There was a mistake in the proposed Google Health go live posted yesterday.
Google has removed the 100-connected-user trigger that previously started the CASA assessment after completing OAuth verification, so our clients can now start their CASA assessment as soon as OAuth app verification is complete.
What was missed in yesterday's entry, and has been updated today, is that until the CASA assessment is completed, Google will only allow 100 connected users to the Google Health API credentials.
Please take this into account in planning your go live with Google Health in your marketplace for production orgs.
We've published a guide for testing Google Health in your sandbox org and moving to your production org. Google's guidance on this process has shifted several times, so this document consolidates the current requirements and our recommended approach, including timing for Google's required assessments.
Questions? Reply to your existing support ticket or email support@validic.com to open one.
Posted Aug 06, 2026 - 12:19 EDT
Update
Two updates today:
1. We have production support for the nutrition endpoint now with Google Health. Clients that want to use this endpoint and have already delivered us credentials would need to add the nutrition.readonly scope to their GCP project that contains the Google Health credentials, and then reach out to support@validic.com with the Org ID we have enabled the credentials for and ask us to add them. We do not have a scheduled job for the nutrition endpoint, so configuration of webhooks is required to ingest data from this source: https://help.validic.com/space/VCS/5754421279/Google+Health:+Enable+webhooks+for+near+real+time+data+delivery
2. Previously, we were told by Google that we had to complete our CASA assessment before our clients could move to production with their Google Health projects. Google has relaxed that restriction, and our clients can now move to production if they have already tested in lower environments and enabled webhooks. Just reach out to support@validic.com with the production JSON file containing credentials for Google Health, verification of the scopes selected for those credentials, the JSON file with webhook configuration, and confirmation of your production org ID. We'll be happy to add Google Health to your production Validic org. Things to be aware of when you move your GCP project with Google Health credentials to production. This will trigger your OAuth verification on the Google side. Completing this step will give you your tier for your CASA assessment. This FAQ will talk you through these at a very high level: https://help.validic.com/space/VCS/5539037190/Requirements+and+Assessments+FAQs+for+Google+Health+API
Posted Jul 28, 2026 - 13:51 EDT
Update
Currently, the Google Health integration is using scheduled jobs to pull data from end users, but we are excited to offer webhooks as a configuration option for this source. Webhooks will allow for near real time data to be synced into our servers and then immediately delivered in the Streaming API or Push service your organization uses for org level data ingestion.
This will require an adjustment in the Google Cloud Platform project you created the Google Health credentials in. Follow the instructions in the following KBA to enable webhooks in your GCP project and deliver the JSON file that will download to your computer upon completion of the steps to Validic Support. If you already have a ticket about Google Health open with support, you can deliver it in that ticket, and if not, just email support@validic.com so we can get this enabled for your Google Health credentials in your organization.
If you haven't delivered Google Health credentials to Validic Support yet, then include this with the Google Health credentials to get it all enabled at once.
We are completing our CASA certification before clients can transition to production with the Google Health integration in Inform. Our verification is underway, and the assessment begins when complete. If your CASA review starts before ours concludes, it will likely be flagged or blocked for unresolved third-party dependencies. Our certification completion will clear the way for your assessment.
While we finalize our certification, you can prepare now. CASA involves substantial documentation and prep work before formal auditing begins:
1. Gather existing certifications - SOC 2 or ISO 27002 documentation. (Note: ISO 27001 alone does not qualify). Assessors can map these to CASA requirements and skip redundant testing. 2. Start assessor conversations - Contact authorized App Defense Alliance assessors, complete scoping surveys, and compare quotes. Formal engagement begins after you receive Google's CASA notification email. https://appdefensealliance.dev/casa/casa-assessors 3. Audit and minimize OAuth scopes - Review which scopes your app requests and remove non-essential ones. Moving from Tier 3 to Tier 2 can reduce costs from 4500 USD to 500 USD and timelines from 4-6 weeks to 2-3 weeks. 4. Run pre-scan on staging - CASA follows OWASP ASVS standards. Test your staging environment now to identify issues like CORS problems or missing security headers: https://github.com/appdefensealliance/ASA-WG/blob/develop/CASA/CASA%20Specification.md 5. Prepare Google demo video - Record a video showing your OAuth grant process (in English), app details with OAuth client ID, and data usage demonstration. Google Drive or accessible file hosting works. This can be done in your lower environment 6. Check in-app disclosure - Google requires sensitive data use disclosure within the app during normal use, separate from privacy policy or website disclosures.
We will notify you immediately in this status page upon certification completion so you can begin your transition to production with our Google Health integration with minimal delay. Contact Validic support with questions.
Posted Jul 08, 2026 - 15:18 EDT
Update
Google has set a definitive date for the shutdown of the Fitbit Web API that Validic uses for the current Fitbit integration. Clients are advised to reach out to Validic support to start testing Google Health so that they will be ready when Google sunsets the Fitbit Web API and Validic is forced to shut down our current Fitbit integration:
September 30, 2026. This is the definitive calendar date when the legacy Fitbit Web API will be fully decommissioned and disabled.
If your organization already has a Google Cloud Console project in Production mode used for other Google services (Google Fit, Google Maps, YouTube, or an Android application), do not add Google Health credentials to that project. Adding the Google Health API and its scopes to an existing Production-mode app can affect that app's OAuth verification status and could trigger a CASA security assessment for your existing production project.
The recommended path is to create a new, separate Google Cloud project dedicated to Google Health. This isolates the Google Health credential lifecycle from your existing production infrastructure and lets you test in Testing mode without any impact on your current users.
Posted Jun 11, 2026 - 13:32 EDT
Update
A couple of bugs and one piece of expected behavior we are tracking on the Google side that our clients who are testing should be aware of:
1. We have noticed that the Google Health API is returning timeouts intermittently. We have escalated this to Google and will update in this unique status page post: https://trust.validic.com/incidents/qnd7xjy4c63j
2. Google has acknowledged a bug that causes the step count delivered in the Google Health API to not match what is shown in the app. Google has escalated it to engineering. We will update as we learn more in this status page thread.
Be aware that Google is still in active development on the Google Health API. We would generally wait until the vendor api is fully developed and stable to introduce a new source in our ecosystem, but due to the short runway with Google sunsetting the Fitbit APi in late August, we have tried to give our clients as much time as possible to test and become acquainted with the Google Health integration. We are in communication with Google and are adjusting to any breaking changes and adding any new metrics and endpoints as Google makes them available in their API. See this page for updates on what metrics are available today and ballpark estimates for when we will be able to introduce the metrics that Google is working to make available: https://help.validic.com/space/VCS/5436080132/Fitbit+to+Google+Health+API+Metric+Mapping+Guide#How-to-Read-This-Guide
If anyone has any questions about this new source, send an email to support@validic.com to open a ticket with our technical support team. We are here to help you through this transition with any questions that may come up.
Once you create those, open a ticket with Validic technical support by sending an email to support@validic.com, cc any colleagues that need to be aware of the communication, and deliver the file downloaded in the process with your credentials, a screenshot of the scopes selected for the credentials, and your sandbox organization ID. Those three pieces of information are required to set up Google Health in your sandbox so your organization can test the new integration.
Posted May 26, 2026 - 09:29 EDT
Update
We're close to letting clients test Google Health integration in their sandboxes. Updates will be coming soon on that.
We're hosting a free webinar on May 27 at 2 PM ET specifically to walk your team through what this migration from the current Fitbit integration to the Google Health integration entails. It's more involved than a simple config change; it touches your data pipeline, your marketplace reconnection flow, and potentially parts of your data model. The sooner your engineers have a clear picture of the scope, the better.
We have been making progress on having the Google Health integration ready for our clients to test in their sandbox. We're not quite there yet, but updates will be coming as we reach that milestone.
What's coming next? -We will be providing documentation to guide our clients on the steps they need to take to go through the steps on Google's side to get developer credentials to share with our support team, so we can enable Google Health in your sandbox with your unique developer credentials. This will be made available when we have the integration ready for sandbox testing.
-Before taking the steps to create your developer credentials, you need to look at what your organization uses from Fitbit currently and use that to guide what scopes you will add to your developer credentials for Google Health. You should only select the scopes you actually ingest and use in your application. You should only select scopes that are currently supported by our coming Google Health integration.
We're excited about the Google Health integration, but we know that a lot of our clients still have questions about what the transition from the existing Fitbit integration to the Google Health integration will be like. You can ask all questions by reaching out to our support team at support@validic.com. We're always here to help!
The end user's app is Fitbit today and will continue to be that until the change on May 19th, 2026, when it is rebranded as Google Health
Posted May 11, 2026 - 15:59 EDT
Update
As an update, the integration for Google Health API will be available for sandbox testing in Inform in late May. Additionally, we have created this document to help with some clarification of the review process that Google is planning for the use of the Google Health API. If you have any questions about any of this, feel free to open a support ticket by emailing support@validic.com so we can assist further https://help.validic.com/space/VCS/5535203416/Fitbit+to+Google+Health+API:+Developer+Migration+Timeline
Posted May 06, 2026 - 15:48 EDT
Update
Google is replacing the Fitbit Web API with the Google Health API. All Validic clients currently using the Fitbit cloud integration will need to transition to the new Google Health API integration before September 2026, when the legacy Fitbit Web API will be decommissioned. Both integrations will run side by side from May through September; there is no planned downtime.
What's new: - Validic's Google Health API integration will be available for testing in the Inform Marketplace in early May 2026. Google recommends production launches begin in late May. - Clients will need to register directly with Google for developer credentials. Validic will provide the necessary callback URL and setup information. Please wait to create your developer credentials until we have our integration finalized so we can share best practices to ensure they work seamlessly with our platform. - The Google Health API accesses restricted scopes, the highest category under Google's OAuth verification framework. Full app verification, a security assessment, and annual re-verification are required before going to production. Details on Google's verification process: https://support.google.com/cloud/answer/13463073 - While you should wait for Validic's outreach before requesting developer credentials, you can begin verification groundwork now: prepare your homepage, privacy policy, domain verification, demo video, and scope justifications. Getting ahead on these steps will give your team more runway once development begins.
Key dates: - Now — Begin OAuth app verification groundwork (no credentials needed for this step) - Early May 2026 — Google Health API source available in Validic Marketplace (testing) - May 19, 2026 — Fitbit users who haven't migrated their login to a Google Account lose access to Fitbit (separate status page: https://trust.validic.com/incidents/hp77lmtp130s) - Late May 2026 — Google's recommended production launch window - September 2026 — Legacy Fitbit Web API decommissioned
Important: This transition is separate from the Fitbit-to-Google Account login migration (May 19 deadline), which is tracked on a separate status page: https://trust.validic.com/incidents/hp77lmtp130s. End users need to complete both actions: the account login migration AND reconnecting through the new Google Health API integration.
We will share detailed migration documentation, including a data mapping guide and a developer migration guide, as they are finalized. Subscribe to this page for updates.
Posted Apr 09, 2026 - 15:01 EDT
Update
We have added some integration details and support guides for this transition.
The timeline remains that this source won't be available until May 2026, but we are getting this information ahead of time so that our clients can plan for this transition. After reading all our documentation, if you still have questions, reach out to Validic technical support so we can assist. These documents will be updated as new information becomes available about this coming source in the Inform ecosystem.
This will require action from your users and your dev team. We've been preparing for this and are here to help you through it.
- - -
Here's the timeline: - May 2026: The new Google Health API integration becomes available in your Inform marketplace. You'll need to request it be added on or after this date to get started. - May 19, 2026: Fitbit users must transition to a Google Account before this date, or they'll lose access to the Fitbit app and data syncing. For more information, see [maintenance PAGE](https://trust.validic.com/incidents/hp77lmtp130s). - September 2026: The legacy Fitbit Web API shuts down for good. All connections must be migrated by then, or data will stop syncing.
- - -
What this means for your users: - Every Fitbit user will need to reconnect through the new Google Health API integration. Google requires each user to sign in with their Google Account and grant permissions.
- - -
What this means for your dev team: - Google Health is a new integration, available in May 2026 in your Inform marketplace. – If you are currently using the Validic v1 (legacy) API, please reach out to our support team for assistance: https://help.validic.com/portal/2 - Plan to update any logic referencing the "fitbit" source type to also handle "google_health". Your data still comes through as the same Validic standard objects. Some metric names have changed, and we'll have a mapping guide available soon. There is no downtime currently planned as part of this transition. Both integrations will run side by side from May through September 2026. And we have dedicated contacts at Google supporting this transition and will make sure any questions get to the right people.
- - -
We know transitions like this can feel like a lot, but this is exactly the kind of thing Validic is here for. We’re preparing additional information for you, which we plan to post next week. We will also continue to provide updated information as it is available through this maintenance page.