Skip to main content
team-mercor
New Member
May 17, 2026
Solved

Oauth App Review - Testing Clarification

  • May 17, 2026
  • 10 replies
  • 172 views

Hello, 

 

I recently submitted my public OAuth app for review, and have included a testing URL and detailed instructions for the team to test with, but I had a fundamental question about testing - if the app is not approved, that means the OAuth flow will only work for my own account (i.e. the same account that submitted the app). For the OAuth flow to work for any other Figma login, the app has to be published in public mode. If that is the case, how will the review team be able to test the app before it is approved? What am I missing here?

Best answer by Celine_

Hey ​@team-mercor , Celine from Figma here, stepping in for ​@Gayani_S . 

I checked internally, and our Content Moderation team has already informed the reviewer about the update you shared regarding the OAuth setup/testing flow. If the reviewer identifies any issue or needs any additional information, they’ll follow up with you directly.
If you have any further questions in the meantime, feel free to reply directly to your ticket (it will automatically reopen, and the team will be happy to assist further there.)
Thank you again for your patience throughout the review process!

10 replies

Gayani_S
Figmate
Community Support
May 18, 2026

Hey ​@team-mercor, thank you for reaching out! I’ve reached out to the team internally to get clarification on how OAuth app testing works prior to approval, and I’ll follow up with you as soon as I hear back. Appreciate your patience in the meantime!

team-mercor
New Member
May 20, 2026

Hi ​@Gayani_S, our app just got rejected for this same reason, i.e. “No option to use the testing credentials. Only available after account approval and cannot test."

 

Can you or a member of the team please clarify how we are supposed to set up our Oauth for testing without the Oauth app being approved?

Celine_
Figmate
Celine_Answer
Community Support
May 22, 2026

Hey ​@team-mercor , Celine from Figma here, stepping in for ​@Gayani_S . 

I checked internally, and our Content Moderation team has already informed the reviewer about the update you shared regarding the OAuth setup/testing flow. If the reviewer identifies any issue or needs any additional information, they’ll follow up with you directly.
If you have any further questions in the meantime, feel free to reply directly to your ticket (it will automatically reopen, and the team will be happy to assist further there.)
Thank you again for your patience throughout the review process!

modao
New Member
September 4, 2026

Hi, ​@Gayani_S ​@Celine_  we have encountered a similar issue. The reviewer reported that there was no OAuth flow, but before the public permissions are approved, it is impossible to make another Figma account publicly available through the OAuth flow. Therefore, we can only bind a fixed account so that the reviewer can test the subsequent functionality. Even though we recorded a video showing the OAuth flow, our submission still failed review after multiple attempts.

Could you please advise what we should do in this situation to pass the review? OAuth is required for the review, but without passing the review, we cannot enable the reviewer to use OAuth. Are we supposed to provide a Figma account and password? However, Figma’s policies also state that Figma account credentials must not be shared. We are currently stuck in a deadlock. Please provide a clear solution. Thank you.

modao
New Member
September 4, 2026

When I applied for Public App review, the review was rejected because we were unable to provide the OAuth flow.
 

The reviewer reported that there was no OAuth flow, but before the public permissions are approved, it is impossible to make another Figma account publicly available through the OAuth flow. Therefore, we can only bind a fixed account so that the reviewer can test the subsequent functionality. Even though we recorded a video showing the OAuth flow, our submission still failed review after multiple attempts.

Could you please advise what we should do in this situation to pass the review? OAuth is required for the review, but without passing the review, we cannot enable the reviewer to use OAuth. Are we supposed to provide a Figma account and password? However, Figma’s policies also state that Figma account credentials must not be shared. We are currently stuck in a deadlock. Please provide a clear solution. Thank you.

Celine_
Figmate
Community Support
September 4, 2026

Hey ​@modao , Celine from the Figma Community Support team here, stepping in for ​@Gayani_S ! Thanks for the detail, and sorry for the loop you've been stuck in.
To clarify: sharing your personal Figma account credentials isn't necessary or recommended here. Your OAuth app submission has a dedicated test credentials section for exactly this situation (this lets our reviewer test your OAuth flow without needing your personal login).

Could you go back into your submission, fill in that test credentials field, and resubmit for review? That should unblock the reviewer from validating the OAuth flow directly.
Hope this helps. If you still having concerns or questions, you can reach out directly to our Support team via this form, thank you!

modao
New Member
September 7, 2026

Hello ​@Celine_ ,thank you for your reply.

I filled out the “test credentials” section, and in the reviews that were rejected multiple times due to the lack of an OAuth flow, I provided test accounts specifically intended for this review.

However, the issue is that this account is an account for my app, not a Figma account. When the reviewer logs into this account, they are only logging into my app. If authorization is required, they still need to log in to a Figma account. However, because of the rules, I cannot provide a Figma account and password. Also, since the app is not yet public, other Figma accounts cannot complete the OAuth flow either.

likdsds
New Member
September 7, 2026

@Celine_ 

When submitting the OAuth app for review, does the client_id need to be from a public app? We have been rejected multiple times.

likdsds
New Member
September 7, 2026

@Celine_ When submitting the OAuth app for review, does the client_id need to be from a public app? We have been rejected multiple times.

Celine_
Figmate
Community Support
September 7, 2026

Hey there! Thanks for the additional questions, I’ve checked with the internal team.

To answer your question directly: no, the client_id does not need to come from an already-public app its from the app you submitted for review. You can find it under the OAuth credentials tab at figma.com/developers/apps. You also wouldn't be able to make it public without going through review first, so that's expected.

On the repeated rejections: this is usually related to whether the reviewer can actually test your OAuth setup flow, not the client_id itself. To clarify how this works: our reviewer uses a dedicated Figma service account to complete the OAuth flow, which works even on unapproved/draft apps. So your app doesn't need to be public for review.
On your end, make sure you've filled in the test credentials field in your submission with login details for your own app (not a Figma account) — that's what lets the reviewer reach your "Connect Figma" button and complete the flow from there.

One more thing that might simplify this for you: if your app has a free version that anyone can sign up for and test the functionality with, you don't need to provide test credentials at all — the reviewer can just sign up on their own.

Hope this clarifies !