Skip to main content
Google Workspace sign-in runs through a Google Cloud project. You create an OAuth client there — think of it as issuing Variable a badge that lets it ask Google “who is this person?” — and the project’s consent screen decides which Google accounts may use it. You need a Google Workspace super admin, or an admin who can create projects in your organization’s Google Cloud. Read the single sign-on overview first if you have not verified your domain in Variable.

Create or choose a project

  1. Open the Google Cloud console signed in with a Workspace admin account.
  2. Use the project picker to select an existing project, or choose New project and name it Variable SSO. Make sure the project belongs to your Workspace organization, not to a personal account.
The consent screen is what people see when Google asks them to allow Variable to read their name and email.
  1. Go to Google Auth Platform → Branding (older consoles: APIs & Services → OAuth consent screen) and complete the app name, support email and developer contact.
  2. Under Audience, set the user type to Internal. This restricts sign-in to accounts in your Workspace organization. It is the control that keeps outside Google accounts out, so do not choose External unless you have discussed it with us.
  3. Under Data Access, add the scopes openid, .../auth/userinfo.email and .../auth/userinfo.profile. These are the non-sensitive defaults and need no Google verification review.
With the audience set to External, any Google account can attempt to sign in and Google may show an “unverified app” warning. Internal apps skip both.

Create the OAuth client

  1. Go to Google Auth Platform → Clients (older consoles: APIs & Services → Credentials → Create credentials → OAuth client ID) and select Create client.
  2. Set Application type to Web application and name it Variable.
  3. Under Authorized redirect URIs, add:
    It must match exactly, including https and no trailing slash. Leave Authorized JavaScript origins empty.
  4. Select Create, then copy the Client ID and Client secret. Keep the secret out of shared documents and chat.

Send us the credentials

Send us the following through an agreed-upon secure channel:
  • Provider: Google
  • Client ID
  • Client secret
  • The email domains to cover, each verified in Variable, including your primary Workspace domain
  • A contact who can test the sign-in
Google reports your organization’s primary domain for every account, including people whose address is on a secondary domain. Variable only accepts an account whose primary domain is linked to the connection, so include it even if nobody signs in with it. We confirm once it is switched on. Google client secrets do not expire on their own, but rotate yours on your usual schedule and send us the new one before you disable the old.

Test it

  1. Open a private browser window and go to https://app.variable.global.
  2. Enter your work email and continue. You are sent to Google.
  3. Choose your Workspace account. You land back in Variable.
Variable passes your domain to Google as a hint, so the account picker leans toward your Workspace accounts. The hint is a convenience, not a lock. The boundary is enforced twice: the Internal audience keeps outside accounts at Google, and Variable rejects an account whose email Google has not verified or whose Workspace domain is not linked to your connection.

Troubleshooting

Restrict who can sign in (optional)

To limit Variable to specific people, open the Admin console at admin.google.com, go to Security → Access and data control → API controls → Manage third-party app access, add the OAuth client by its client ID, and set access to Limited or Specific Google Workspace groups.