\n
\n\n\n\n```\n\n### Backend verification example\nOn the server, verify the token using Google libraries.\n\n**Node.js example:**\n```js\nimport { OAuth2Client } from 'google-auth-library';\n\nconst client = new OAuth2Client('YOUR_CLIENT_ID');\n\napp.post('/auth/google', async (req, res) => {\n const { credential } = req.body;\n\n const ticket = await client.verifyIdToken({\n idToken: credential,\n audience: 'YOUR_CLIENT_ID',\n });\n\n const payload = ticket.getPayload();\n const googleUserId = payload.sub;\n const email = payload.email;\n\n // Find/create user in your DB, then create your session\n res.json({ success: true });\n});\n```\n\n## 5) Mobile apps\nIf you’re building:\n- **Android**: use Google Sign-In / Google Identity Services with Android credentials\n- **iOS**: use Google Sign-In SDK\n- Often you’ll send the Google ID token to your backend for verification\n\n## 6) Security best practices\n- Verify the token on the **server**\n- Use HTTPS\n- Don’t trust user info from the client alone\n- Store your own app session, not the Google token, for auth\n- Request only the scopes you need\n\n---\n\nIf you tell me your stack — for example **React**, **Next.js**, **Flutter**, **Android**, **iOS**, **Node**, **Django**, etc. — I can give you exact step-by-step instructions and code."}}}Prompt
How do I add Google sign-in to my app?
Latest observation
Oct 6, 2026
OpenAI APIWeb search: off
To add Google sign-in, the exact steps depend on your app type, but the overall flow is:
- Create a Google Cloud project
- Configure OAuth consent screen
- Create OAuth client credentials
- Add Google Sign-In to your app
- Verify the ID token / handle the callback on your backend
- Create your own app session
1) Create a Google Cloud project
- Go to the Google Cloud Console
- Create a new project or choose an existing one
2) Configure the OAuth consent screen
- In APIs & Services → OAuth consent screen
- Set:
- App name
- Support email
- Authorized domains
- Privacy policy / terms URLs if needed
- Add test users if the app is in testing
3) Create OAuth client credentials
In APIs & Services → Credentials:
- Create an OAuth client ID
- Choose the app type:
- Web application
- Android
- iOS
- Desktop
- For web apps, add:
- Authorized JavaScript origins
- Authorized redirect URIs
You’ll get a Client ID and sometimes a Client Secret.
4) Implement the sign-in flow
For web apps
Common approach:
- User clicks “Sign in with Google”
- Google returns an authorization code or ID token
- Your backend verifies it
- Your app creates a session for the user
Google’s newer recommended approach for many web apps is Google Identity Services.
Example front-end button:
<script src="https://accounts.google.com/gsi/client" async defer></script>
<div id="g_id_onload"
data-client_id="YOUR_CLIENT_ID"
data-callback="handleCredentialResponse">
</div>
<div class="g_id_signin" data-type="standard"></div>
<script>
function handleCredentialResponse(response) {
// response.credential is a JWT ID token
fetch('/auth/google', {
method: 'POST',
headers: { 'Content-Type': 'application/json' },
body: JSON.stringify({ credential: response.credential })
});
}
</script>
Backend verification example
On the server, verify the token using Google libraries.
Node.js example:
import { OAuth2Client } from 'google-auth-library';
const client = new OAuth2Client('YOUR_CLIENT_ID');
app.post('/auth/google', async (req, res) => {
const { credential } = req.body;
const ticket = await client.verifyIdToken({
idToken: credential,
audience: 'YOUR_CLIENT_ID',
});
const payload = ticket.getPayload();
const googleUserId = payload.sub;
const email = payload.email;
// Find/create user in your DB, then create your session
res.json({ success: true });
});
5) Mobile apps
If you’re building:
- Android: use Google Sign-In / Google Identity Services with Android credentials
- iOS: use Google Sign-In SDK
- Often you’ll send the Google ID token to your backend for verification
6) Security best practices
- Verify the token on the server
- Use HTTPS
- Don’t trust user info from the client alone
- Store your own app session, not the Google token, for auth
- Request only the scopes you need
If you tell me your stack — for example React, Next.js, Flutter, Android, iOS, Node, Django, etc. — I can give you exact step-by-step instructions and code.