We connect sign-in for your application to Google account authentication.
Most people already have a Google account, and many businesses run on Google Workspace. Letting them sign in with it removes a password to forget and a sign-up form to fill in. For staff, access can be limited to your company domain, so only your Workspace accounts can get in.
What we build with it
- Staff sign-in with a Workspace account
- Customer portal sign-in
- Domain-restricted access for Workspace organisations
How it works
- The user clicks sign in with Google in the web app or mobile app.
- Google asks them to choose an account and confirms their identity, applying any two-step verification they have set.
- Google returns a signed token with the user's ID, email and basic profile.
- The system verifies the token, checks any domain restriction and signs the user in to their matching account.
Data exchanged
- Google account identifier
- Email address and basic profile
- Authentication tokens
What is needed to set it up
- A Google Cloud project with OAuth credentials
- Authorised redirect URIs
- Optional domain restriction
Good to know
- Basic sign-in only asks for identity and email. Requesting access to other Google data, such as Drive, needs further consent and may need Google's review.
- The consent screen shows your application name and logo, which Google may ask you to verify for public applications.
- If staff leave, disabling their Workspace account also stops them signing in to the system.
