[ Sorry for the long response delay. Must be That Time Of Year or something. ?? ]
I did that search, and the OAuth consent screen tab definitely says “In production”, but since read-only photo access is a “sensitive scope”, it seems there are yet more hoops to jump through. I was thinking that since the end goal here is to have a single web site pull photos from a single Google account, that perhaps the “service account” concept was a better match.
A twisty little maze of passages, all different.