Does https://support.google.com/accounts/answer/185833?hl=en not work?
So, yeah, "Advanced Protection" offerings would be good. Looks like I could make my own app that uses open id to connect?
On Fedora, I think I had to dnf install "isync" (for mbsync) and "libkgapi" (for the SASL XOAUTH2 plugin) and also pip install "oauth2token".
You'll need to get credentials from Google. I think this describes how: https://developers.google.com/identity/protocols/oauth2
If you have a plain gmail account (instead of Google Workspace, or whatever it's called now), one irritating thing is that you have to renew the access tokens (using oauth2create) once a week.