Google login and Google One Tap for your SaaS
Add "Sign in with Google" and Google One Tap to a ShipAny app with better-auth — create the OAuth client, set the redirect URI and switch it on from the admin panel.
Last updated: Oct 8, 2026
Google sign-in is usually the highest-converting login option on a SaaS. ShipAny uses better-auth, so Google OAuth and Google One Tap are already wired — you only add credentials.
What ShipAny handles
- OAuth flow through better-auth's catch-all route; the callback is
/api/auth/callback/google. - Google One Tap: an optional prompt that signs returning visitors in with one click, without leaving the page.
- Account linking and sessions: users, accounts and sessions are stored in your own database (httpOnly cookies).
- Runtime configuration: credentials live in the admin panel, so you can rotate them without redeploying.
Setup
- In the Google Cloud Console, open APIs & Services → Credentials and create an OAuth client ID of type Web application. (New projects need the OAuth consent screen configured first.)
- Add your domain to Authorized JavaScript origins, e.g.
https://your-domain.com. - Add the redirect URI
https://your-domain.com/api/auth/callback/google. - Copy the client ID and client secret.
- In ShipAny, open Admin → Settings → Auth → Google Auth, paste both values and switch on Enable Google auth. Switch on Enable Google One Tap too if you want the one-click prompt.
Tips
- Add every domain you serve (production, staging, custom domains) to both the JavaScript origins and the redirect URIs, or Google returns
redirect_uri_mismatch. - Publish the consent screen before launch — in testing mode only listed test users can sign in.
- One Tap only appears to signed-out visitors with an active Google session in the browser.
