Skip to content
💻 🧠 Code 1001 > 🧪📓 Uncategorized > Google OAuth: Where to Find Your Client ID and Client Secret

Google OAuth: Where to Find Your Client ID and Client Secret

Google OAuth can sometimes seem confusing, especially when authentication has already been configured and an application suddenly asks for some kind of “Google key.” In practice, there are usually two related values involved:

  • Client ID — the identifier of the OAuth application.
  • Client Secret — the application’s secret.

In this article, we’ll look at where to find them in Google Cloud Console and how to tell them apart.

1. What Is Google OAuth?

OAuth 2.0 is an authorization framework that allows an application to use a user’s Google account without requiring the user to provide their Google password to the application.

For example, a user clicks:

Sign in with Google

Google then authenticates the user and informs your application which user has successfully signed in.

A typical flow looks like this:

User
     │
     │ "Sign in with Google"
     ▼
Your application
     │
     │ OAuth
     ▼
Google
     │
     │ User authentication
     ▼
Your application

To allow Google to identify which application is making the request, an OAuth client is created.


2. Client ID

When you create an OAuth client, Google assigns it a unique identifier.

It usually looks something like this:

741761730064-kr7ef8ikf4rf5fh1nt1htlvlqjgb0m7r.apps.googleusercontent.com

This is a:

Google OAuth Client ID

How to Recognize a Client ID

A Google OAuth Client ID usually:

  • contains .apps.googleusercontent.com;
  • is a long string;
  • is not a secret;
  • is used to identify the OAuth application.

For example:

GOOGLE_CLIENT_ID=
741761730064-kr7ef8sdkjfahnskfj1htlksadjfva;dsljgbm7r.apps.googleusercontent.com

A Client ID can be included in frontend configuration and may sometimes be visible to users. By itself, a Client ID does not provide access to a Google account.


3. Client Secret

The second important value is the Client Secret.

It is used by the application during OAuth communication with Google and should be treated as sensitive information.

It may look something like this:

GOCSPX-xxxxxxxxxxxxxxxxxxxxxxxx

Unlike a Client ID, a Client Secret should not be published in:

  • GitHub repositories;
  • browser-side JavaScript code;
  • public configuration files;
  • articles;
  • screenshots;
  • Docker images if the secret can be extracted from them;
  • publicly accessible .env files.

A typical configuration looks like this:

GOOGLE_CLIENT_ID=741761730064-....apps.googleusercontent.com
GOOGLE_CLIENT_SECRET=GOCSPX-....

The .env file is usually added to .gitignore.


4. Where to Find Your Google OAuth Client

Google OAuth credentials are managed through Google Cloud Console.

The usual path is:

Google Cloud Console
        ↓
APIs & Services
        ↓
Credentials
        ↓
OAuth 2.0 Client IDs

The OAuth 2.0 Client IDs section contains your existing OAuth clients.

For example:

OAuth 2.0 Client IDs

My Web Application
    Client ID:
    741761730064-kr7ef8ikf4rf5fh1nt1htlvlqjgb0m7r.apps.googleusercontent.com

By opening the appropriate OAuth client, you can view its configuration.


5. How to Find the Client Secret

Open:

Google Cloud Console
→ APIs & Services
→ Credentials

Then locate the required OAuth 2.0 Client ID.

Open its settings to view the client configuration.

If Google provides an option to download the configuration, you can use Download JSON.

For a web application, the JSON file may look something like this:

{
  "web": {
    "client_id": "741761730064-....apps.googleusercontent.com",
    "client_secret": "GOCSPX-....",
    "redirect_uris": [
      "https://example.com/oauth/callback"
    ]
  }
}

This file can contain:

client_id
client_secret
redirect_uris

6. Client ID and Client Secret Are Not API Keys

This is an important distinction.

Google uses several different types of credentials.

OAuth Client

An OAuth client is used for:

User authentication
        ↓
Sign in with Google

The main values are:

Client ID
Client Secret

API Key

An API key is used to access certain Google APIs:

Application
    ↓
API Key
    ↓
Google API

An API Key and an OAuth Client are not the same thing.

Therefore, if your application’s documentation requires:

GOOGLE_CLIENT_ID
GOOGLE_CLIENT_SECRET

you need an OAuth Client, not a regular API Key.


7. Which OAuth Client Type Should You Choose?

Google provides several types of OAuth clients.

For example:

Web application
Desktop app
Android
iOS
TVs and Limited Input devices

For a typical website or web application, the usual choice is:

Web application

One particularly important setting is:

Authorized redirect URIs

For example:

https://example.com/oauth/callback

This is the address Google redirects the user to after successful authentication.


8. Redirect URI

One of the most common problems with Google OAuth is an incorrect redirect_uri.

Suppose your application sends the user to Google:

https://accounts.google.com/...

After authentication, Google needs to redirect the user back to your application.

For example:

https://example.com/auth/google/callback

This address must be allowed in the OAuth client settings.

If your application uses:

https://example.com/auth/google/callback

but Google Cloud Console contains:

https://example.com/oauth/callback

the authentication process may fail.

Therefore, the redirect_uri used by your application must match one of the authorized redirect URIs configured for the OAuth client.


9. What This Looks Like in an Application

An application will typically have configuration variables such as:

GOOGLE_CLIENT_ID
GOOGLE_CLIENT_SECRET
GOOGLE_REDIRECT_URI

For example:

GOOGLE_CLIENT_ID=741761730064-....apps.googleusercontent.com
GOOGLE_CLIENT_SECRET=GOCSPX-....
GOOGLE_REDIRECT_URI=https://example.com/auth/google/callback

Here is what each value means:

ParameterPurpose
GOOGLE_CLIENT_IDIdentifies the OAuth application
GOOGLE_CLIENT_SECRETThe secret associated with the OAuth application
GOOGLE_REDIRECT_URIThe URL where the user is redirected after authentication

10. Can You Publish a Client ID?

Yes. A Client ID is not a secret by itself.

For example:

741761730064-kr7ef8ikf4rf5fh1nt1htlvlqjgb0m7r.apps.googleusercontent.com

is a Client ID.

Its presence in HTML or JavaScript does not, by itself, mean that a secret has been compromised.

However, this does not mean that all OAuth credentials can be published.

It is especially important to protect:

Client Secret

11. What If the Client Secret Is Lost?

If you can no longer find your Client Secret, do not try to guess it.

Instead, open:

Google Cloud Console
→ APIs & Services
→ Credentials

and locate the corresponding OAuth client.

If the original secret cannot be recovered, create a new OAuth client or use Google’s supported credential rotation process.

After that, update the secret in your application configuration.


12. An Important Point When Using Cloudflare

Google OAuth may be used not only directly by your application.

For example:

User
    ↓
Cloudflare Access
    ↓
Google
    ↓
Authentication

In this case, the Google OAuth client may be configured through Cloudflare Zero Trust.

This is different from OAuth implemented directly inside your Python, Node.js, or other application.

Therefore, before looking for a credential, you should first determine:

Who is actually using Google OAuth — your application or Cloudflare?

If authentication is configured through Cloudflare Access, the credentials may belong to the Cloudflare authentication setup.

If authentication is implemented directly in your application’s code, you need to locate the OAuth client used by that application.


13. How to Quickly Identify What You Have

If you have a string like:

741761730064-kr7ef8ikf4rf5fh1nt1htlvlqjgb0m7r.apps.googleusercontent.com

then it is almost certainly a:

Client ID

If the application also requires:

GOOGLE_CLIENT_SECRET

then that string alone is not enough.

You also need to find:

Client Secret

The final configuration may look something like this:

GOOGLE_CLIENT_ID=741761730064-kr7ef8ikf4rf5fh1nt1htlvlqjgb0m7r.apps.googleusercontent.com
GOOGLE_CLIENT_SECRET=GOCSPX-XXXXXXXXXXXXXXXX

14. Key Takeaways

Google OAuth involves two important concepts:

Client ID
    ↓
Who am I?

Client Secret
    ↓
The secret that authenticates the OAuth client

In our example:

741761730064-kr7ef8ikf4rf5fh1nt1htlvlqjgb0m7r.apps.googleusercontent.com

is a Client ID, not a secret key.

A complete OAuth configuration may also require a Client Secret.

And the most important security rule is:

You can expose a Client ID, but you should never publish a Client Secret.

If a Client Secret has accidentally been published on GitHub, in a chat, in an article, or in another public location, it is safest to treat it as compromised and replace or rotate it.

Leave a Reply

Your email address will not be published. Required fields are marked *