Official agent skill

Sign In With Google Web

by google in google/skills

Implement, configure, and secure Sign In With Google (SiwG) using Google Identity Services (GIS / https://accounts.google.com/gsi/client) across web architectures.

OfficialApache-2.0Auto-check passedBackend & APIs

Install Sign In With Google Web

skills CLI
$ npx skills add google/skills --skill sign-in-with-google-web -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install google/skills sign-in-with-google-web --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/google/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/identity/sign-in-with-google-web .claude/skills/sign-in-with-google-web && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
sign-in-with-google-web
GitHub stars
21k
Token cost
~4.1k tokens
SKILL.md length
1,212 words
Files
6 (incl. references)
Skills in repo
150
Repo updated
First seen
Licence
Apache-2.0

At a glance

Implement, configure, and secure Sign In With Google (SiwG) using Google Identity Services (GIS / https://accounts.google.com/gsi/client) across web architectures.

  • Works in 6 steps: IETF Architecture Taxonomy & Hierarchy… → Mandatory Security Directives & Browser… → Implementation Contracts & Anti-Pattern… → …
  • Creating Google sign-in buttons
  • SKILL.md covers 1. IETF Architecture Taxonomy…, 2. Mandatory Security…, 3. Implementation Contracts &… and 4. Implementation Recipes…, plus 2 more sections
  • Reaches accounts.google.com and googleapis.com

What it does

Sign In With Google Web is an agent skill from google/skills, published by the product's own GitHub organization. Implement, configure, and secure Sign In With Google (SiwG) using Google Identity Services (GIS / https://accounts.google.com/gsi/client) across web architectures. Use when creating Google sign-in buttons, implementing Google One Tap with FedCM, integrating GIS in React/Next.js/Angular/HTML, verifying ID tokens on backend runtimes (Python/Node.js/Go/Java), enforcing Google Workspace domain restrictions (hd), securing client-side ID tokens via WebCrypto nonces or encrypted IndexedDB, embedding in cross-origin…

Its SKILL.md is about 4.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including reference files (for example `references/bff_fastapi_verification.md`, `references/in_memory_spa_nonce.md` and `references/intermediate_iframe.md`).

It sits in Backend & APIs, covering Authentication, Embeddings and Cloud office suites. It works with Google Cloud, Angular, Next.js and React. The repository describes itself as: Agent Skills for Google products and technologies. The licence is Apache-2.0.

When your agent uses it

  • Creating Google sign-in buttons
  • Implementing Google One Tap with FedCM
  • Integrating GIS in React/Next.js/Angular/HTML
  • Verifying ID tokens on backend runtimes (Python/Node.js/Go/Java)

Example prompts

  • “/sign-in-with-google-web”

Requirements

  • Node.js

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. IETF Architecture Taxonomy & Hierarchy (RECOMMEND BFF / TMB FIRST)
  2. Mandatory Security Directives & Browser Policies
  3. Implementation Contracts & Anti-Pattern Bans
  4. Implementation Recipes (Progressive Disclosure)
  5. Sign-Out & Account Revocation Across All Patterns
  6. References & Normative Standards

What it can do on your machine

Read from SKILL.md and the folder at commit 4b940dd. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are http, html and javascript).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • accounts.google.com
    • googleapis.com

    Also links to:

    • datatracker.ietf.org
    • developers.google.com
    • w3.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Sign In With Google Web loads about 4.1k tokens when it runs, and up to ~8k if it reads all its reference files. Until then it costs about 227 tokens; SKILL.md has 1,212 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~227
When it runs · the whole SKILL.md, loaded when a task matches
~4.1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from google/skills at commit 4b940dd, republished under its Apache-2.0 licence (© google). 1,212 words, ~4,148 tokens.

Download SKILL.mdSave it as .claude/skills/sign-in-with-google-web/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.
name
sign-in-with-google-web
description
Implement, configure, and secure Sign In With Google (SiwG) using Google Identity Services (GIS / `https://accounts.google.com/gsi/client`) across web architectures. Use when creating Google sign-in buttons, implementing Google One Tap with FedCM, integrating GIS in React/Next.js/Angular/HTML, verifying ID tokens on backend runtimes (Python/Node.js/Go/Java), enforcing Google Workspace domain restrictions (`hd`), securing client-side ID tokens via WebCrypto nonces or encrypted IndexedDB, embedding in cross-origin iframes via the Intermediate Iframe API (`https://accounts.google.com/gsi/intermediate`), configuring Content Security Policy (CSP), COOP, and Permissions Policy (`identity-credentials-get`) headers, or handling sign-out and revocation. Don't use for legacy Google Sign-In (`gapi.auth2`), Google Cloud IAM service accounts, or Android/iOS native Credential Manager.
metadata.category
Identity
metadata.version
1.0.0

Sign In With Google (SiwG) Integration & Security Architecture

This skill provides normative architectural guidelines, secure implementation contracts, and failure-prevention protocols for integrating Sign In With Google via the Google Identity Services (GIS) Web SDK (https://accounts.google.com/gsi/client).

1. IETF Architecture Taxonomy & Hierarchy (RECOMMEND BFF / TMB FIRST)

All Sign In With Google implementations MUST align with the IETF OAuth 2.0 for Browser-Based Applications (draft-ietf-oauth-browser-based-apps) taxonomy.

[!IMPORTANT] Primary Recommendation: Always recommend backend-mediated patterns (Pattern A: Backend For Frontend or Pattern B: Token-Mediating Backend / Redirect Mode) as the most secure, robust, and industry-standard architectures whenever an application has a backend server. Fall back to client-only browser patterns (Patterns C & D) only when constrained by serverless static hosting or offline-first PWA requirements.

<!-- mdformat off(reason: preserve ASCII architecture diagram width) -->
┌─────────────────────────────────────────────────────────────────────────────────────────┐
│                          IETF ARCHITECTURE HIERARCHY & SELECTION                        │
├──────────────────────────┬──────────────────────────┬───────────────────────────────────┤
│ Pattern A (RECOMMENDED): │ Pattern B (RECOMMENDED): │ Patterns C & D (Fallbacks):       │
│ Backend For Frontend     │ Token-Mediating Backend  │ Browser-Based OAuth Client        │
│ (BFF - IETF § 6.1)       │ (TMB / Redirect § 6.2)   │ (JavaScript-Only - IETF § 6.3)    │
├──────────────────────────┼──────────────────────────┼───────────────────────────────────┤
│ 🏆 GOLD STANDARD         │ 🚀 NATIVE FORM REDIRECT  │ ⚡ STATIC SPA / 💾 OFFLINE PWA    │
│ • Full-stack SPA + API   │ • Server-rendered & apps │ • Pure client-side or offline PWAs│
│ • Client JS fetch to API │ • GIS HTTP POST login_uri│ • C: Ephemeral in-memory closure  │
│ • HttpOnly session cookie│ • Direct server redirect │ • D: WebCrypto Encrypted IndexedDB│
│ • Tokens never in browser│ • Tokens never in JS     │ • Strict WebCrypto nonces / keys  │
└──────────────────────────┴──────────────────────────┴───────────────────────────────────┘
<!-- mdformat on -->
🏆 Pattern A: Backend For Frontend (BFF - IETF § 6.1) — STRONGLY RECOMMENDED
  • Why it is the Gold Standard: ID tokens (JWTs) and access tokens are never exposed to browser JavaScript across page reloads. This provides complete architectural immunity against XSS token harvesting.

  • Architecture: The browser frontend loads the GIS SDK, captures the credential in JavaScript callback (callback: handleCredentialResponse), and immediately forwards the ID token (JWT) via fetch('/api/auth/google', { method: 'POST' }) to the backend.

  • Backend Responsibilities: The backend validates the JWT cryptographic signature against Google's public JWKs (google.oauth2.id_token.verify_oauth2_token), checks the aud, hd, and nonce claims against server session state, creates a server session, and issues a first-party HttpOnly; Secure; SameSite=Lax session cookie.

  • See full implementation in references/bff_fastapi_verification.md.

🚀 Pattern B: Token-Mediating Backend via login_uri Redirect (IETF § 6.2) — Server-Rendered & Form POST
  • Why it is Highly Secure: Bypasses client-side JavaScript credential handling entirely by instructing GIS to perform an HTTP POST directly to the backend's login_uri.

  • Architecture: Configured via google.accounts.id.initialize({ client_id, login_uri: "https://example.com/api/auth/callback", ux_mode: "redirect" }) or HTML attributes (data-login_uri="https://example.com/api/auth/callback" and data-ux_mode="redirect").

  • Backend Responsibilities: The backend receives the ID token as a form POST body (credential parameter), validates the double-submit g_csrf_token cookie against the g_csrf_token POST body field, cryptographically verifies the ID token server-side, establishes a session cookie, and returns a standard HTTP 302/303 redirect.

  • See full implementation in references/tmb_login_uri_redirect.md.

Pattern C: Browser-Based OAuth Client — Ephemeral In-Memory (IETF § 6.3) — Fallback for Static SPAs
  • Scope: Use ONLY when deployment is strictly serverless/static (e.g., GitHub Pages, Firebase static hosting) with no backend component.

  • Storage Invariant: The ID token is held strictly in private JavaScript memory/closures during the active tab session. Never store raw tokens in localStorage or sessionStorage.

  • Session Renewal: Uses GIS One Tap / FedCM auto-select (auto_select: true) to transparently re-acquire fresh ID tokens into memory on page reload without persistent browser storage.

  • XSS & Replay Protection: Generate a cryptographic nonce via window.crypto.getRandomValues() and pass it directly to google.accounts.id.initialize({ client_id, nonce: clientNonce }). Validate that payload.nonce === clientNonce before trusting claims in memory.

  • See full implementation in references/in_memory_spa_nonce.md.

Pattern D: Browser-Based OAuth Client — WebCrypto Encrypted IndexedDB (IETF § 6.3) — Fallback for Offline PWAs
  • Scope: Use ONLY for offline-first Progressive Web Apps (PWAs) where user authentication proof must survive tab refreshes when disconnected from the network.

  • Storage Invariant: NEVER store raw plaintext ID tokens in localStorage. Encrypt the ID token payload using WebCrypto AES-GCM with a non-extractable session key (extractable: false) before writing ciphertext and IV to IndexedDB.

  • See full implementation in references/offline_pwa_encryption.md.


2. Mandatory Security Directives & Browser Policies

To avoid multi-turn repair loops and browser security exceptions, provide all required CSP, COOP, and user activation directives in the initial deliverable:

A. Content Security Policy (CSP) Directives
http
Content-Security-Policy:
  script-src 'self' https://accounts.google.com/gsi/client;
  frame-src https://accounts.google.com/gsi/;
  connect-src https://accounts.google.com/gsi/;

If using strict nonce-based CSP, attach the nonce to the GIS script tag: <script src="https://accounts.google.com/gsi/client" async defer nonce="{{NONCE}}"></script>.

B. Cross-Origin Opener Policy (COOP)

To allow GIS popup dialogs to communicate credentials back to the parent window via postMessage:

http
Cross-Origin-Opener-Policy: same-origin-allow-popups

(Serving same-origin without allow-popups breaks GIS popups and results in silent failures).

C. Automatic Selection, FedCM, & Sign-Out Lifecycle (disableAutoSelect)

When enabling automatic zero-click return sign-in with Google One Tap (FedCM is enabled by default in GIS):

  • Set auto_select: true in google.accounts.id.initialize({...}) (do not pass the deprecated use_fedcm_for_prompt parameter).

  • Deprecated Library Warning: NEVER mix deprecated gapi.auth2 (gapi.auth2.init, gapi.auth2.getAuthInstance().signOut()) with Google Identity Services (GIS). gapi.auth2 is completely retired; use GIS methods exclusively.

  • Sign-Out Protocol: When the user explicitly logs out of your application, you MUST call google.accounts.id.disableAutoSelect():

    javascript
    function handleUserLogout() {
      // 1. Disable automatic One Tap / FedCM re-authentication
      google.accounts.id.disableAutoSelect();
    
      // 2. Clear application session state / server cookie
      fetch('/api/auth/logout', { method: 'POST' }).then(() => {
        window.location.href = '/login';
      });
    }
  • (Failing to call disableAutoSelect() causes an immediate automatic re-login loop on the next page visit after intentional user logout).

Show full SKILL.md (498 more words)Show less
D. Reliable Dynamic Script Loading & Framework Lifecycle (React, Next.js, SPAs)

When mounting Sign In With Google in Single Page Applications (React, Next.js, Vue, Angular):

  • Modern SPAs execute component lifecycles asynchronously. Attempting to access window.google.accounts.id before <script src="https://accounts.google.com/gsi/client"> has finished loading causes ReferenceError: google is not defined.

  • NEVER use gapi or polling (setInterval): Use deterministic dynamic script loading with onload / addEventListener('load') event listeners.

  • Dynamic Script Loader Pattern:

    tsx
    import React, { useEffect, useState } from 'react';
    
    export function useGoogleIdentityScript() {
      const [isLoaded, setIsLoaded] = useState(false);
    
      useEffect(() => {
        if (window.google?.accounts?.id) {
          setIsLoaded(true);
          return;
        }
    
        const existingScript = document.querySelector(
          'script[src="https://accounts.google.com/gsi/client"]'
        );
        if (existingScript) {
          existingScript.addEventListener('load', () => setIsLoaded(true));
          return;
        }
    
        const script = document.createElement('script');
        script.src = 'https://accounts.google.com/gsi/client';
        script.async = true;
        script.defer = true;
        script.onload = () => setIsLoaded(true);
        document.head.appendChild(script);
      }, []);
    
      return isLoaded;
    }
  • (Always use deterministic onload event listeners or framework <Script strategy="afterInteractive"> rather than brittle setInterval polling).

E. Embedded Iframes & Permissions Policy (identity-credentials-get)

When embedding Sign In With Google or One Tap inside cross-origin <iframe> elements or widget integrations, modern browser security models and FedCM require explicit Permissions Policy delegation on the container frame:

html
<iframe
  src="https://example.com/embed"
  allow="identity-credentials-get 'src' https://accounts.google.com">
</iframe>

(Omitting allow="identity-credentials-get" blocks FedCM / One Tap initialization inside embedded or cross-origin contexts). See full integration guide in references/intermediate_iframe.md.


3. Implementation Contracts & Anti-Pattern Bans

A. Strict Ban on Legacy GAPI (gapi.auth2)
  • NEVER import or reference gapi.auth2, gapi.auth2.init, gapi.auth2.getAuthInstance(), or gapi.signin2. Always warn that gapi.auth2 is deprecated and decommissioned.

  • GIS (google.accounts.id.* and google.accounts.oauth2.*) is completely stateless. It replaces all legacy GAPI authentication libraries.


4. Implementation Recipes (Progressive Disclosure)

Load the specific reference file matching your target architecture when generating implementation code:

  • Recipe 1 — Pattern A (Backend For Frontend with Python / FastAPI) [RECOMMENDED]: Load references/bff_fastapi_verification.md for custom UI button prompting, google.oauth2.id_token.verify_oauth2_token cryptographic verification, nonce replay checks, Google Workspace hd domain enforcement, and HttpOnly; Secure; SameSite=Lax session cookie issuance.

  • Recipe 2 — Pattern B (Token-Mediating Backend with login_uri Form POST Redirect) [RECOMMENDED]: Load references/tmb_login_uri_redirect.md for data-login_uri / ux_mode: 'redirect' frontend setup and FastAPI double-submit g_csrf_token cookie vs. form-body validation.

  • Recipe 3 — Pattern C (Browser-Based Ephemeral In-Memory SPA with Native GIS Nonce) [Fallback]: Load references/in_memory_spa_nonce.md for WebCrypto nonce generation (google.accounts.id.initialize({ client_id, nonce: clientNonce })), UTF-8 safe Base64URL JWT decoding, and private closure token management.

  • Recipe 4 — Pattern D (Browser-Based WebCrypto Encrypted IndexedDB for Offline PWAs) [Fallback]: Load references/offline_pwa_encryption.md for non-extractable (extractable: false) AES-GCM CryptoKey generation and encrypted IndexedDB storage.

  • Recipe 5 — Embedded Cross-Origin Contexts (gsi/intermediate): Load references/intermediate_iframe.md for <div id="g_id_intermediate_iframe">, allow="identity-credentials-get", and strict window.postMessage origin verification.


5. Sign-Out & Account Revocation Across All Patterns

javascript
export function handleSignOut(userEmail) {
  // 1. Disable client-side One Tap auto-selection
  google.accounts.id.disableAutoSelect();

  // 2. Revoke OAuth grant if user disconnected account
  if (userEmail) {
    google.accounts.id.revoke(userEmail, () => {
      console.log('User grant revoked');
    });
  }

  // 3. Clear storage / session
  AuthManager.clear(); // Pattern C
  fetch('/api/auth/logout', { method: 'POST' }); // Pattern A
}

6. References & Normative Standards

© google, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 5 other files (references) in skills/identity/sign-in-with-google-web of google/skills.

  • SKILL.md
  • references/bff_fastapi_verification.md
  • references/in_memory_spa_nonce.md
  • references/intermediate_iframe.md
  • references/offline_pwa_encryption.md
  • references/tmb_login_uri_redirect.md

Open the folder on GitHubat commit 4b940dd

Compare with similar skills

Sign In With Google Web next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Sign In With Google Web compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Sign In With Google Web this skillgoogle/skills21k—~4.1kAutomated safety check: PassApache-2.0
Workos Widgetsusenotra/notra256—~2kAutomated safety check: PassAGPL-3.0
Fullstack DevHHU3637kr/skills1453 repos~8.6kAutomated safety check: NotesMIT
Google Workspaceericrisco/rsc-harness180—~3.2kAutomated safety check: PassMIT
Fullstack Devinfometa/workbuddyskills348—~1kAutomated safety check: PassMIT
Playwright Coretestdino-hq/playwright-skill3901 repos~1.4kAutomated safety check: PassMIT

Similar skills

  • Workos Widgets

    usenotra/notra

    A skill your agent uses when the user is implementing, embedding, or debugging a WorkOS Widget — specifically the User Management, User Profile, Admin Portal SSO Connection, or Admin Portal Domain…

    256 GitHub stars~2k tokensUpdated today
    AI & LLM EngineeringAuto-check passed
  • Fullstack Dev

    HHU3637kr/skills

    Full-stack backend architecture and frontend-backend integration guide.

    145 GitHub starsUsed in 3 repos~8.6k tokens
    Backend & APIsAuto-check: notes
  • Google Workspace

    ericrisco/rsc-harness

    A skill your agent uses when server-side code reads or writes Gmail, Drive, Calendar, or Sheets with a GCP service account and no human in the OAuth loop: picking the auth mode (app-owned vs…

    180 GitHub stars~3.2k tokensUpdated today
    Backend & APIsAuto-check passed
  • Fullstack Dev

    infometa/workbuddyskills

    Full-stack backend architecture and frontend-backend integration guide.

    348 GitHub stars~1k tokensUpdated today
    Backend & APIsAuto-check passed
  • Playwright Core

    testdino-hq/playwright-skill

    Battle-tested Playwright patterns for writing and debugging reliable E2E, API, component, visual, accessibility, and security tests.

    390 GitHub starsUsed in 1 repo~1.4k tokens
    Testing & QAAuto-check passed
  • Official

    Technology-agnostic prompt generator that creates customizable AI prompts for scanning codebases and identifying high-quality code exemplars.

    40k GitHub starsUsed in 2 repos~1.7k tokens
    DevelopmentAuto-check passed

More from google/skills

All 150 skills in this repo
  • Official

    Query Cloud Trace spans, filter by latency thresholds or error status, correlate distributed traces with Cloud Logging, and diagnose latency bottlenecks across Google Cloud services.

    21k GitHub stars~1.7k tokensUpdated today
    Auto-check passed
  • Official

    Manages Google Cloud Privileged Access Manager entitlements and grants: create and edit entitlements, request temporary access, and approve or deny pending grants.

    21k GitHub stars~3.2k tokensUpdated today
    Auto-check passed
  • Official

    Writes Terraform alerting policies for AI agents that emit OpenTelemetry metrics, covering reliability, cost, safety, security and quality signals on Google Cloud.

    21k GitHub stars~4.2k tokensUpdated today
    Auto-check passed
  • Official

    Deploys open models or custom weights from Model Garden to Agent Platform endpoints, checks deployment status and cleans up endpoints, confirming before any change.

    21k GitHub stars~5k tokensUpdated today
    Auto-check passed
  • Official

    Searches, manages and scaffolds skills in the Gemini Enterprise Agent Platform Skill Registry using bundled Python scripts and Google Cloud credentials.

    21k GitHub stars~584 tokensUpdated today
    Auto-check passed
  • Designs GCP infrastructure as local Terraform, validates and scans it against best practices, then imports it to Application Design Center for deployment and troubleshooting.

    21k GitHub stars~4.4k tokensUpdated today
    Auto-check passed

Questions about Sign In With Google Web

What does Sign In With Google Web do?

Implement, configure, and secure Sign In With Google (SiwG) using Google Identity Services (GIS / https://accounts.google.com/gsi/client) across web architectures. Sign In With Google Web is an agent skill from google/skills, published by the product's own GitHub organization.com/gsi/client) across web architectures.

When should I use Sign In With Google Web?

Sign In With Google Web fits situations like: creating Google sign-in buttons; implementing Google One Tap with FedCM; integrating GIS in React/Next.js/Angular/HTML; verifying ID tokens on backend runtimes (Python/Node.js/Go/Java).

How do I install Sign In With Google Web in Claude Code?

Run `npx skills add google/skills --skill sign-in-with-google-web -a claude-code`. Or copy the skill folder (skills/identity/sign-in-with-google-web in google/skills) into .claude/skills/sign-in-with-google-web in your project. Claude Code loads it when a task matches its description.

How do I install Sign In With Google Web in Codex?

Run `npx skills add google/skills --skill sign-in-with-google-web -a codex`. Or copy the skill folder (skills/identity/sign-in-with-google-web in google/skills) into .agents/skills/sign-in-with-google-web in your project. Codex loads it when a task matches its description.

Can I use Sign In With Google Web in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add google/skills --skill sign-in-with-google-web -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/sign-in-with-google-web, .gemini/skills/sign-in-with-google-web, .github/skills/sign-in-with-google-web and .opencode/skills/sign-in-with-google-web in your project.

What does Sign In With Google Web need to run?

SKILL.md names no scripts, command-line tools or credentials: Sign In With Google Web is instructions for the agent only. Our summary lists: Node.js.

Does Sign In With Google Web access the network?

SKILL.md names 5 domains. In commands or code: accounts.google.com and googleapis.com; the agent is likely to contact these when it follows the instructions. As links in the text: datatracker.ietf.org, developers.google.com and w3.org. This is read from the text; nothing was executed.

Is Sign In With Google Web safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Sign In With Google Web use?

Sign In With Google Web is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Sign In With Google Web use?

About 4.1k tokens (SKILL.md is roughly 17k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.8k tokens, read only when the agent opens those files.

What are the alternatives to Sign In With Google Web?

Skills that share tags, products or a category with Sign In With Google Web: Workos Widgets (usenotra/notra, 256 stars), Fullstack Dev (HHU3637kr/skills, 145 stars), Google Workspace (ericrisco/rsc-harness, 180 stars) and Fullstack Dev (infometa/workbuddyskills, 348 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Sign In With Google Web?

google (a GitHub organization, an official publisher) maintains it in google/skills, which has 21,097 GitHub stars. The repository holds 150 skills in this directory. The repository was last updated on October 9, 2026.

Source: google/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.