They should have a debug mode that is user-activated for stuff like this.
I also have burned too many hours trying to get various OAuth flows working.
I also have burned too many hours trying to get various OAuth flows working.
To avoid it being used as an attack vector they could be tied to special app registrations that had to be registered with the mail development system in advance.