Repository navigation
How to use Oauth Installed application authorization code flow with gcloud-node? #678
Description
Activity
I think you're talking about 3LO (where a user gets a screen, and you get an OAuth2 token to use on their behalf, which you refresh from time to time...) right?
If so, we currently don't support that, as we're focused on server-to-server communication using service accounts. Pull-requests would be welcome for this, but we're not seeing a lot of customer demand for this one.
@jgeewax You can support it easily via grabbing the local token from
gcloud login. For deployed applications, we should strongly advise against using anything but service accounts (be they via a file or directly via GCE or GAE).@dhermes : I believe we do pull the token from
gcloud auth loginalready... I think this is about prompting the user for authorization (aka, do the work thatgcloud auth logindoes)Gotcher. I would cite the support for 3LO tokens minted via
gcloud auth loginas sufficient and would mark this as "Fixed" (closed on GH).We are dynamically creating new GCP project and want to upload files there. Currently, you can only create new GCP projects using 3LO (service accounts does not work). So, we have no service account associated with those GCP projects. I can use gapi-nodejs-client to work around it.
That makes sense -- a non-existent project doesn't have a service account that would have access.
That said, I think the only way to make that work is to steal the same code that something like
gcloud auth loginuses, and at that rate, you might as well run that command ... right?If you don't want to require having the
gcloudCLI installed, theGOOGLE_APPLICATION_CREDENTIALSenvironment variable is used with the "Google Default Credentials". You can pick it up as a secondary fallback.If you have the JSON object with
client_id,client_secret, etc. for anauthorized_usertype, you can give that to gcloud:var gcloud = require('gcloud')({ credentials: { client_id: "1111.apps.googleusercontent.com", client_secret: '...', refresh_token: '...', type: 'authorized_user' } });
@tamalsaha Is there any chance that is what you're looking for?
Reacted by Linda Lawton@tamalsaha going to close, but please re-open if that doesn't resolve the issue.
- added a commit that references this issue
on Nov 17, 2022 - added a commit that references this issue
on Jan 10, 2023 - added a commit that references this issue
on Jul 23, 2025 9 remaining items
- added a commit that references this issue
on Jan 28, 2026 - added a commit that references this issue
on Feb 5, 2026 - added a commit that references this issue
on Feb 23, 2026 - added 2 commits that reference this issue
on Feb 24, 2026 - added a commit that references this issue
on Feb 26, 2026 - added a commit that references this issue
on Feb 26, 2026 - added a commit that references this issue
on Mar 12, 2026 - added a commit that references this issue
on Mar 17, 2026 - added a commit that references this issue
on Mar 18, 2026