Skip to content

Create your OAuth client (Google & Microsoft)

Google and Microsoft integrations sign in with your own OAuth client: a small app registration you create once in the vendor’s console. Your tokens then go straight from Google or Microsoft to your browser and never pass through awflow’s servers.

It takes about 5 minutes, once. You can reuse the same client for every credential of that vendor (for example one Google client for Gmail, Drive, Sheets and Calendar, as long as the matching APIs are enabled).

For Gmail, Google Drive, Google Sheets and Google Calendar credentials.

  1. Create a project. Open the Google Cloud Console and create a project. Any name works, for example awflow.

  2. Enable the API(s) you need in the API Library for that project:

    IntegrationEnable
    GmailGmail API
    Google DriveGoogle Drive API
    Google SheetsGoogle Sheets API and Google Drive API (the spreadsheet picker lists files through Drive)
    Google CalendarGoogle Calendar API
  3. Set up the OAuth consent screen. Open the OAuth consent screen, choose External (or Internal if you use Google Workspace and only need your organization), fill in the app name and your email, then add your own Google account as a test user.

  4. Create the OAuth client. In Credentials, click Create credentials → OAuth client ID, choose the type Web application, and under Authorized redirect URIs add the redirect URI copied from the credential form. Click Create.

  5. Paste it into awflow. Copy the Client ID and Client Secret into the credential form, then click Check connection and approve the Google consent window.

Microsoft 365 uses a public client: no client secret is created or stored, only the Application (client) ID.

  1. Register an app. Open the Azure portal’s App registrations and click New registration. Any name works.

  2. Choose who can sign in. Under Supported account types, choose Accounts in any organizational directory and personal Microsoft accounts.

  3. Add the redirect URI. Under Redirect URI, choose the platform Single-page application and paste the redirect URI copied from the credential form. Click Register.

  4. Add permissions. In API permissions → Add a permission → Microsoft Graph → Delegated permissions, add offline_access, Mail.ReadWrite, Mail.Send, Files.ReadWrite, Calendars.ReadWrite and Tasks.ReadWrite.

  5. Paste it into awflow. Copy the Application (client) ID from the app’s Overview page into the credential form, then click Check connection. No client secret is needed.

  • redirect_uri_mismatch (Google) / AADSTS50011 (Microsoft) — the redirect URI in the console doesn’t match this install. Copy it again from the credential form’s guide and make sure there’s no trailing space or missing /oauth2.
  • access_denied / “app is blocked” — on Google, add your account as a test user on the consent screen. On Microsoft, your organization may require an admin to grant consent.
  • A node fails with “insufficient scope” / 403 — the API for that integration isn’t enabled (Google), or a permission is missing (Microsoft). Enable it, then click Check connection again so the new permissions are granted.

See also: Create credentials.