What the tool does
The tool uses a dedicated Gmail test mailbox to receive ARBI staging test messages, extracts one-time verification codes, checks staging business APIs, and removes the synthetic application accounts it creates. Access is configured by an authorised ARBI operator. It is not a general-purpose Gmail client or a public sign-in service.
Why Gmail access is requested
Receiving a test email is part of verifying the complete registration and sign-in flow. The tool requests Google's Gmail read-only permission. This permission technically allows reading the entire authorised mailbox; Google does not restrict it to a test alias. The implementation filters by the unique test alias, configured sender, expected subject, and recent delivery time.
How information is handled
Message contents and verification codes are processed in memory. Test evidence records check outcomes and operational metadata, with GitHub Actions artifacts configured for 14-day retention. The tool does not delete or modify Gmail messages.
Contact
For questions about this tool or its access to the test mailbox, email carterwellsdeveloper@gmail.com.
