Skip to main content
  • Always validate the authentication data received
  • Use HTTPS for all redirect URLs
  • Request only the scopes you actually need
  • Provide a clear privacy policy for cloud storage (if in use)