---
name: google-oauth-app
description: The multi-API Google connector layer on top of the shared `google-cloud-console-oauth` skill — the combined scope set a connector requests when one Google connection spans several APIs at once (identity, Gmail, Calendar/Meet, Contacts/People, Drive/Sheets), and the tier that union lands in. Read the base skill first. Use this when the job is a Google connection covering several products or you need the combined scope picture; for a single product use its own skill — `gmail-oauth-app`, `google-calendar-oauth-app`, `google-drive-oauth-app`, `google-sheets-oauth-app`, `google-docs-oauth-app`, `google-contacts-oauth-app`, `google-meet-oauth-app`, `google-tasks-oauth-app`, `google-analytics-oauth-app`, `google-ads-oauth-app` or `google-business-profile-oauth-app`. For a plain Google OAuth client with no product named, the base skill alone is the whole job. For any other vendor's developer portal, use that vendor's skill instead.
---

# Google OAuth2 App Registration — Gmail, Calendar/Meet, Contacts/People, Drive/Sheets

The Google-API-specific half of registering an OAuth 2.0 client for this connector: what it asks Google for, what
that costs in review terms, and how its authorize and token requests are shaped.

The registration mechanics themselves are not here. They are the same for every Google API and live in the base skill.

## Built on: `google-cloud-console-oauth`

**Read `google-cloud-console-oauth` first, in full, then come back here.** It owns:

- **Project and app setup** — picking or creating the Cloud project, organization placement, permissions, and the
  Google Auth Platform pages (Overview, Branding, Audience, Clients, Data Access, Verification Center).
- **The client itself** — why **Web application** is the only common type that yields a usable client secret, and why
  a service account is not a substitute; plus the exact-match **redirect-URI rules** and the platform's callback list.
- **Scope mechanics** — the non-sensitive / sensitive / restricted tiers, why the Data Access declaration and the
  authorize request must be identical, and the refresh-token rules (`access_type=offline`, `prompt=consent`, 100 live
  tokens per account per client, six-month idle expiry).
- **The client secret** — shown and downloadable in full exactly once at creation, hashed afterwards with only the
  last four characters visible, and rotated by add-then-disable rather than replace.
- **Testing vs In production, verification and CASA** — the seven-day refresh tokens in `Testing`, the two different
  100-user caps, the brand / sensitive / restricted review layers, the CASA assurance levels and annual
  revalidation, and the end-to-end verification and hand-off checklists.

If you loaded only this file, you are missing all of the above, and nothing below substitutes for it — in particular,
declaring a scope, capturing the secret and publishing the app are base-skill steps.

## Inputs specific to this connector

The base skill's input table still applies (app name, branding assets, owning account, redirect URIs, audience, new
client vs edit). Collect these on top of it, in the same batch:

| Input | Notes |
| --- | --- |
| **Which Google products the customer actually needs** — Gmail, Calendar/Meet, Contacts/People, Drive, Sheets | Decides the scope set, and therefore the review tier |
| **Do the Gmail or broad Drive scopes apply?** | Blocking on timeline — they put the whole app in the restricted tier |
| **Can the product live with per-file Drive access (`drive.file`)?** | A product decision, not a console setting — raise it, do not decide it |

## 1. APIs to enable for these scopes

Scopes belonging to an API that is not enabled do not appear in the Data Access picker, and a call made with such a
scope fails with `403 accessNotConfigured`. Enable, from **APIs & Services → Library**, whichever of these the chosen
scope set needs:

| Product area | API to enable |
| --- | --- |
| Gmail | Gmail API |
| Calendar | Google Calendar API |
| Meet | Google Meet API |
| Contacts / People | People API |
| Drive | Google Drive API |
| Sheets | Google Sheets API |

Identity scopes (`openid`, `profile`, `email`, `userinfo.*`) need no API enabled.

## 2. What the connector actually requests

As of 2026-09-20, **the connector requests the following scope strings**, assembled per object type — only the scopes
for the objects a given connection uses are sent. **Confirm the current set with the connector's owner** before
declaring scopes on Data Access or submitting for verification.

Identity, on nearly every request:

```
openid
profile
email
https://www.googleapis.com/auth/userinfo.email
https://www.googleapis.com/auth/userinfo.profile
```

Calendar and Meet:

```
https://www.googleapis.com/auth/calendar.readonly
https://www.googleapis.com/auth/calendar
https://www.googleapis.com/auth/calendar.events.readonly
https://www.googleapis.com/auth/calendar.events
https://www.googleapis.com/auth/calendar.freebusy
https://www.googleapis.com/auth/calendar.events.freebusy
https://www.googleapis.com/auth/meetings.space.readonly
```

Gmail (**restricted**):

```
https://www.googleapis.com/auth/gmail.readonly
https://www.googleapis.com/auth/gmail.compose
https://www.googleapis.com/auth/gmail.modify
```

Contacts / People:

```
https://www.googleapis.com/auth/profile.emails.read
https://www.googleapis.com/auth/contacts.readonly
https://www.googleapis.com/auth/contacts.other.readonly
https://www.googleapis.com/auth/contacts
```

Drive (**restricted**, except `drive.file`) and Sheets:

```
https://www.googleapis.com/auth/drive.readonly
https://www.googleapis.com/auth/drive
https://www.googleapis.com/auth/drive.file
https://www.googleapis.com/auth/drive.labels.readonly
https://www.googleapis.com/auth/spreadsheets.readonly
https://www.googleapis.com/auth/spreadsheets
```

### The tier consequence

**Declared as a union, this connector's scope set is restricted-tier**, because of the Gmail scopes and the broad
Drive scopes (`drive`, `drive.readonly`). Since the tier of the app is the tier of its most sensitive scope, that
pulls the whole project into restricted verification plus the CASA assessment and its annual revalidation.

Read the other way round, that is a lever:

- Calendar, Meet, Contacts/People and Sheets on their own are **sensitive**, not restricted — brand check,
  justification and demo video, no security assessment.
- **`https://www.googleapis.com/auth/drive.file` is not restricted.** It grants access only to files the app created
  or the user explicitly picked. Where the product can live with per-file access, dropping `drive`/`drive.readonly`
  removes an entire annual assessment from the roadmap.
- **Gmail has no such escape hatch** — every Gmail scope, including `gmail.readonly`, is restricted. If the customer
  needs Gmail at all, the app is restricted-tier.

So confirm which objects the customer actually needs before declaring the union of everything. Adding Gmail or broad
Drive later can force an out-of-cycle re-assessment; declaring them now when nobody uses them buys the same review for
nothing.

## 3. Auth quirks this connector relies on

Also as of 2026-09-20, and also worth confirming with the connector's owner:

- Authorize endpoint `https://accounts.google.com/o/oauth2/v2/auth`; token and refresh endpoint
  `https://oauth2.googleapis.com/token`.
- The authorize request carries `client_id`, `scope`, `response_type=code`, `state`, `redirect_uri`,
  **`access_type=offline`** and **`prompt=consent`** — the two parameters without which a reconnect stores no refresh
  token (base skill, scope mechanics).
- Token exchange is a **form POST with the credentials in the body** (`client_id`, `client_secret`, `code`,
  `grant_type`, `redirect_uri`) — not HTTP Basic. Refresh sends `client_id`, `client_secret`, `grant_type`,
  `refresh_token`.
- Access tokens are sent as `Bearer`. Scopes are joined with a single space.
- **No PKCE.** This is a confidential web-application client authenticating with its secret; no `code_challenge` is
  sent. That matches Google's web server flow, which does not require PKCE for confidential clients — but it means the
  secret is load-bearing and must be protected accordingly.
- Login-only flows request `openid profile email` and nothing else.

## 4. Gmail-specific token behaviour

**A user changing their Google Account password invalidates refresh tokens that carry Gmail scopes.** Nothing carrying
only Calendar, Contacts, Drive or Sheets scopes is affected. So a support report of "our Gmail connections keep
breaking but everything else is fine" is usually expected behaviour, not a bug: the user re-authorizes. Expect it to
look like a cluster whenever a customer runs a password-rotation policy.

## 5. Symptoms specific to these APIs

The base skill's table covers the generic OAuth failures. These are the ones that come from this scope set:

| Symptom | Cause |
| --- | --- |
| `403` with `accessNotConfigured` on the first Gmail / Calendar / Meet / People / Drive / Sheets call | That product's API is not enabled in the project (§1) — the OAuth grant succeeded, the API is simply off |
| Gmail connections break when a user changes their password, others survive | Expected: Gmail-scoped refresh tokens are invalidated on password change (§4) |
| Drive lists only a handful of files, or 404s on a file the user can see | `drive.file` was granted instead of full Drive — it only reaches files the app created or the user picked (§2) |
| A Calendar-only or Contacts-only customer is stuck behind a restricted-scope review | The Data Access page declares the union including Gmail / broad Drive, so the whole app is restricted-tier (§2) |

## Stop and ask

On top of the base skill's list, hand back to a human when: the choice between `drive.file` and full Drive access is
really a product decision; the customer needs Gmail at all and nobody has budgeted for CASA and its annual
revalidation; or someone wants the union of every scope above declared when only one product area is in use.

## References

The base skill carries the generic Google OAuth, verification and CASA references. These are the per-API scope pages
for this connector:

- Choose Gmail API scopes — https://developers.google.com/workspace/gmail/api/auth/scopes
- Google Drive API-specific authorization and scopes — https://developers.google.com/workspace/drive/api/guides/api-specific-auth
- Google Calendar API auth and scopes — https://developers.google.com/workspace/calendar/api/auth
- People API authorization and scopes — https://developers.google.com/people/v1/how-tos/authorizing
- Google Sheets API scopes — https://developers.google.com/workspace/sheets/api/scopes
