# Google: OAuth2 single service

This document contains instructions for creating a Google credential for a single service. They're also available as a [video](/guides/automated-workflows#video).

## Prerequisites

* [Google Cloud](https://cloud.google.com/){:targe=_blank .external-link} account
* [Google Cloud Platform project](https://developers.google.com/workspace/marketplace/create-gcp-project){:targe=_blank .external-link}
* If you haven't used OAuth in your Google Cloud project before, you need to [configure the OAuth consent screen](/guides/automated-workflows/guides/configure-oauth-consent).
* If using Google Perspective: [Request API Access](https://developers.perspectiveapi.com/s/docs-get-started){:targe=_blank .external-link}
* If using Google Ads: [Developer Token](https://developers.google.com/google-ads/api/docs/first-call/dev-token){:targe=_blank .external-link}


## Set up OAuth

### Create a new credential in Mosaic Workflows

1. Follow the steps to [Create a credential](/guides/automated-workflows/credentials/add-edit-credentials). If you create a credential by selecting **Create new** in the credentials dropdown in a node, Mosaic Workflows automatically creates the correct credential type for that node. If you select **Credentials > New**, you must browse for the credential type. To create a credential for a [custom API call](#), select **Google OAuth2 API**. This allows you to create a generic credential, then set its scopes.
2. Note the **OAuth Redirect URL** from the node credential modal. You'll need this in the next section.


### Set up OAuth in Google Cloud

1. Go to [Google Cloud Console | APIs and services](https://console.cloud.google.com/apis/credentials) and make sure you're in the project you want to use.
2. **Optional:** If you haven't used OAuth in your Google Cloud project before, you need to [configure the OAuth consent screen](/guides/automated-workflows/guides/configure-oauth-consent). Expand the detailed steps below for more guidance.


details
summary
b
View detailed steps
1. Select **OAuth consent screen**.
2. For **User Type**, select **Internal** for user access within your organization's Google workspace or **External** for any user with a Google account.
3. Select **Create**.
4. Enter the essential information: **App name**, **User support email**, and the **Email addresses** field in **Developer contact information**.
5. Add an authorized domain: select **+ ADD DOMAIN**. Enter `transmit.cloud` if using Mosaic Workflows's Cloud service, or the domain of your Mosaic Workflows instance if you're self-hosting.
6. Select **SAVE AND CONTINUE** to go to the **Scopes** page.
7. You don't need to set any scopes. Select **SAVE AND CONTINUE** again to go to the **Summary** page.
8. On the **Summary** page, review the information, then select **BACK TO DASHBOARD**.


1. Select **+ CREATE CREDENTIALS > OAuth client ID**.
2. In the **Application type** dropdown, select **Web application**. Google automatically generates a name.
3. Under **Authorizes redirect URIs**, select **+ ADD URI**. Paste in the OAuth redirect URL from Mosaic Workflows.
4. Select **CREATE**.
5. Enable each Google service API that you want to use:
  1. If using Google Perspective or Google Ads: [Request API Access for Perspective](https://developers.perspectiveapi.com/s/docs-get-started) or a [Developer Token for Ads](https://developers.google.com/google-ads/api/docs/first-call/dev-token).
  2. Access your [Google Cloud Console - Library](https://console.cloud.google.com/apis/library). Make sure you're in the correct project.
6. Search for and select the API(s) you want to enable. For example, for the Gmail node, search for and enable the Gmail API.
7. Select **ENABLE**.


### Create and test your connection

In Mosaic Workflows:

1. Enter your new **Client ID** and **Client Secret** from Google Cloud Console in the credentials modal.
2. Select **Sign in with Google** to complete your Google authentication.
3. **Save** your new credentials.


## Troubleshooting

### Google hasn't verified this app

If using the OAuth authentication method, you might see the warning **Google hasn't verified this app**. To avoid this, you can create OAuth credentials from the same account you want to authenticate.

If you need to use credentials generated by another account (by a developer or another third party), follow the instructions in [Google Cloud documentation | Authorization errors: Google hasn't verified this app](https://developers.google.com/nest/device-access/reference/errors/authorization#google_hasnt_verified_this_app).

### Google Cloud app becoming unauthorized

For Google Cloud apps with **Publishing status** set to **Testing** and **User type** set to **External**, consent and tokens expire after seven days. Refer to [Google Cloud Platform Console Help | Setting up your OAuth consent screen](https://support.google.com/cloud/answer/10311615?hl=en#zippy=%2Ctesting) for more information. To resolve this, reconnect the app in the Mosaic Workflows credentials modal.