Skip to content

How to use Oauth Installed application authorization code flow with gcloud-node? #678

Description

@tamalsaha
No description provided.

Activity

  1. jgeewax commented on Jun 18, 2015

    @jgeewax
    Contributor

    I think you're talking about 3LO (where a user gets a screen, and you get an OAuth2 token to use on their behalf, which you refresh from time to time...) right?

    If so, we currently don't support that, as we're focused on server-to-server communication using service accounts. Pull-requests would be welcome for this, but we're not seeing a lot of customer demand for this one.

  2. dhermes commented on Jun 18, 2015

    @dhermes
    Contributor

    @jgeewax You can support it easily via grabbing the local token from gcloud login. For deployed applications, we should strongly advise against using anything but service accounts (be they via a file or directly via GCE or GAE).

  3. jgeewax commented on Jun 18, 2015

    @jgeewax
    Contributor

    @dhermes : I believe we do pull the token from gcloud auth login already... I think this is about prompting the user for authorization (aka, do the work that gcloud auth login does)

  4. dhermes commented on Jun 18, 2015

    @dhermes
    Contributor

    Gotcher. I would cite the support for 3LO tokens minted via gcloud auth login as sufficient and would mark this as "Fixed" (closed on GH).

  5. tamalsaha commented on Jun 19, 2015

    @tamalsaha
    Author

    We are dynamically creating new GCP project and want to upload files there. Currently, you can only create new GCP projects using 3LO (service accounts does not work). So, we have no service account associated with those GCP projects. I can use gapi-nodejs-client to work around it.

  6. jgeewax commented on Jun 19, 2015

    @jgeewax
    Contributor

    That makes sense -- a non-existent project doesn't have a service account that would have access.

    That said, I think the only way to make that work is to steal the same code that something like gcloud auth login uses, and at that rate, you might as well run that command ... right?

  7. dhermes commented on Jun 22, 2015

    @dhermes
    Contributor

    If you don't want to require having the gcloud CLI installed, the GOOGLE_APPLICATION_CREDENTIALS environment variable is used with the "Google Default Credentials". You can pick it up as a secondary fallback.

  8. stephenplusplus commented on Aug 14, 2015

    @stephenplusplus
    Contributor

    If you have the JSON object with client_id, client_secret, etc. for an authorized_user type, you can give that to gcloud:

    var gcloud = require('gcloud')({
      credentials: {
        client_id: "1111.apps.googleusercontent.com",
        client_secret: '...',
        refresh_token: '...',
        type: 'authorized_user'
      }
    });

    @tamalsaha Is there any chance that is what you're looking for?

  9. stephenplusplus commented on Aug 24, 2015

    @stephenplusplus
    Contributor

    @tamalsaha going to close, but please re-open if that doesn't resolve the issue.

  10. added a commit that references this issue on Jul 23, 2025
  11. 9 remaining items

  12. added a commit that references this issue on Jan 28, 2026
  13. added a commit that references this issue on Feb 17, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

No labels
No labels

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions