We connect sign-in for your application to Google account authentication.

Most people already have a Google account, and many businesses run on Google Workspace. Letting them sign in with it removes a password to forget and a sign-up form to fill in. For staff, access can be limited to your company domain, so only your Workspace accounts can get in.

What we build with it

  • Staff sign-in with a Workspace account
  • Customer portal sign-in
  • Domain-restricted access for Workspace organisations

How it works

  1. The user clicks sign in with Google in the web app or mobile app.
  2. Google asks them to choose an account and confirms their identity, applying any two-step verification they have set.
  3. Google returns a signed token with the user's ID, email and basic profile.
  4. The system verifies the token, checks any domain restriction and signs the user in to their matching account.

Data exchanged

  • Google account identifier
  • Email address and basic profile
  • Authentication tokens

What is needed to set it up

  • A Google Cloud project with OAuth credentials
  • Authorised redirect URIs
  • Optional domain restriction

Good to know

  • Basic sign-in only asks for identity and email. Requesting access to other Google data, such as Drive, needs further consent and may need Google's review.
  • The consent screen shows your application name and logo, which Google may ask you to verify for public applications.
  • If staff leave, disabling their Workspace account also stops them signing in to the system.