GOOGLE_CLIENT_ID and GOOGLE_CLIENT_SECRET are set on the server.Before you start
- A Google account that can create projects in Google Cloud console. To keep sign-in limited to your company, use an account in your Google Workspace.
- A OneCLI organization admin account. Members can’t change credentials.
Set up your Google client
Start in OneCLI
- For the whole organization: Global Connections → Apps → Gmail → Custom credentials.
- For one workspace only: Connections → Apps → Gmail → Custom credentials in that workspace. This overrides the organization’s client in that workspace.

The Google credentials form in OneCLI.
- 1. Click Enable the Google APIs in your Cloud project. It opens the next step.
- 2. Copy the Redirect URI. You’ll paste it into Google in step 4.
- 3. Leave this page open. You’ll paste the Client ID and Client Secret here at the end.
- 4. Save credentials comes last.
Enable the Google APIs

Confirm the project, then enable the APIs.
- 1. Check the project. Pick or create the project for OneCLI here.
- 2. Click Next, then Enable.
Choose who can sign in
OneCLI and your support email, then come back here.
Pick Internal or External.
- 1. Open Audience.
- 2. Choose the user type:
Create the client

Start a new OAuth client.
- 1. Open Clients.
- 2. Click Create client.

Web application, named OneCLI.
- 1. Set Application type to Web application.
- 2. Set Name to
OneCLI.

Add the Redirect URI from OneCLI.
- 1. Under Authorized redirect URIs, click Add URI.
- 2. Paste the Redirect URI you copied from OneCLI. It ends in
/v1/apps/oauth/google/callback. One URI covers every Google app. Google only acceptshttpsURIs, except forlocalhost.
Save in OneCLI and connect
- Back in OneCLI, paste the Client ID and Client Secret, then click Save credentials.
- Open any Google app, for example Google Drive, and click Connect. You don’t need to enter credentials again for other Google apps.
- Sign in with Google and click Allow. With External in Testing, Google first shows Google hasn’t verified this app. Click Continue.
- Ask your agent for something simple, such as “List my 5 most recent Drive files.”
Where credentials apply
Troubleshooting
Error 403: org_internal
Error 403: org_internal
Error 400: redirect_uri_mismatch
Error 400: redirect_uri_mismatch
https, the host, and that it ends in /v1/apps/oauth/google/callback. Changes can take a few minutes.SERVICE_DISABLED or API has not been used in project
SERVICE_DISABLED or API has not been used in project
Error 403: access_denied
Error 403: access_denied
Error 400: admin_policy_enforced or Access blocked
Error 400: admin_policy_enforced or Access blocked
Error 401: invalid_client
Error 401: invalid_client
Connections stop working after 7 days
Connections stop working after 7 days
Next steps
- Grant the connection to an agent.
- Add organization-wide rules.
- See what each app can do: Gmail, Google Calendar, Google Drive, and the other Google pages.