Guides

Google Apps Script First Run: Getting Past the 'Unverified App' Warning

8 min read#apps-script#guide#beginner

Who this is forAnyone whose first Apps Script run stopped at the red 'unverified app' warning and who wants to judge whether it's safe to click through.

TL;DR: Apps Script is a tool that runs your code with nothing to install and no server, just a Google account. On the first run, an approval screen and a red warning appear in sequence. The warning does not mean “this is a dangerous app.” It means the app has not yet gone through Google’s review. And the person who made that app is you. This post covers that judgment and what to check when you get stuck, using real screenshots.

Contents

  1. No install, no server
  2. Put the code in the editor
  3. What happens when you press Run
  4. Authorization required, then choosing an account
  5. “Google hasn’t verified this app”: where people freeze
  6. Completion check: the execution log
  7. When you get stuck
  8. If someone else gave you the script, the answer is different

No install, no server

You only need to sign in to script.google.com with a Google account. There is nothing to download and no server to set up. A single browser tab serves as both the editor and the runtime.

Once you’re in, the left side shows a New project button and a list of projects you created before.

The script.google.com home screen. The New project button is at the top left, and the list of my projects shows each project's name, owner, and last-modified time
The script.google.com home screen. Everything starts from the New project button at the top left

Clicking New project opens the editor right away. There is no signup and no install check.

Put the code in the editor

New project editor screen. It shows the name Untitled project, a saving indicator, the Code.gs file, an empty myFunction function, and Run and Debug buttons at the top
When you open a new project, its name is automatically set to "Untitled project," and it saves automatically as you type

The name starts out as Untitled project. You can rename it later, so don’t worry about it now. In the file list on the left, there is one file called Code.gs, and it contains an empty function.

function myFunction() {

}

Put your code between those curly braces. In this post, we’ll add one line that fetches the email address of your Google account.

function myFunction() {
  Session.getActiveUser().getEmail();
}

What happens when you press Run

The top toolbar has Run, Debug, a dropdown for choosing a function name, and an Execution log button. When you press Run, the code does not run immediately. It goes through one step first.

Apps Script scans the code to see which services it uses, and automatically determines the permissions those services need. The line you just added reads your account email, which is personal information, through the Session service. If you haven’t approved this permission yet, an approval window appears first. You only go through this approval once, the first time you run in a given project. After that, it won’t ask again. The approval screens for code that reads or sends Gmail are covered separately in Granting Gmail permissions in Apps Script.

Screens you pass through on the first run

  1. 1 Authorization required dialog Click Review permissions
  2. 2 Account selection Choose the account you want to run the code under
  3. 3 Unverified app warning This is where most people stop
  4. 4 Advanced → Go to You have to click this to move on

You go through this only once per project

Four screens appear in order. The fork is at step three, the red warning

Authorization required, then choosing an account

When you press Run, this window appears first.

Authorization required dialog that appears right after Run. It says the app may not work as expected unless you grant all requested permissions, with Cancel and Review permissions buttons
It warns that the app may not work as expected unless you grant all the permissions it requests

Click Review permissions. Next is the account selection screen.

Account selection screen for signing in with a Google account. It has the prompt to choose an account, a link to go to Untitled project, account information, and an option to use another account
Pick the account you want to run this code under. The link shows the project name ("Untitled project") as is

So far, nothing unusual. It’s the same as signing in to any other service with a Google account. As soon as you pick an account, the next screen changes the mood.

“Google hasn’t verified this app”: where people freeze

Google unverified app warning screen. A red warning triangle, a notice that the app is requesting access to sensitive information in the Google account, the developer's name blurred out, a Back to safety button, and at the bottom a Go to Untitled project (unsafe) link
When the red warning triangle and the "unsafe" link appear together, most people stop here

Here is the on-screen text, with what each line means.

On-screen text What it means
Google hasn’t verified this app This app has not gone through Google’s review
This app is requesting access to sensitive information in your Google Account The code you just added is trying to read personal information such as your email
Don’t use this app until the developer [name]’s app is verified by Google It names the person who made the app and tells you to proceed only if you trust that person
Continue only if you understand the risks and trust the developer The screen itself gives the criterion. It’s not the size of the risk, it’s whether you trust the developer
Go to Untitled project (unsafe) A link to proceed anyway. “Unsafe” means Google hasn’t reviewed the app, not that a risk was confirmed

Google’s official explanation states the reason for this warning precisely:

“An unverified app is an app or Apps Script that requests a sensitive or restricted OAuth scope, but hasn’t gone through the Google verification process.” Google support doc: Unverified apps

So the warning does not mean “this app is dangerous.” It means “this app has not yet been reviewed by Google.” The same document also explains that apps in experimental or testing stages don’t need this verification unless they are made public.

Clicking Go to (unsafe) takes you back to the editor you were running from, and the code actually runs.

Completion check: the execution log

Screen after a successful run. The Execution log panel at the bottom shows two lines with timestamps: Execution started and Execution completed
After approval, the Run you pressed earlier finally executes. The results appear in the Execution log at the bottom

When the Execution log panel opens at the bottom of the screen and two lines appear, you’re done.

When you get stuck

That’s the normal path. Depending on your account type or editing state, you may get stuck in the ways below. I’ve listed only the causes confirmed in Google’s official documentation.

Symptom Cause What to do
The “Go to (unsafe)” link is missing, or clicking it doesn’t advance to the next screen Company or school Google Workspace accounts may have admins blocking new installs of unverified third-party apps Try again with a personal Gmail account. If you must use a work account, ask your admin to add this app to the allowlist
You fixed the code and ran it again, but the approval screen didn’t change The project save didn’t take effect, or the editor wasn’t reloaded Save the project, reload the editor, then run again
After setting up automatic runs such as a time-based trigger, an “authorization required” error appears again Triggers must be approved by the person who created them, and adding code that needs new permissions requires going through approval again Run the function once manually from the script editor to bring the approval window back up, then approve

If someone else gave you the script, the answer is different

Everything above, including the judgment that it’s fine to click through the “unverified app” warning, holds only if you wrote the script yourself.

If someone sent you a script by link or file and you hit the same warning, the name in the developer spot is no longer you. At that moment, the whole decision changes.

For your next step, if you want Apps Script to pull in external data, you can choose sources from 9 public data API sources (Korean government open-data APIs).

The screens in this post were checked on August 25, 2026. The explanations quoted come from the Apps Script authorization official docs and the Unverified apps support doc. Google may change the screens and wording, so if your screen differs, go by the wording on that screen.

Frequently asked questions

Why does Google warn "hasn't verified this app" when I run my own Apps Script?
The warning means the app has not gone through Google's verification review, not that it is dangerous. If you ran a script you wrote, the developer name shown is your own account.
What to do if the "Go to (unsafe)" link is missing on the first run?
Company or school Google Workspace admins may block unverified apps, so try a personal Gmail account or ask your admin to allowlist the app. Saving and reloading the editor, then running again, can also help.

Want the full system? The Claude Code & Codex Skills guidebook collects the skills and subagents behind this blog, from $19.