How do I verify my application for production?

Read as Markdown

There is no separate process required with Google or Microsoft to approve your application for production. As Cronofy manages all calendar and conferencing connections as part of our infrastructure we can approve with a simple verification step.

In order to verify your application:

Redirect URIs #

Having a permitted list of values helps us guard against phishing attacks by controlling where we return authorization codes to for your application.

This Stack Exchange article is a good explanation of why this is necessary: What is the purpose of OAuth 2.0 redirect_uri checking?

Wildcards #

We do support wildcards in the host name, but only for subdomains of domains under your control, eg: https://*.example.com/auth/cronofy/callback. If your application uses dynamic URLs, we’d recommend using the state parameter. Our FAQ on using this to support dynamic values in your OAuth flow explains how to use this.

Mobile redirects #

Please note that mobile app schemes are not supported as redirect URLs. If you are integrating with a mobile application, the recommended approach is to:

  • Configure a web redirect URL in your Cronofy application settings.
  • Handle the response on your web endpoint.

This approach allows the OAuth flow to complete using a supported web redirect, while still returning users to the appropriate location.

Billing #

Billing starts once your application is in production, so your billing details need to be in place before you go live. Billing covers when you’re charged, how usage is counted and how to pay.

When you’re ready to go, email support@cronofy.com your Application Client ID and list of permitted redirect_uri values and we’ll switch you to production mode.