Skip to content

chore: complete Google Health verification and CASA #613

Description

@JeffOtano

Outcome

Complete Google's external launch requirements for Roni's Google Health integration after the production Fitbit feature shipped and passed a real OAuth and sync flow in #91.

Current state

  • Google Health API is enabled.
  • Roni requests only activity/fitness, health metrics/measurements, and sleep read-only scopes.
  • Production OAuth credentials and callback are configured.
  • A production account completed OAuth with all three scopes and a manual sync succeeded after fix: use documented Fitbit filter names #611.
  • OAuth branding now uses Roni and roni.coach; domain ownership is verified in Search Console.
  • Branding re-verification has been submitted and is currently in progress.

Remaining external gates

  • Wait for Google branding re-verification to complete.
  • Submit restricted-scope data-access verification with the required end-to-end demo video and scope-specific justifications.
  • Complete the Google-requested CASA security assessment and submit its Letter of Validation.
  • Confirm the production consent screen shows verified Roni branding and no unverified-app warning.
  • Validate a public-user OAuth flow after approval and monitor Google Health usage/error rates.

Acceptance criteria

  • Google Cloud shows branding and data access verified.
  • The required CASA assessment is accepted.
  • Production OAuth no longer presents the unverified-app warning.
  • A production connect and sync succeeds after verification without exposing credentials or user identifiers.

Tracked separately from #91 because the product integration and runtime configuration are complete; this issue covers Google-controlled compliance and launch approval only.

Metadata

Metadata

Assignees

No one assigned

    Labels

    area: productUser-facing product backlog outside the AI infrastructure epicenhancementImprovement to an existing capabilitypriority: lowLow priority work

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions