Workos Widgets
usenotra/notra
A skill your agent uses when the user is implementing, embedding, or debugging a WorkOS Widget — specifically the User Management, User Profile, Admin Portal SSO Connection, or Admin Portal Domain…
Implement, configure, and secure Sign In With Google (SiwG) using Google Identity Services (GIS / https://accounts.google.com/gsi/client) across web architectures.
$ npx skills add google/skills --skill sign-in-with-google-web -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install google/skills sign-in-with-google-web --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/google/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/identity/sign-in-with-google-web .claude/skills/sign-in-with-google-web && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "sign-in-with-google-web" agent skill from https://github.com/google/skills/tree/main/skills/identity/sign-in-with-google-web into .claude/skills/sign-in-with-google-web/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sign-in-with-google-web", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/google/skills/tree/main/skills/identity/sign-in-with-google-webType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add google/skills --skill sign-in-with-google-web -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install google/skills sign-in-with-google-web --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/google/skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/identity/sign-in-with-google-web .agents/skills/sign-in-with-google-web && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "sign-in-with-google-web" agent skill from https://github.com/google/skills/tree/main/skills/identity/sign-in-with-google-web into .agents/skills/sign-in-with-google-web/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sign-in-with-google-web", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add google/skills --skill sign-in-with-google-web -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install google/skills sign-in-with-google-web --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/google/skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/identity/sign-in-with-google-web .cursor/skills/sign-in-with-google-web && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "sign-in-with-google-web" agent skill from https://github.com/google/skills/tree/main/skills/identity/sign-in-with-google-web into .cursor/skills/sign-in-with-google-web/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sign-in-with-google-web", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/google/skills.git --path skills/identity/sign-in-with-google-web--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add google/skills --skill sign-in-with-google-web -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install google/skills sign-in-with-google-web --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/google/skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/identity/sign-in-with-google-web .gemini/skills/sign-in-with-google-web && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "sign-in-with-google-web" agent skill from https://github.com/google/skills/tree/main/skills/identity/sign-in-with-google-web into .gemini/skills/sign-in-with-google-web/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sign-in-with-google-web", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install google/skills sign-in-with-google-webInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add google/skills --skill sign-in-with-google-web -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/google/skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/identity/sign-in-with-google-web .github/skills/sign-in-with-google-web && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "sign-in-with-google-web" agent skill from https://github.com/google/skills/tree/main/skills/identity/sign-in-with-google-web into .github/skills/sign-in-with-google-web/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sign-in-with-google-web", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add google/skills --skill sign-in-with-google-web -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install google/skills sign-in-with-google-web --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/google/skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/identity/sign-in-with-google-web .opencode/skills/sign-in-with-google-web && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "sign-in-with-google-web" agent skill from https://github.com/google/skills/tree/main/skills/identity/sign-in-with-google-web into .opencode/skills/sign-in-with-google-web/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sign-in-with-google-web", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
sign-in-with-google-webImplement, configure, and secure Sign In With Google (SiwG) using Google Identity Services (GIS / https://accounts.google.com/gsi/client) across web architectures.
Sign In With Google Web is an agent skill from google/skills, published by the product's own GitHub organization. Implement, configure, and secure Sign In With Google (SiwG) using Google Identity Services (GIS / https://accounts.google.com/gsi/client) across web architectures. Use when creating Google sign-in buttons, implementing Google One Tap with FedCM, integrating GIS in React/Next.js/Angular/HTML, verifying ID tokens on backend runtimes (Python/Node.js/Go/Java), enforcing Google Workspace domain restrictions (hd), securing client-side ID tokens via WebCrypto nonces or encrypted IndexedDB, embedding in cross-origin…
Its SKILL.md is about 4.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including reference files (for example `references/bff_fastapi_verification.md`, `references/in_memory_spa_nonce.md` and `references/intermediate_iframe.md`).
It sits in Backend & APIs, covering Authentication, Embeddings and Cloud office suites. It works with Google Cloud, Angular, Next.js and React. The repository describes itself as: Agent Skills for Google products and technologies. The licence is Apache-2.0.
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 4b940dd. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are http, html and javascript).
From the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
accounts.google.comgoogleapis.comAlso links to:
datatracker.ietf.orgdevelopers.google.comw3.orgFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Sign In With Google Web loads about 4.1k tokens when it runs, and up to ~8k if it reads all its reference files. Until then it costs about 227 tokens; SKILL.md has 1,212 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from google/skills at commit 4b940dd, republished under its Apache-2.0 licence (© google). 1,212 words, ~4,148 tokens.
.claude/skills/sign-in-with-google-web/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.This skill provides normative architectural guidelines, secure implementation
contracts, and failure-prevention protocols for integrating Sign In With Google
via the Google Identity Services (GIS) Web SDK
(https://accounts.google.com/gsi/client).
All Sign In With Google implementations MUST align with the
IETF OAuth 2.0 for Browser-Based Applications (draft-ietf-oauth-browser-based-apps)
taxonomy.
[!IMPORTANT] Primary Recommendation: Always recommend backend-mediated patterns (Pattern A: Backend For Frontend or Pattern B: Token-Mediating Backend / Redirect Mode) as the most secure, robust, and industry-standard architectures whenever an application has a backend server. Fall back to client-only browser patterns (Patterns C & D) only when constrained by serverless static hosting or offline-first PWA requirements.
<!-- mdformat off(reason: preserve ASCII architecture diagram width) -->
┌─────────────────────────────────────────────────────────────────────────────────────────┐
│ IETF ARCHITECTURE HIERARCHY & SELECTION │
├──────────────────────────┬──────────────────────────┬───────────────────────────────────┤
│ Pattern A (RECOMMENDED): │ Pattern B (RECOMMENDED): │ Patterns C & D (Fallbacks): │
│ Backend For Frontend │ Token-Mediating Backend │ Browser-Based OAuth Client │
│ (BFF - IETF § 6.1) │ (TMB / Redirect § 6.2) │ (JavaScript-Only - IETF § 6.3) │
├──────────────────────────┼──────────────────────────┼───────────────────────────────────┤
│ 🏆 GOLD STANDARD │ 🚀 NATIVE FORM REDIRECT │ ⚡ STATIC SPA / 💾 OFFLINE PWA │
│ • Full-stack SPA + API │ • Server-rendered & apps │ • Pure client-side or offline PWAs│
│ • Client JS fetch to API │ • GIS HTTP POST login_uri│ • C: Ephemeral in-memory closure │
│ • HttpOnly session cookie│ • Direct server redirect │ • D: WebCrypto Encrypted IndexedDB│
│ • Tokens never in browser│ • Tokens never in JS │ • Strict WebCrypto nonces / keys │
└──────────────────────────┴──────────────────────────┴───────────────────────────────────┘<!-- mdformat on -->
Why it is the Gold Standard: ID tokens (JWTs) and access tokens are never exposed to browser JavaScript across page reloads. This provides complete architectural immunity against XSS token harvesting.
Architecture: The browser frontend loads the GIS SDK, captures the
credential in JavaScript callback (callback: handleCredentialResponse),
and immediately forwards the ID token (JWT) via fetch('/api/auth/google', { method: 'POST' }) to the backend.
Backend Responsibilities: The backend validates the JWT cryptographic
signature against Google's public JWKs
(google.oauth2.id_token.verify_oauth2_token), checks the aud, hd, and
nonce claims against server session state, creates a server session, and
issues a first-party HttpOnly; Secure; SameSite=Lax session cookie.
See full implementation in references/bff_fastapi_verification.md.
login_uri Redirect (IETF § 6.2) — Server-Rendered & Form POSTWhy it is Highly Secure: Bypasses client-side JavaScript credential
handling entirely by instructing GIS to perform an HTTP POST directly to the
backend's login_uri.
Architecture: Configured via google.accounts.id.initialize({ client_id, login_uri: "https://example.com/api/auth/callback", ux_mode: "redirect" })
or HTML attributes (data-login_uri="https://example.com/api/auth/callback"
and data-ux_mode="redirect").
Backend Responsibilities: The backend receives the ID token as a form
POST body (credential parameter), validates the double-submit
g_csrf_token cookie against the g_csrf_token POST body field,
cryptographically verifies the ID token server-side, establishes a session
cookie, and returns a standard HTTP 302/303 redirect.
See full implementation in references/tmb_login_uri_redirect.md.
Scope: Use ONLY when deployment is strictly serverless/static (e.g., GitHub Pages, Firebase static hosting) with no backend component.
Storage Invariant: The ID token is held strictly in private JavaScript
memory/closures during the active tab session. Never store raw tokens in
localStorage or sessionStorage.
Session Renewal: Uses GIS One Tap / FedCM auto-select (auto_select: true) to transparently re-acquire fresh ID tokens into memory on page
reload without persistent browser storage.
XSS & Replay Protection: Generate a cryptographic nonce via
window.crypto.getRandomValues() and pass it directly to
google.accounts.id.initialize({ client_id, nonce: clientNonce }). Validate
that payload.nonce === clientNonce before trusting claims in memory.
See full implementation in references/in_memory_spa_nonce.md.
Scope: Use ONLY for offline-first Progressive Web Apps (PWAs) where user authentication proof must survive tab refreshes when disconnected from the network.
Storage Invariant: NEVER store raw plaintext ID tokens in
localStorage. Encrypt the ID token payload using WebCrypto AES-GCM
with a non-extractable session key (extractable: false) before writing
ciphertext and IV to IndexedDB.
See full implementation in references/offline_pwa_encryption.md.
To avoid multi-turn repair loops and browser security exceptions, provide all required CSP, COOP, and user activation directives in the initial deliverable:
Content-Security-Policy:
script-src 'self' https://accounts.google.com/gsi/client;
frame-src https://accounts.google.com/gsi/;
connect-src https://accounts.google.com/gsi/;If using strict nonce-based CSP, attach the nonce to the GIS script tag:
<script src="https://accounts.google.com/gsi/client" async defer nonce="{{NONCE}}"></script>.
To allow GIS popup dialogs to communicate credentials back to the parent window
via postMessage:
Cross-Origin-Opener-Policy: same-origin-allow-popups(Serving same-origin without allow-popups breaks GIS popups and results in
silent failures).
disableAutoSelect)When enabling automatic zero-click return sign-in with Google One Tap (FedCM is enabled by default in GIS):
Set auto_select: true in google.accounts.id.initialize({...}) (do not
pass the deprecated use_fedcm_for_prompt parameter).
Deprecated Library Warning: NEVER mix deprecated gapi.auth2
(gapi.auth2.init, gapi.auth2.getAuthInstance().signOut()) with Google
Identity Services (GIS). gapi.auth2 is completely retired; use GIS methods
exclusively.
Sign-Out Protocol: When the user explicitly logs out of your
application, you MUST call google.accounts.id.disableAutoSelect():
function handleUserLogout() {
// 1. Disable automatic One Tap / FedCM re-authentication
google.accounts.id.disableAutoSelect();
// 2. Clear application session state / server cookie
fetch('/api/auth/logout', { method: 'POST' }).then(() => {
window.location.href = '/login';
});
}(Failing to call disableAutoSelect() causes an immediate automatic
re-login loop on the next page visit after intentional user logout).
When mounting Sign In With Google in Single Page Applications (React, Next.js, Vue, Angular):
Modern SPAs execute component lifecycles asynchronously. Attempting to
access window.google.accounts.id before <script src="https://accounts.google.com/gsi/client"> has finished loading causes
ReferenceError: google is not defined.
NEVER use gapi or polling (setInterval): Use deterministic dynamic
script loading with onload / addEventListener('load') event listeners.
Dynamic Script Loader Pattern:
import React, { useEffect, useState } from 'react';
export function useGoogleIdentityScript() {
const [isLoaded, setIsLoaded] = useState(false);
useEffect(() => {
if (window.google?.accounts?.id) {
setIsLoaded(true);
return;
}
const existingScript = document.querySelector(
'script[src="https://accounts.google.com/gsi/client"]'
);
if (existingScript) {
existingScript.addEventListener('load', () => setIsLoaded(true));
return;
}
const script = document.createElement('script');
script.src = 'https://accounts.google.com/gsi/client';
script.async = true;
script.defer = true;
script.onload = () => setIsLoaded(true);
document.head.appendChild(script);
}, []);
return isLoaded;
}(Always use deterministic onload event listeners or framework <Script strategy="afterInteractive"> rather than brittle setInterval polling).
identity-credentials-get)When embedding Sign In With Google or One Tap inside cross-origin <iframe>
elements or widget integrations, modern browser security models and FedCM
require explicit Permissions Policy delegation on the container frame:
<iframe
src="https://example.com/embed"
allow="identity-credentials-get 'src' https://accounts.google.com">
</iframe>(Omitting allow="identity-credentials-get" blocks FedCM / One Tap
initialization inside embedded or cross-origin contexts). See full integration
guide in references/intermediate_iframe.md.
gapi.auth2)NEVER import or reference gapi.auth2, gapi.auth2.init,
gapi.auth2.getAuthInstance(), or gapi.signin2. Always warn that
gapi.auth2 is deprecated and decommissioned.
GIS (google.accounts.id.* and google.accounts.oauth2.*) is completely
stateless. It replaces all legacy GAPI authentication libraries.
Load the specific reference file matching your target architecture when generating implementation code:
Recipe 1 — Pattern A (Backend For Frontend with Python / FastAPI)
[RECOMMENDED]: Load
references/bff_fastapi_verification.md
for custom UI button prompting, google.oauth2.id_token.verify_oauth2_token
cryptographic verification, nonce replay checks, Google Workspace hd
domain enforcement, and HttpOnly; Secure; SameSite=Lax session cookie
issuance.
Recipe 2 — Pattern B (Token-Mediating Backend with login_uri Form POST
Redirect) [RECOMMENDED]: Load
references/tmb_login_uri_redirect.md
for data-login_uri / ux_mode: 'redirect' frontend setup and FastAPI
double-submit g_csrf_token cookie vs. form-body validation.
Recipe 3 — Pattern C (Browser-Based Ephemeral In-Memory SPA with Native
GIS Nonce) [Fallback]: Load
references/in_memory_spa_nonce.md for
WebCrypto nonce generation (google.accounts.id.initialize({ client_id, nonce: clientNonce })), UTF-8 safe Base64URL JWT decoding, and private
closure token management.
Recipe 4 — Pattern D (Browser-Based WebCrypto Encrypted IndexedDB for
Offline PWAs) [Fallback]: Load
references/offline_pwa_encryption.md
for non-extractable (extractable: false) AES-GCM CryptoKey generation
and encrypted IndexedDB storage.
Recipe 5 — Embedded Cross-Origin Contexts (gsi/intermediate): Load
references/intermediate_iframe.md for
<div id="g_id_intermediate_iframe">, allow="identity-credentials-get",
and strict window.postMessage origin verification.
export function handleSignOut(userEmail) {
// 1. Disable client-side One Tap auto-selection
google.accounts.id.disableAutoSelect();
// 2. Revoke OAuth grant if user disconnected account
if (userEmail) {
google.accounts.id.revoke(userEmail, () => {
console.log('User grant revoked');
});
}
// 3. Clear storage / session
AuthManager.clear(); // Pattern C
fetch('/api/auth/logout', { method: 'POST' }); // Pattern A
}RFC 7519: JSON Web Token (JWT)
— Standard claims (iss, sub, aud, exp, iat, nonce), formatting,
and processing rules.
RFC 7515: JSON Web Signature (JWS)
— Cryptographic signature verification against Google's public JWK certs
(https://www.googleapis.com/oauth2/v3/certs).
RFC 4648 § 5: Base64url Encoding — URL-safe Base64 encoding without padding used across JWT segments.
IETF OAuth 2.0 Browser-Based Applications — Normative architecture standards (§ 6.1 BFF, § 6.2 TMB, § 6.3 Client-side).
Google Identity Services Web Reference — Official GIS API reference.
Intermediate Iframe API Reference — Cross-origin iframe embedding guide.
Verify ID Tokens Server-Side — Server-side token verification protocols.
W3C Federated Credential Management API (FedCM) — Browser identity credential mediation standard.
W3C Web Cryptography API —
Non-extractable key generation (extractable: false) and AES-GCM standards.
© google, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 5 other files (references) in skills/identity/sign-in-with-google-web of google/skills.
Open the folder on GitHubat commit 4b940dd
Sign In With Google Web next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Sign In With Google Web this skillgoogle/skills | 21k | — | ~4.1k | Automated safety check: Pass | Apache-2.0 | |
| Workos Widgetsusenotra/notra | 256 | — | ~2k | Automated safety check: Pass | AGPL-3.0 | |
| Fullstack DevHHU3637kr/skills | 145 | 3 repos | ~8.6k | Automated safety check: Notes | MIT | |
| Google Workspaceericrisco/rsc-harness | 180 | — | ~3.2k | Automated safety check: Pass | MIT | |
| Fullstack Devinfometa/workbuddyskills | 348 | — | ~1k | Automated safety check: Pass | MIT | |
| Playwright Coretestdino-hq/playwright-skill | 390 | 1 repos | ~1.4k | Automated safety check: Pass | MIT |
usenotra/notra
A skill your agent uses when the user is implementing, embedding, or debugging a WorkOS Widget — specifically the User Management, User Profile, Admin Portal SSO Connection, or Admin Portal Domain…
HHU3637kr/skills
Full-stack backend architecture and frontend-backend integration guide.
ericrisco/rsc-harness
A skill your agent uses when server-side code reads or writes Gmail, Drive, Calendar, or Sheets with a GCP service account and no human in the OAuth loop: picking the auth mode (app-owned vs…
infometa/workbuddyskills
Full-stack backend architecture and frontend-backend integration guide.
testdino-hq/playwright-skill
Battle-tested Playwright patterns for writing and debugging reliable E2E, API, component, visual, accessibility, and security tests.
github/awesome-copilot
Technology-agnostic prompt generator that creates customizable AI prompts for scanning codebases and identifying high-quality code exemplars.
google/skills
Query Cloud Trace spans, filter by latency thresholds or error status, correlate distributed traces with Cloud Logging, and diagnose latency bottlenecks across Google Cloud services.
google/skills
Manages Google Cloud Privileged Access Manager entitlements and grants: create and edit entitlements, request temporary access, and approve or deny pending grants.
google/skills
Writes Terraform alerting policies for AI agents that emit OpenTelemetry metrics, covering reliability, cost, safety, security and quality signals on Google Cloud.
google/skills
Deploys open models or custom weights from Model Garden to Agent Platform endpoints, checks deployment status and cleans up endpoints, confirming before any change.
google/skills
Searches, manages and scaffolds skills in the Gemini Enterprise Agent Platform Skill Registry using bundled Python scripts and Google Cloud credentials.
google/skills
Designs GCP infrastructure as local Terraform, validates and scans it against best practices, then imports it to Application Design Center for deployment and troubleshooting.
Categories
Implement, configure, and secure Sign In With Google (SiwG) using Google Identity Services (GIS / https://accounts.google.com/gsi/client) across web architectures. Sign In With Google Web is an agent skill from google/skills, published by the product's own GitHub organization.com/gsi/client) across web architectures.
Sign In With Google Web fits situations like: creating Google sign-in buttons; implementing Google One Tap with FedCM; integrating GIS in React/Next.js/Angular/HTML; verifying ID tokens on backend runtimes (Python/Node.js/Go/Java).
Run `npx skills add google/skills --skill sign-in-with-google-web -a claude-code`. Or copy the skill folder (skills/identity/sign-in-with-google-web in google/skills) into .claude/skills/sign-in-with-google-web in your project. Claude Code loads it when a task matches its description.
Run `npx skills add google/skills --skill sign-in-with-google-web -a codex`. Or copy the skill folder (skills/identity/sign-in-with-google-web in google/skills) into .agents/skills/sign-in-with-google-web in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add google/skills --skill sign-in-with-google-web -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/sign-in-with-google-web, .gemini/skills/sign-in-with-google-web, .github/skills/sign-in-with-google-web and .opencode/skills/sign-in-with-google-web in your project.
SKILL.md names no scripts, command-line tools or credentials: Sign In With Google Web is instructions for the agent only. Our summary lists: Node.js.
SKILL.md names 5 domains. In commands or code: accounts.google.com and googleapis.com; the agent is likely to contact these when it follows the instructions. As links in the text: datatracker.ietf.org, developers.google.com and w3.org. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Sign In With Google Web is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.1k tokens (SKILL.md is roughly 17k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.8k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Sign In With Google Web: Workos Widgets (usenotra/notra, 256 stars), Fullstack Dev (HHU3637kr/skills, 145 stars), Google Workspace (ericrisco/rsc-harness, 180 stars) and Fullstack Dev (infometa/workbuddyskills, 348 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
google (a GitHub organization, an official publisher) maintains it in google/skills, which has 21,097 GitHub stars. The repository holds 150 skills in this directory. The repository was last updated on October 9, 2026.
Source: google/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.