---
title: "Fitbit to Google Health API — Developer Transition Guide"
canonical: "https://help.validic.com/space/VCS/5513478151/Fitbit%20to%20Google%20Health%20API%20%E2%80%94%20Developer%20Transition%20Guide"
format: markdown
---
**Important:** Google is replacing the Fitbit Web API with the new Google Health API. This guide covers everything your engineering team needs to plan and execute the migration. For additional reference, see the [Fitbit to Google Health API Migration](https://validic.atlassian.net/wiki/spaces/VCS/pages/5436964886) documentation.

> ℹ️ As you review this, please understand, the timeline, verification requirements, and security assessment are Google's, not Validic's. We're here to help you get through them, as best we can.

---

## Overview

Google is replacing the Fitbit Web API with the new Google Health API. **This isn't an update to the existing integration,  it's an entirely new platform with new authentication, new endpoints, and a new source type in Validic** (`google_health` replaces `fitbit`). Your data still flows through as the same Validic standard objects, but there are changes your team will need to account for.

Validic's engineering team has been in Google's beta program since December 2025, and the `google_health` integration is coming to Inform in May 2026.

---

## Key Dates

| Date | What Happens |
| --- | --- |
| **Now** | You can begin Google's OAuth app verification groundwork, homepage, privacy policy, domain verification, demo video, and scope justifications. None of this requires waiting for the May launch. |
| **May 2026** | The `google_health` integration becomes available. Validic will reach out with the callback URL and everything you need to request your Google Health API developer credentials and get enabled in your Inform marketplace. |
| **May 19, 2026** | Fitbit users who haven't migrated their Fitbit login to a Google Account will lose access to the Fitbit app and data syncing. ([Status page](https://trust.validic.com/incidents/hp77lmtp130s)) |
| October** 30, 2026** | The legacy Fitbit Web API shuts down permanently. All connections must be on Google Health API by then, or data stops. |

The Fitbit and Google Health API integrations will run side by side from May through October 30, 2026, so there is no planned downtime.

---

## What This Means for Your Users

Every Fitbit user will need to take two separate actions:

1. **[Migrate their Fitbit login to a Google Account](https://help.validic.com/space/VCS/3755213034/Moving+a+Fitbit+user+to+a+Google+Account)** (before May 19),  this happens in the Fitbit app under Settings. This does *not* complete the transition; it only changes how they sign in.
2. **Reconnect through the Google Health API integration** in your marketplace (between May and October,) Google requires each user to individually sign in with their Google Account and grant permissions. There is no way to silently migrate users; this is a Google security requirement.

> **Note:** Google Workspace accounts are not supported. This is a firm Google limitation. Users need a personal Google Account.

---

## What This Means for Your Engineering Team

Google Health API is a completely new Validic source type, because it accesses restricted health data, your application will need to complete [Google's OAuth app verification](https://support.google.com/cloud/answer/13464321) before going to production.

### Before May — Start Now

**Begin your OAuth verification groundwork.** You can get ahead of all of these before development even starts:

- A live homepage on a verified domain describing your app's functionality
- A privacy policy covering how your app accesses, uses, stores, and shares Google user data — linked from your homepage and OAuth consent screen
- Domain ownership verified in Google Search Console
- A demo video showing the complete end-to-end OAuth flow with the consent screen

**Prepare your scope justifications.** Google requires detailed written justifications for each requested scope. Be specific about what your app does with each data type and why a narrower scope wouldn't work. Your Validic account team can help you understand which scopes are needed for your use case.

### Phase 1 — Planning and Enablement (May, ~1–2 weeks)

- Validic will reach out with your callback URL and everything you need to request Google Health API developer credentials. Share credentials with Validic via secure channel once setup is complete.
- Request the `google_health` integration be added to your Inform marketplace
- Review the [metric mapping guide](https://help.validic.com/space/VCS/5436080132/Fitbit+to+Google+Health+Metric+Mapping+Guide) and [migration documentation](https://validic.atlassian.net/wiki/spaces/VCS/pages/5436964886)
- Audit your codebase for logic that references the `fitbit` source type

### Phase 2 — Development (~2–4 weeks)

- Update backend logic that filters, routes, or transforms data by source type to also handle `google_health`
- Update your marketplace UI to surface the new Google Health API integration
- Adjust metric-specific logic — some metric names have changed; see the [metric mapping guide](https://help.validic.com/space/VCS/5436080132/Fitbit+to+Google+Health+Metric+Mapping+Guide). The underlying Validic data objects remain the same.
- If you're using the Validic v1 (legacy) API, contact support: [help.validic.com/portal/2](https://help.validic.com/portal/2)

### Phase 3 — Testing (~2–3 weeks)

- End-to-end validation in your staging environment
- Test the user connection flow through your marketplace
- Regression testing to confirm existing Fitbit connections still work during the overlap period
- Validate downstream consumers (dashboards, reports, member-facing displays)

### Phase 4 — Security Assessment

Google's Trust and Safety team will reach out directly once all other verification requirements are complete. You don't schedule this yourself.

The assessment uses the CASA framework via an [authorized lab](https://appdefensealliance.dev/casa/casa-assessors). Upon passing, your app receives a Letter of Validation (LOV).

- **Annual requirement** — revalidation is required every year. Tier is assigned by Google based on user count, scopes, and risk factors.
- **CASA Accelerator** — organizations with SOC 2 or ISO 27001 may qualify for a reduced assessment scope.
- **Contact assessors early** — reach out to an authorized lab now to understand timelines and pricing. Full list: [CASA Assessors](https://appdefensealliance.dev/casa/casa-assessors) | [CASA Tiering](https://appdefensealliance.dev/casa/casa-tiering)

### Phase 5 — Production Rollout and User Migration (target: early-to-mid July)

- Deploy to production. Validic recommends removing the Fitbit integration from your marketplace at launch to avoid new users connecting to the legacy integration.
- Communicate to your Fitbit users about reconnecting through Google Health API
- Monitor reconnection rates via Validic's Connections API

### Phase 6 — Fitbit Cleanup (after October 30, 2026)

- Remove remaining `fitbit` source type references from your codebase

> **The earlier you start on verification groundwork, the more comfortable your timeline will be.** A mid-July production target gives you a solid buffer before the October 30, 2026 hard cutoff.

---

## What Validic Is Doing to Help

- Metric mapping guide: [Fitbit to Google Health Metric Mapping Guide](https://help.validic.com/space/VCS/5436080132/Fitbit+to+Google+Health+Metric+Mapping+Guide)
- Validic has dedicated contacts at Google supporting this transition
- Subscribe to our [status page](https://trust.validic.com/incidents/8lzmtg20hp90) for updates
- Additional documentation will be shared as it's finalized

For questions or support requests: [help.validic.com/portal/2](https://help.validic.com/portal/2)

---

## Related Documentation

| Resource | Link |
| --- | --- |
| Fitbit to Google Health API Migration | [Migration documentation](https://validic.atlassian.net/wiki/spaces/VCS/pages/5436964886) |
| Metric Mapping Guide | [Fitbit to Google Health Metric Mapping Guide](https://help.validic.com/space/VCS/5436080132/Fitbit+to+Google+Health+Metric+Mapping+Guide) |
| User Account Migration Guide | [Moving a Fitbit user to a Google Account](https://help.validic.com/space/VCS/3755213034/Moving+a+Fitbit+user+to+a+Google+Account) |
| Google OAuth App Verification | [Verification overview](https://support.google.com/cloud/answer/13464321) |
| Google Restricted Scope Requirements | [Verification requirements](https://support.google.com/cloud/answer/13465431) |
| CASA Tiering | [CASA tier breakdown](https://appdefensealliance.dev/casa/casa-tiering) |
| CASA Authorized Assessors | [Authorized assessors list](https://appdefensealliance.dev/casa/casa-assessors) |
| Status Page — Account Migration | [trust.validic.com](https://trust.validic.com/incidents/hp77lmtp130s) |
| Status Page — API Transition | [trust.validic.com](https://trust.validic.com/incidents/8lzmtg20hp90) |
| Support Portal | [help.validic.com/portal/2](https://help.validic.com/portal/2) |