승인에 OAuth 2.0을 사용하는 경우 Google에서 사용자에게 프로젝트 및 정책 요약과 요청된 승인 액세스 범위가 포함된 동의 화면을 표시합니다. 앱의 OAuth 동의 화면을 구성하면 사용자 및 앱 검토자에게 표시되는 항목이 정의되고 나중에 게시할 수 있도록 앱이 등록됩니다.
앱에 부여된 액세스 수준을 정의하려면 승인 범위를 식별하고 선언해야 합니다. 승인 범위는 Google Workspace 앱 이름, 액세스하는 데이터 종류, 액세스 수준을 포함하는 OAuth 2.0 URI 문자열입니다. 범위는 사용자의 Google 계정 데이터를 비롯한 Google Workspace 데이터와 상호작용하기 위한 앱의 요청입니다.
앱이 설치되면 사용자에게 앱에서 사용하는 범위를 확인하라는 메시지가 표시됩니다. 일반적으로 가능한 한 가장 좁은 범위를 선택하고 앱에 필요하지 않은 범위는 요청하지 않아야 합니다. 사용자는 제한적이고 명확하게 설명된 범위에 더 쉽게 액세스 권한을 부여합니다.
OAuth 2.0을 사용하는 모든 앱에는 동의 화면 구성이 필요하지만 Google Workspace 조직 외부 사용자가 사용하는 앱의 범위만 나열하면 됩니다.
도움말: 필수 동의 화면 정보를 모르는 경우 출시 전에 자리표시자 정보를 사용할 수 있습니다.
민감하지 않은 범위, 민감한 범위, 제한된 범위의 세 섹션에 나열된 범위를 검토합니다. '민감한 범위' 또는 '제한된 범위' 섹션에 나열된 범위의 경우 불필요한 추가 검토를 방지하기 위해 민감하지 않은 대체 범위를 파악해 보세요.
일부 범위에는 Google의 추가 검토가 필요합니다. Google Workspace 조직에서 내부적으로만 사용하는 앱의 경우 동의 화면에 범위가 나열되지 않으며 제한되거나 민감한 범위를 사용하는 데 Google의 추가 검토가 필요하지 않습니다. 자세한 내용은 범위 카테고리를 참고하세요.
[null,null,["최종 업데이트: 2025-08-04(UTC)"],[[["\u003cp\u003eWhen using OAuth 2.0 for authorization with Google Workspace APIs, you need to configure an OAuth consent screen that defines the access your app requests and displays this information to users.\u003c/p\u003e\n"],["\u003cp\u003eYou should carefully select authorization scopes to provide your app with the minimum necessary access to Google Workspace data, as users are more likely to grant consent to apps with limited and clearly defined scopes.\u003c/p\u003e\n"],["\u003cp\u003eAll apps require an OAuth consent screen, but explicitly listing scopes is necessary only for apps used outside your organization, and certain scope categories necessitate additional reviews by Google.\u003c/p\u003e\n"],["\u003cp\u003eTo configure your OAuth consent screen, you'll need to provide app details, select the user type (internal or external), define the necessary scopes, and potentially add test users if applicable.\u003c/p\u003e\n"],["\u003cp\u003eSensitive and restricted scopes require additional verification and security assessments due to their access levels to user data, so consider using non-sensitive alternatives whenever possible.\u003c/p\u003e\n"]]],["OAuth 2.0 requires configuring a consent screen, defining the app's project details, policies, and authorization scopes. Scopes, which specify the level of data access, should be narrowly defined. Configuration involves setting the app name, support email, audience, and contact information in the Google Cloud console. If the app is for external users, you must add and select appropriate scopes, choosing the least sensitive option. Different scope categories—non-sensitive, sensitive, and restricted—have varied review requirements.\n"],null,["When you use OAuth 2.0 for authorization, Google displays a consent screen to\nthe user including a summary of your project, its policies, and the requested\nauthorization scopes of access. Configuring your app's OAuth consent screen\ndefines what is displayed to users and app reviewers, and registers your app\nso you can publish it later.\n| **Note:** Some Google Workspace APIs, such as the Google Drive API, have documentation covering API-specific authentication and authorization information. Ensure you read that documentation before continuing with this page.\n\nTo define the level of access granted to your app, you need to identify and\ndeclare *authorization scopes*. An authorization scope is an OAuth 2.0 URI string\nthat contains the Google Workspace app name, what kind of data it accesses, and\nthe level of access. Scopes are your app's requests to work with Google Workspace data, including\nusers' Google Account data.\n\n\nWhen your app is installed, a user is asked to validate the scopes used\nby the app. Generally, you should choose the most narrowly focused scope\npossible and avoid requesting scopes that your app doesn't require. Users more\nreadily grant access to limited, clearly described scopes.\n\nAll apps using OAuth 2.0 require a consent screen configuration, but you only\nneed to list scopes for apps used by people outside your Google Workspace\norganization.\n\n**Tip:** If you don't know required consent screen information, you can use\nplaceholder information prior to release.\n\nFor security reasons, you can't remove the OAuth 2.0 consent screen\nafter you've configured it.\n\nConfigure OAuth consent\n\n1. In the Google Cloud console, go to Menu menu \\\u003e **Google Auth platform** \\\u003e **Branding** .\n\n [Go to Branding](https://console.cloud.google.com/auth/branding)\n2. If you have already configured the Google Auth platform, you can configure the following OAuth Consent Screen settings in [Branding](https://console.cloud.google.com/auth/branding), [Audience](https://console.cloud.google.com/auth/audience), and [Data Access](https://console.cloud.google.com/auth/scopes). If you see a message that says **Google Auth platform not configured yet** , click **Get Started**:\n 1. Under **App Information** , in **App name** , enter an **App name**.\n 2. In **User support email**, choose a support email address where users can contact you if they have questions about their consent.\n 3. Click **Next**.\n 4. Under **Audience**, select the user type for your app.\n 5. Click **Next**.\n 6. Under **Contact Information** , enter an **Email address** where you can be notified about any changes to your project.\n 7. Click **Next**.\n 8. Under **Finish** , review the [Google API Services User Data Policy](https://developers.google.com/terms/api-services-user-data-policy) and if you agree, select **I agree to the Google API Services: User Data Policy**.\n 9. Click **Continue**.\n 10. Click **Create**.\n 11. If you selected **External** for user type, add test users:\n 1. Click **Audience**.\n 2. Under **Test users** , click **Add users**.\n 3. Enter your email address and any other authorized test users, then click **Save**.\n3. If you're creating an app for use outside of your Google Workspace\n organization, click **Data Access** **\\\u003e** **Add or Remove Scopes**. We recommend the following best practices when\n selecting scopes:\n\n - Select the scopes that provide the minimum level of access required by your app. For a list of available scopes, see [OAuth 2.0 Scopes for Google APIs](/identity/protocols/oauth2/scopes).\n - Review the scopes listed in each of the three sections: non-sensitive scopes, sensitive scopes, and restricted scopes. For any scopes listed in the \"Your sensitive scopes\" or \"Your restricted scopes\" sections, try to identify alternative non-sensitive scopes to avoid unnecessary additional reviews.\n - Some scopes require additional reviews by Google. For apps used only internally by your Google Workspace organization, scopes aren't listed on the consent screen and use of restricted or sensitive scopes doesn't require further review by Google. For more information, see [Scope categories](/workspace/guides/configure-oauth-consent#scope_categories).\n4. After selecting the scopes required by your app, click **Save**.\n\n\nFor more information about configuring OAuth consent, see\n[Get started with the Google Auth platform](https://support.google.com/cloud/answer/15544987).\n\nScope categories\n\nSome scopes require additional reviews and requirements\nbecause of the level or type of access they grant. Consider the following types\nof scopes:\n\n| | | | [Basic app verification](https://support.google.com/cloud/answer/9110914#ver-prep&zippy=%2Csteps-to-prepare-for-verification) required | [Additional app verification](https://support.google.com/cloud/answer/9110914#ver-prep&zippy=%2Csteps-to-submit-your-app) required | [Security assessment](https://support.google.com/cloud/answer/9110914#sec-assess&zippy=%2Csecurity-assessment) required |\n|---|------------------------------------------|-------------------------------------------------------------------------------------|----------------------------------------------------------------------------------------------------------------------------------------|------------------------------------------------------------------------------------------------------------------------------------|-------------------------------------------------------------------------------------------------------------------------|\n| | **Non-sensitive scopes** *(recommended)* | Grant access only to limited data that's immediately relevant to a specific action. | check | --- | --- |\n| | **Sensitive scopes** | Grant access to personal user data, resources, or actions. | check | check | --- |\n| | **Restricted scopes** | Grant access to highly-sensitive or extensive user data or actions. | check | check | check |\n\nNext step\n\n[Create access credentials](/workspace/guides/create-credentials) for your app."]]