Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Scan for outdated or missing drivers - takes under a minute3Clear out junk files and repair common Windows errorsiTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
If your external Google OAuth app is in Testing, refresh tokens generally expire after seven days when the app requests scopes beyond basic identity information. That can break scheduled jobs and other recurring work. Before relying on a token in production, publish the OAuth app and check whether its scopes require verification. Publishing does not make tokens permanent or complete every review.
When does the seven-day refresh-token limit apply?
Google documents this limit for OAuth projects configured for an external user type and a publishing status of Testing. It generally applies when the app requests scopes beyond basic identity information. The exception is an app requesting only basic identity scopes for name, email, and profile. See Google’s OAuth 2.0 documentation for the rule and its scope qualification.
A refresh token lets an application obtain new access tokens without asking the user to authorize again. If a scheduled task depends on a refresh token that expires, the task can lose access until the user completes authorization again and the app obtains a usable token.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →What Testing status means for users and tokens
Testing is a development status, not a dependable production state for external apps. In general, an external app in Testing can authorize only Google Accounts added as test users, and Google documents a 100-test-user cap. Google notes an exception for apps requesting only basic identity scopes. User type and publishing status are distinct settings: external describes who can use the app, while Testing describes its publishing status. Google Workspace or Cloud Identity administrators may also apply access restrictions. See Google’s OAuth user-type and publishing guidance.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
The seven-day limit concerns the refresh token, not necessarily the access token’s lifetime. Do not assume that a token issued during Testing will continue to support a recurring integration simply because the initial authorization succeeded.
How to prepare an OAuth app for scheduled production work
- Review the project’s user type and status. In Google Cloud, open the project’s OAuth consent screen settings and confirm whether the app is external or internal and whether its publishing status is Testing or In production. The applicable options and access rules depend on those settings.
- Inventory the scopes the live app actually needs. Remove unnecessary scopes and identify whether any requested scopes are sensitive or restricted. Verification requirements depend on the user type, branding, and scopes; publishing alone does not satisfy every review requirement.
- Configure the production OAuth client for the live app. Check that its client settings, redirect URIs, and authorized origins match the production environment. Google recommends keeping testing and production in separate OAuth projects; see Google’s production-readiness guidance.
- Publish the consent screen when the app is ready. Change the publishing status to In production in the OAuth consent screen settings. Then complete any applicable verification steps for the app’s branding or scopes. A published app may still display warnings or face user limitations if required verification has not been completed. See Google’s OAuth verification guidance.
- Authorize and validate the production integration. Have the intended user authorize the production app, store its credentials securely, and confirm that the scheduled process can refresh access and handle authorization errors. Do not rely on a testing token as proof that the production configuration is ready.
Does publishing make refresh tokens permanent?
No. Google says refresh tokens for published apps generally do not expire solely because of the seven-day Testing rule, but they can still stop working if revoked or unused for a prolonged period—typically six months. Treat refresh tokens as credentials that can become invalid, and build the integration to detect authentication failures and provide a way to reauthorize. Google’s OAuth documentation describes token behavior and the relevant qualifications.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Publishing, verification, and user type are different
- Publishing status: Testing limits an external app to test users, subject to the documented exception for basic identity scopes. In production permits broader availability, subject to applicable policies and verification.
- Verification: Some apps requesting sensitive or restricted scopes need Google review. An app can be published without having completed all required verification, which may leave users with warnings or access limitations.
- User type: Internal is for users within the relevant Google Workspace or Cloud Identity organization. External is for users who may be outside it. An organization’s administrator can impose additional restrictions.
Brand verification and scope verification are separate readiness considerations. Check Google’s verification guidance against the actual branding and scopes in your project rather than assuming that publishing completes every review.
Free tools Windows power users keep installed
One-click scans. No signup required.
Quick Recap
Best Value
- POWERFUL SECURITY KEY: The YubiKey 5C Nano is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C Nano secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: The YubiKey 5C Nano is designed to stay plugged into your device via USB-C. Simply tap it to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Rank #4
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Rank #3
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

