. Sign-in and token refresh stop at once, and calls to developerapi.motaware.com stop within about 30 seconds. You get an email with the reason. If you think it's a mistake, write to help@motaware.com.