Auth with Google¶
Your app signs people in with Google and sends the id token to API Maker. An auth provider of type Google checks it against your OAuth client, finds the person in a table of yours, and runs the call with the groups of that person.
| Page | API Security → Auth Providers → type Google. |
| Header | x-google-authorization: <Google id token> |
| In code | g.req.auth.authGoogle : the opened token, and the columns selected from your table. |
The groups of the person¶
sourceFieldOfUniqueIdis the claim of the token which identifies the person (an email,sub,oid).groupsDataSourcenames the table of yours which holds that person :targetFieldForUniqueIdis the column with the same value,groupsColumnthe comma separated groups of the person,selectthe columns to put ing.req.auth.- Without
groupsDataSource, the token is checked but the person gets no group of its own : only the API user decides.
Require it¶
authProviders: ['google_token_generator']in the settings of the APIs, tables or databases, or incommon.authProvidersof the secret.- The call carries the API user token in
x-am-authorizationand the token of the provider inx-google-authorization. testObjin the provider is the person the API testing page pretends to be.