Earlier quoted context omitted.
The wording seems to imply that if, on a yearly whim, someone at Google decides to "empanel" a security assessment team, you have no choice, you will not necessarily be asked permission and you will be paying that invoice whether or not you needed that assessment. Do you have evidence - in writing - to the contrary from a Google official? Abridged wording and my non-lawyer interpretation below in case I'm not clear:…
> you will be paying that invoice whether or not you needed that assessment They don't just send you a bill for $10k. You can opt-out of the yearly audit by removing your use of restricted scopes. But yes, it is a yearly required audit, and they're serious about it. This limits the kind of apps that can be built on Gmail (basically – no free apps), but it is undoubtedly better for end users. Having gone through the p…
Software that, for now, under Google's current interpretation of the rules, is allowed to use their OAuth without paying these fees.
The question I'm asking is, what happens next year when Google decides to silently change their interpretation of the rules? Do you, as a FOSS email client writer working on JohnnyMail, risk a massive yearly bill of 1/6th or more of your salary that you are contractually obliged to pay - or just say "Sorry Google, you've outpriced me" while their interpretations are still favourable?
It's not "undoubtedly better for end users" that free email apps be excluded from Gmail. It's not better for end users that open source software developers are given a sword of Damocles hovering above their heads. Sure, it's undoubtedly better if these free apps can be guaranteed to be secure, it would be even better if Google could do that in a way that didn't cost a massive amount or a surprise bill.
I'm glad you had the resources to be able to go through the process, and that you found it a useful process to go through. But it doesn't justify the uncertainty.