Google login and Google One Tap for your SaaS

Add "Sign in with Google" and Google One Tap to a ShipAny app with better-auth — create the OAuth client, set the redirect URI and switch it on from the admin panel.

Last updated: Oct 8, 2026

Google sign-in is usually the highest-converting login option on a SaaS. ShipAny uses better-auth, so Google OAuth and Google One Tap are already wired — you only add credentials.

What ShipAny handles

  • OAuth flow through better-auth's catch-all route; the callback is /api/auth/callback/google.
  • Google One Tap: an optional prompt that signs returning visitors in with one click, without leaving the page.
  • Account linking and sessions: users, accounts and sessions are stored in your own database (httpOnly cookies).
  • Runtime configuration: credentials live in the admin panel, so you can rotate them without redeploying.

Setup

  1. In the Google Cloud Console, open APIs & Services → Credentials and create an OAuth client ID of type Web application. (New projects need the OAuth consent screen configured first.)
  2. Add your domain to Authorized JavaScript origins, e.g. https://your-domain.com.
  3. Add the redirect URI https://your-domain.com/api/auth/callback/google.
  4. Copy the client ID and client secret.
  5. In ShipAny, open Admin → Settings → Auth → Google Auth, paste both values and switch on Enable Google auth. Switch on Enable Google One Tap too if you want the one-click prompt.

Tips

  • Add every domain you serve (production, staging, custom domains) to both the JavaScript origins and the redirect URIs, or Google returns redirect_uri_mismatch.
  • Publish the consent screen before launch — in testing mode only listed test users can sign in.
  • One Tap only appears to signed-out visitors with an active Google session in the browser.

Related reading

More in Integrations

Ship your AI SaaS with ShipAny

Auth, payments, credits, i18n and admin are pre-wired — start from a production-ready template and focus on your product.