Skip to main content

Sign in with Google

How to register Curupira in the Google Cloud Console so your tenant's users can sign in with their Google account.

Console: console.cloud.google.com (pick or create a project first).

What you'll hand to Curupira at the end: a Client ID and a Client Secret. Everything else below is Google-side configuration so those credentials work.

Curupira detailValue
TypeOpenID Connect (signed id_token, verified)
Callback URL to registerhttps://auth.curupira.api.br/sso/google/callback
Default scopesopenid email profile

APIs & Services → OAuth consent screen.

FieldWhat to put
User typeExternal (unless every user is in your Google Workspace org → Internal)
App nameYour app's name
User support emailYour support address
Authorized domaincurupira.api.br
Developer contactYour email

Scopes: add openid, email, profile. These are non-sensitive — no Google verification/review required.

Publishing status: while testing, add yourself under Test users, or click Publish app (non-sensitive scopes publish without review). Unpublished apps only let listed test users sign in.

2 · Create the OAuth client ID

APIs & Services → Credentials → Create Credentials → OAuth client ID.

FieldWhat to put
Application typeWeb application
Authorized redirect URIshttps://auth.curupira.api.br/sso/google/callback (paste exactly)

Google matches the redirect URI character-for-character — https, no trailing slash, lower-case. Create.

3 · Copy the credentials

The dialog shows the Client ID and Client secret — copy both (you can re-open them from the credential's detail page later).

4 · Add the connection in Curupira

In the admin dashboard → SSO Connections, choose your tenant and Add SSO Connection:

  • Provider: Google
  • Client ID / Client Secret: from step 3 (the secret is stored encrypted and never shown again)
  • Scopes: leave blank to use the defaults (openid email profile)
  • Enabled: on

Then test at https://auth.curupira.api.br/sso/google/authorize?tenant=<your-tenant-slug> — a Google consent screen should send you back to Curupira signed in.

:::note Account linking If Google returns an email that matches an existing password account, sign-in is refused — sign in with your password first, then connect SSO from your account settings. A brand-new email creates an SSO-only user automatically. :::

Checklist

  • Consent screen: External, app name, authorized domain curupira.api.br
  • Scopes openid email profile added (non-sensitive → no review)
  • Test users added or app Published
  • OAuth client ID: Web application
  • Redirect URI https://auth.curupira.api.br/sso/google/callback (exact)
  • Client ID + Client Secret entered in SSO Connections