Google OAuth can sometimes seem confusing, especially when authentication has already been configured and an application suddenly asks for some kind of “Google key.” In practice, there are usually two related values involved:
- Client ID — the identifier of the OAuth application.
- Client Secret — the application’s secret.
In this article, we’ll look at where to find them in Google Cloud Console and how to tell them apart.
1. What Is Google OAuth?
OAuth 2.0 is an authorization framework that allows an application to use a user’s Google account without requiring the user to provide their Google password to the application.
For example, a user clicks:
Sign in with Google
Google then authenticates the user and informs your application which user has successfully signed in.
A typical flow looks like this:
User
│
│ "Sign in with Google"
▼
Your application
│
│ OAuth
▼
Google
│
│ User authentication
▼
Your application
To allow Google to identify which application is making the request, an OAuth client is created.
2. Client ID
When you create an OAuth client, Google assigns it a unique identifier.
It usually looks something like this:
741761730064-kr7ef8ikf4rf5fh1nt1htlvlqjgb0m7r.apps.googleusercontent.com
This is a:
Google OAuth Client ID
How to Recognize a Client ID
A Google OAuth Client ID usually:
- contains
.apps.googleusercontent.com; - is a long string;
- is not a secret;
- is used to identify the OAuth application.
For example:
GOOGLE_CLIENT_ID=
741761730064-kr7ef8sdkjfahnskfj1htlksadjfva;dsljgbm7r.apps.googleusercontent.com
A Client ID can be included in frontend configuration and may sometimes be visible to users. By itself, a Client ID does not provide access to a Google account.
3. Client Secret
The second important value is the Client Secret.
It is used by the application during OAuth communication with Google and should be treated as sensitive information.
It may look something like this:
GOCSPX-xxxxxxxxxxxxxxxxxxxxxxxx
Unlike a Client ID, a Client Secret should not be published in:
- GitHub repositories;
- browser-side JavaScript code;
- public configuration files;
- articles;
- screenshots;
- Docker images if the secret can be extracted from them;
- publicly accessible
.envfiles.
A typical configuration looks like this:
GOOGLE_CLIENT_ID=741761730064-....apps.googleusercontent.com
GOOGLE_CLIENT_SECRET=GOCSPX-....
The .env file is usually added to .gitignore.
4. Where to Find Your Google OAuth Client
Google OAuth credentials are managed through Google Cloud Console.
The usual path is:
Google Cloud Console
↓
APIs & Services
↓
Credentials
↓
OAuth 2.0 Client IDs
The OAuth 2.0 Client IDs section contains your existing OAuth clients.
For example:
OAuth 2.0 Client IDs
My Web Application
Client ID:
741761730064-kr7ef8ikf4rf5fh1nt1htlvlqjgb0m7r.apps.googleusercontent.com
By opening the appropriate OAuth client, you can view its configuration.
5. How to Find the Client Secret
Open:
Google Cloud Console
→ APIs & Services
→ Credentials
Then locate the required OAuth 2.0 Client ID.
Open its settings to view the client configuration.
If Google provides an option to download the configuration, you can use Download JSON.
For a web application, the JSON file may look something like this:
{
"web": {
"client_id": "741761730064-....apps.googleusercontent.com",
"client_secret": "GOCSPX-....",
"redirect_uris": [
"https://example.com/oauth/callback"
]
}
}
This file can contain:
client_id
client_secret
redirect_uris
6. Client ID and Client Secret Are Not API Keys
This is an important distinction.
Google uses several different types of credentials.
OAuth Client
An OAuth client is used for:
User authentication
↓
Sign in with Google
The main values are:
Client ID
Client Secret
API Key
An API key is used to access certain Google APIs:
Application
↓
API Key
↓
Google API
An API Key and an OAuth Client are not the same thing.
Therefore, if your application’s documentation requires:
GOOGLE_CLIENT_ID
GOOGLE_CLIENT_SECRET
you need an OAuth Client, not a regular API Key.
7. Which OAuth Client Type Should You Choose?
Google provides several types of OAuth clients.
For example:
Web application
Desktop app
Android
iOS
TVs and Limited Input devices
For a typical website or web application, the usual choice is:
Web application
One particularly important setting is:
Authorized redirect URIs
For example:
https://example.com/oauth/callback
This is the address Google redirects the user to after successful authentication.
8. Redirect URI
One of the most common problems with Google OAuth is an incorrect redirect_uri.
Suppose your application sends the user to Google:
https://accounts.google.com/...
After authentication, Google needs to redirect the user back to your application.
For example:
https://example.com/auth/google/callback
This address must be allowed in the OAuth client settings.
If your application uses:
https://example.com/auth/google/callback
but Google Cloud Console contains:
https://example.com/oauth/callback
the authentication process may fail.
Therefore, the redirect_uri used by your application must match one of the authorized redirect URIs configured for the OAuth client.
9. What This Looks Like in an Application
An application will typically have configuration variables such as:
GOOGLE_CLIENT_ID
GOOGLE_CLIENT_SECRET
GOOGLE_REDIRECT_URI
For example:
GOOGLE_CLIENT_ID=741761730064-....apps.googleusercontent.com
GOOGLE_CLIENT_SECRET=GOCSPX-....
GOOGLE_REDIRECT_URI=https://example.com/auth/google/callback
Here is what each value means:
| Parameter | Purpose |
|---|---|
GOOGLE_CLIENT_ID | Identifies the OAuth application |
GOOGLE_CLIENT_SECRET | The secret associated with the OAuth application |
GOOGLE_REDIRECT_URI | The URL where the user is redirected after authentication |
10. Can You Publish a Client ID?
Yes. A Client ID is not a secret by itself.
For example:
741761730064-kr7ef8ikf4rf5fh1nt1htlvlqjgb0m7r.apps.googleusercontent.com
is a Client ID.
Its presence in HTML or JavaScript does not, by itself, mean that a secret has been compromised.
However, this does not mean that all OAuth credentials can be published.
It is especially important to protect:
Client Secret
11. What If the Client Secret Is Lost?
If you can no longer find your Client Secret, do not try to guess it.
Instead, open:
Google Cloud Console
→ APIs & Services
→ Credentials
and locate the corresponding OAuth client.
If the original secret cannot be recovered, create a new OAuth client or use Google’s supported credential rotation process.
After that, update the secret in your application configuration.
12. An Important Point When Using Cloudflare
Google OAuth may be used not only directly by your application.
For example:
User
↓
Cloudflare Access
↓
Google
↓
Authentication
In this case, the Google OAuth client may be configured through Cloudflare Zero Trust.
This is different from OAuth implemented directly inside your Python, Node.js, or other application.
Therefore, before looking for a credential, you should first determine:
Who is actually using Google OAuth — your application or Cloudflare?
If authentication is configured through Cloudflare Access, the credentials may belong to the Cloudflare authentication setup.
If authentication is implemented directly in your application’s code, you need to locate the OAuth client used by that application.
13. How to Quickly Identify What You Have
If you have a string like:
741761730064-kr7ef8ikf4rf5fh1nt1htlvlqjgb0m7r.apps.googleusercontent.com
then it is almost certainly a:
Client ID
If the application also requires:
GOOGLE_CLIENT_SECRET
then that string alone is not enough.
You also need to find:
Client Secret
The final configuration may look something like this:
GOOGLE_CLIENT_ID=741761730064-kr7ef8ikf4rf5fh1nt1htlvlqjgb0m7r.apps.googleusercontent.com
GOOGLE_CLIENT_SECRET=GOCSPX-XXXXXXXXXXXXXXXX
14. Key Takeaways
Google OAuth involves two important concepts:
Client ID
↓
Who am I?
Client Secret
↓
The secret that authenticates the OAuth client
In our example:
741761730064-kr7ef8ikf4rf5fh1nt1htlvlqjgb0m7r.apps.googleusercontent.com
is a Client ID, not a secret key.
A complete OAuth configuration may also require a Client Secret.
And the most important security rule is:
You can expose a Client ID, but you should never publish a Client Secret.
If a Client Secret has accidentally been published on GitHub, in a chat, in an article, or in another public location, it is safest to treat it as compromised and replace or rotate it.