In the trenches of agent development, access is everything. But for Tin, the creator of Seneschal, a small open-source broker that mediates between AI agents and Google Workspace, the cost of production access is a barrier he’s choosing not to climb. Built in April, Seneschal acts as a security choke point, holding OAuth tokens and requiring manual approval for every write action, ensuring agents never hold the keys to the kingdom directly.
The Wall of Restricted Scopes
Google’s OAuth tier system is a minefield for indie devs. While 'Sensitive' scopes like sending mail require a standard review, 'Restricted' scopes—which include reading inboxes and Drive data—trigger a much heavier process. Seneschal requires three Restricted scopes to function as a true broker. Because these tokens reside on Seneschal’s servers, Google mandates a security assessment by an authorized lab, specifically using the CASA framework. This isn’t just a checkbox; it’s a $675 bill for the basic assessment, plus a month-long slog of fixing vulnerabilities and answering fifty-odd justification questions.
The Trap of the 100-User Cap
Until that wall is climbed, Seneschal lives in 'Testing' mode. This isn’t a beta label; it’s a hard constraint. Google caps Testing apps at 100 users for the life of the project. Crucially, these slots are permanent. If a user is removed, the slot does not return. Every user must manually approve the app, staring down the 'Google hasn’t verified this app' warning, and their access expires every seven days. This forces a weekly login ritual that breaks automation, a cardinal sin in agent workflows. It’s a product designed for a handful of friends, not a scalable service.
Why Open Source Doesn't Buy a Pass
A common misconception is that open-source code bypasses corporate gatekeeping. It doesn’t. Google’s review process probes the running server, not the GitHub README. Furthermore, holding strangers' inboxes introduces GDPR liabilities that don't scale down for small projects. Tin argues that for a niche tool, the math doesn't flip. The big labs are already integrating Gmail natively, and the paranoid users who care most about this level of security are likely to self-host anyway. Seneschal remains small on purpose, offering reserved seating rather than a public lobby.
Key Takeaways
- Restricted OAuth scopes trigger a $675 CASA security assessment and a month-long review cycle.
- Google's Testing mode caps users at 100 for the app's lifetime, with no slot recovery for removed users.
- Open source status does not exempt developers from Google's security audits of live deployments.
- Weekly token expiration in Testing mode disrupts automated agent workflows.
The Bottom Line
Google’s OAuth tiers are a friction tax designed to kill indie innovation before it scales. Sometimes, staying in the sandbox is the only way to keep the code clean and the agents fast.