Skip to content

OAuth providers

Google

Sign in with Google’s OpenID Connect provider. Start with OAuth setup.

Create an OAuth client in the Google Cloud console. Add https://app.example.com/auth/google/callback as an authorized redirect URI.

apps/server/google.ts
import { Redacted } from "effect";
import { Http } from "@yielded/auth";
import * as OpenIdClient from "@yielded/auth-openid-client";
import { AppAuth } from "./auth";
import { config } from "./config";
export const AuthRoutes = Http.layer(AppAuth, {
origin: config.AUTH_ORIGIN,
oauth: {
providers: {
google: OpenIdClient.provider({
protocol: "oidc",
issuer: "https://accounts.google.com",
clientId: config.GOOGLE_CLIENT_ID,
clientSecret: Redacted.make(config.GOOGLE_CLIENT_SECRET),
tokenEndpointAuthMethod: "client_secret_post",
}),
},
},
});

Install openid-client and supply your services. AuthRoutes serves the callback URL derived from origin. Customize callbacks →

The default openid scope is enough for sign-in.

const auth = yield* AppAuth;
const started = yield* auth.signIn({
provider: "google",
returnTarget: "/account",
});

Redirect to Redacted.value(started.authorizationUrl). The callback completes sign-in and redirects to returnTarget. See the server example for Google and GitHub together.