<a id="google"></a>

# Google

<a id="backend-classes"></a>

## Backend classes

For Django, choose from these class paths for `AUTHENTICATION_BACKENDS`.
For other integrations, use the same class paths in the
framework-specific backend setting.

| Backend name    | Class path                                        |
|-----------------|---------------------------------------------------|
| `google-oauth2` | `social_core.backends.google.GoogleOAuth2`        |
| `google-oauth`  | `social_core.backends.google.GoogleOAuth`         |
| `google-onetap` | `social_core.backends.google_onetap.GoogleOneTap` |

This section describes how to setup the different services provided by Google.

<a id="google-oauth"></a>

## Google OAuth

#### ATTENTION
**Google OAuth deprecation**
Important: OAuth 1.0 was officially deprecated on April 20, 2012, and will be
shut down on April 20, 2015. We encourage you to migrate to any of the other
protocols.

Google provides `Consumer Key` and `Consumer Secret` keys to registered
applications, but also allows unregistered application to use their authorization
system with, but beware that this method will display a security banner to the
user telling that the application is not trusted.

Check [Google OAuth](http://code.google.com/apis/accounts/docs/OAuth.html) and make your choice.

- fill `Consumer Key` and `Consumer Secret` values:
  ```default
  SOCIAL_AUTH_GOOGLE_OAUTH_KEY = ''
  SOCIAL_AUTH_GOOGLE_OAUTH_SECRET = ''
  ```

anonymous values will be used if not configured as described in their
[OAuth reference](http://code.google.com/apis/accounts/docs/OAuth_ref.html#SigningOAuth)

- setup any needed extra scope in:
  ```default
  SOCIAL_AUTH_GOOGLE_OAUTH_SCOPE = [...]
  ```

<a id="google-oauth2"></a>

## Google OAuth2

Recently Google launched OAuth2 support following the definition at OAuth2 draft.
It works in a similar way to plain OAuth mechanism, but developers **must** register
an application and apply for a set of keys. Check [Google OAuth2](http://code.google.com/apis/accounts/docs/OAuth2.html) document for details.

<a id="idp-setup"></a>

### IdP Setup

To configure Google OAuth2:

1. Go to the [Google Cloud Console](https://console.cloud.google.com/)
2. Create a new project or select an existing one
3. Navigate to **APIs & Services** > **Credentials**
4. Click **Create Credentials** > **OAuth client ID**
5. Configure:
   * **Application type**: Web application
   * **Authorized redirect URIs**: `https://your-domain.com/complete/google-oauth2/`
6. Note the **Client ID** and **Client Secret**
7. Configure the **OAuth consent screen** (`APIs & Services > OAuth consent screen`):
   * Set the **PRODUCT NAME** and other required fields
   * Add scopes: `email`, `profile`, `openid`

<a id="application-configuration"></a>

### Application Configuration

Fill in `Client ID` and `Client Secret` settings with values from Google:

```default
SOCIAL_AUTH_GOOGLE_OAUTH2_KEY = ''
SOCIAL_AUTH_GOOGLE_OAUTH2_SECRET = ''
```

- setup any needed extra scope:
  ```default
  SOCIAL_AUTH_GOOGLE_OAUTH2_SCOPE = [...]
  ```

Check which applications can be included in their [Google Data Protocol Directory](http://code.google.com/apis/gdata/docs/directory.html)

To allow user selecting Google account to use, add the `prompt` parameter with `select_account` value:

```default
SOCIAL_AUTH_GOOGLE_OAUTH2_AUTH_EXTRA_ARGUMENTS = {'prompt': 'select_account'}
```

To restrict authentication to specific domains (useful for G Suite/Google Workspace organizations), use domain whitelisting. Check the [whitelists](../configuration/settings.html#whitelists) settings for details.

<a id="google-one-tap"></a>

## Google One Tap

[Google One Tap](https://developers.google.com/identity/gsi/web/guides/features) is a bit different from the OAuth2 flow as the login process is started
on the client side. Because of this start url is not available, only a complete one.

* Additional dependencies are needed, these will be automatically installed by the `google-onetap` extra, for example: `uv pip install 'social-core[google-onetap]`.
* To enable the backend create an application using the [Google
  console](https://code.google.com/apis/console) to retrieve your Google Client ID.
  Make sure sure to add your website’s URL to `Authorized JavaScript origins` and
  `Authorized redirect URIs`
  (don’t forget to also include the port number if you are using localhost).
* Fill in the key setting looking inside the Google console the subsection
  `Credentials` inside `API & auth`:
  ```default
  AUTHENTICATION_BACKENDS = (
      ...
      'social_core.backends.google_onetap.GoogleOneTap',
  )

  SOCIAL_AUTH_GOOGLE_ONETAP_KEY = '...'
  SOCIAL_AUTH_GOOGLE_ONETAP_IGNORE_MISSING_CSRF_COOKIE = True / False
  ```

  `SOCIAL_AUTH_GOOGLE_ONETAP_KEY` corresponds to the variable `CLIENT ID`.
  `SOCIAL_AUTH_GOOGLE_ONETAP_IGNORE_MISSING_CSRF_COOKIE` disabled the CSRF checks
  if the token is missing from the cookies. This is an optional setting
  because the cookie is not being set if authentication process started on a different
  domain (for more details check out the [related issue](https://issuetracker.google.com/issues/226157137)).
* Add the [One Tap snippet](https://developers.google.com/identity/gsi/web/guides/display-google-one-tap) to your page:
  ```default
  <div id="g_id_onload"
      data-client_id="YOUR_GOOGLE_CLIENT_ID"
      data-login_uri="{% url 'social:complete' 'google-onetap' %}"
      data-your_own_param_1_to_login="any_value"
      data-your_own_param_2_to_login="any_value">
  </div>
  ```
* And [load the client library](https://developers.google.com/identity/gsi/web/guides/client-library):
  ```default
  <script src="https://accounts.google.com/gsi/client" async></script>
  ```

<a id="orkut"></a>

## Orkut

As of September 30, 2014, Orkut has been [shut down](https://support.google.com/orkut/?csw=1#Authenticating).

<a id="user-identification"></a>

## User identification

Google OAuth2, OpenID Connect, and One Tap use the stable `sub` claim for
account association. The legacy OAuth1 backend uses Google’s stable `id`.
Associations created by older social-core releases used the email address and
migrate to the stable identifier on the next successful authentication.

The following legacy settings remain accepted, but stable identifiers are now
the default:

```default
SOCIAL_AUTH_GOOGLE_OAUTH_USE_UNIQUE_USER_ID = True
```

or:

```default
SOCIAL_AUTH_GOOGLE_OAUTH2_USE_UNIQUE_USER_ID = True
```

depending on the backends in use.

See [Configurable User ID Key](../configuration/settings.html#configurable-user-id-key) for migration controls and custom identifier
settings.

<a id="refresh-tokens"></a>

## Refresh Tokens

To get an OAuth2 refresh token along with the access token, you must pass an extra argument: `access_type=offline`.
To do this with Google OAuth2:

```default
SOCIAL_AUTH_GOOGLE_OAUTH2_AUTH_EXTRA_ARGUMENTS = {
      'access_type': 'offline'
}
```
