Google OAuth
Let users sign in with their Google account.
Google is the only sign-in method in the free version (email sign-in ships with Pro), so the login page needs it. The Google button shows up once GOOGLE_CLIENT_ID is set.
Create the credentials
- Open the Google Cloud console and select or create a project.
- Configure the OAuth consent screen: app name, support email, and your domain once you deploy.
- Go to Credentials, then Create credentials → OAuth client ID, type Web application.
- Add the authorized redirect URIs:
http://localhost:3000/api/auth/callback/google
https://your-domain.com/api/auth/callback/google- Add the authorized JavaScript origins, used by the One Tap prompt below:
http://localhost:3000
https://your-domain.com- Copy the client ID and secret:
GOOGLE_CLIENT_ID=...
GOOGLE_CLIENT_SECRET=...
NEXT_PUBLIC_GOOGLE_CLIENT_ID=... # same client IDThe redirect URI is built from BETTER_AUTH_URL. If they don't match exactly (protocol, domain, no trailing slash), Google refuses the sign-in with redirect_uri_mismatch.
One Tap
Signed-out visitors on the marketing pages get Google's own prompt in the top
right corner, listing the accounts they are already signed in with. It needs
NEXT_PUBLIC_GOOGLE_CLIENT_ID; leave that one empty to turn the prompt off and
keep the button only.
Google rate-limits the prompt: once a visitor dismisses it, it stays hidden for a while. Use a fresh profile or an incognito window when testing.
Publish the app
While the consent screen is in Testing, only the test users you listed can sign in. Publish it before launch.