SaaS Starter

Google OAuth

Let users sign in with their Google account.

Google is the only sign-in method in the free version (email sign-in ships with Pro), so the login page needs it. The Google button shows up once GOOGLE_CLIENT_ID is set.

Create the credentials

  1. Open the Google Cloud console and select or create a project.
  2. Configure the OAuth consent screen: app name, support email, and your domain once you deploy.
  3. Go to Credentials, then Create credentials → OAuth client ID, type Web application.
  4. Add the authorized redirect URIs:
http://localhost:3000/api/auth/callback/google
https://your-domain.com/api/auth/callback/google
  1. Add the authorized JavaScript origins, used by the One Tap prompt below:
http://localhost:3000
https://your-domain.com
  1. Copy the client ID and secret:
GOOGLE_CLIENT_ID=...
GOOGLE_CLIENT_SECRET=...
NEXT_PUBLIC_GOOGLE_CLIENT_ID=... # same client ID

The redirect URI is built from BETTER_AUTH_URL. If they don't match exactly (protocol, domain, no trailing slash), Google refuses the sign-in with redirect_uri_mismatch.

One Tap

Signed-out visitors on the marketing pages get Google's own prompt in the top right corner, listing the accounts they are already signed in with. It needs NEXT_PUBLIC_GOOGLE_CLIENT_ID; leave that one empty to turn the prompt off and keep the button only.

Google rate-limits the prompt: once a visitor dismisses it, it stays hidden for a while. Use a fresh profile or an incognito window when testing.

Publish the app

While the consent screen is in Testing, only the test users you listed can sign in. Publish it before launch.

On this page