Prompt
I need to connect Google login to my existing users
Latest observation
To connect Google login to your existing users, the key is to link a Google account to an already-created local account instead of creating a duplicate user.
Recommended approach
1) Keep one user record
Your user table should represent one person, with optional linked auth methods.
Example fields:
idemailpassword_hashor local auth infogoogle_sub/google_idoauth_provideroauth_email_verified- timestamps
Or better, use a separate table for identities:
users
idemailname- ...
user_identities
iduser_idprovider(google)provider_user_id(Googlesub)emailcreated_at
This is the cleanest setup if you may add more providers later.
2) Use Google’s OpenID Connect flow
When the user clicks “Continue with Google”:
- redirect them to Google OAuth/OIDC consent screen
- on callback, verify the ID token
- extract:
sub= unique Google user IDemailemail_verified- name/profile if needed
3) Match to existing users carefully
When Google returns a profile:
If Google identity already linked
- log the user in directly
Else if email matches an existing account
- do not auto-link blindly unless you trust the email verification
- if
email_verified == true, you can link Google to that existing user - optionally require the user to be logged in first for explicit linking
Else
- create a new user
- link Google identity to it
Safest linking strategy
Best practice is:
Option A: User is logged in and chooses “Link Google”
- user signs in with password first
- clicks “Link Google”
- OAuth flow completes
- link Google identity to the current user
This avoids account takeover risks.
Option B: Login with Google
- user clicks Google login
- if Google
subexists, log in - if no identity exists but email matches an existing account and email is verified, prompt:
- “We found an existing account. Please sign in with your password to link Google.”
This is safer than auto-connecting just because emails match.
Important security rules
- Verify the Google ID token signature and issuer/audience.
- Use only the
subas the stable Google identifier, not email. - Don’t link accounts solely on unverified email.
- If your app has password accounts, consider requiring password confirmation before linking.
- Handle email changes on Google accounts carefully: the
substays stable, email may not.
Example logic
Pseudo-flow:
on Google callback:
verify ID token
google_id = token.sub
email = token.email
verified = token.email_verified
if identity exists where provider="google" and provider_user_id=google_id:
log in linked user
else if current_user is logged in:
link google_id to current_user
log in current_user
else if email matches existing user and verified:
show “existing account found” flow
or link if your policy allows
else:
create new user
link google_id
log in new user
If you already have users with the same email
You’ll need a migration/linking strategy:
- find existing users by email
- ask them to sign in normally
- then connect Google from account settings
- or send them a one-time email link to confirm account ownership before linking
If you tell me your stack, I can give you exact code
If you want, I can provide:
- Node/Express
- Next.js / NextAuth
- Django
- Laravel
- Firebase
- Spring Boot
- PHP / plain OAuth
If you share your current user schema and framework, I can show you the exact implementation to connect Google login to existing users safely.