Agent skill

Google Cloud Auth

by VKirill in VKirill/claude-lane-stack

[RU: oauth google, авторизация гугл, service account, sa key, refresh token, invalidgrant, adc, google cloud auth] Google auth for all Google APIs — OAuth 2.0, Service Account JWT, ADC.

MITAuto-check: notesBackend & APIs

Install Google Cloud Auth

skills CLI
$ npx skills add VKirill/claude-lane-stack --skill google-cloud-auth -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install VKirill/claude-lane-stack google-cloud-auth --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/VKirill/claude-lane-stack.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/lane-stack/skills/google/google-cloud-auth .claude/skills/google-cloud-auth && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
google-cloud-auth
GitHub stars
122
Token cost
~3.1k tokens
SKILL.md length
1,538 words
Files
7 (incl. references)
Skills in repo
53
Repo updated
First seen
Licence
MIT

At a glance

[RU: oauth google, авторизация гугл, service account, sa key, refresh token, invalidgrant, adc, google cloud auth] Google auth for all Google APIs — OAuth 2.0, Service Account JWT, ADC.

  • Tasks that involve OAuth and OpenID Connect
  • SKILL.md covers 🎯 Version Requirements (June…, Usage, Use this skill when and Do not use this skill when, plus 6 more sections
  • Calls gcloud; reaches oauth2.googleapis.com; needs GOOGLE_APPLICATION_CREDENTIALS
  • Tasks that involve Authentication

What it does

Google Cloud Auth is an agent skill from VKirill/claude-lane-stack. [RU: oauth google, авторизация гугл, service account, sa key, refresh token, invalidgrant, adc, google cloud auth] Google auth for all Google APIs — OAuth 2.0, Service Account JWT, ADC. Use when: auth setup, invalidgrant, SA key, refresh token, PKCE, gcloud ADC. SKIP: GA4 (→google-analytics); GSC (→google-search-console); GTM (→google-tag-manager).

Its SKILL.md is about 3.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including reference files (for example `references/adc.md`, `references/errors.md` and `references/oauth2-user-flow.md`).

It sits in Backend & APIs, covering OAuth and OpenID Connect, Authentication and Go-to-market strategy. It works with Google Cloud, Google Analytics and Google Search Console. The repository describes itself as: Multi-agent AI coding factory for one person — Claude Code PM + Codex/Qwen/Grok/Kimi/AGY writers, durable conveyor, auto-merge to main. The licence is MIT.

When your agent uses it

  • Tasks that involve OAuth and OpenID Connect
  • Tasks that involve Authentication
  • Tasks that involve Go-to-market strategy

Example prompts

  • “/google-cloud-auth”

Requirements

  • Python 3
  • Node.js

What it can do on your machine

Read from SKILL.md and the folder at commit ad5d501. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gcloud

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • oauth2.googleapis.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • GOOGLE_APPLICATION_CREDENTIALS

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Google Cloud Auth loads about 3.1k tokens when it runs, and up to ~17k if it reads all its reference files. Until then it costs about 93 tokens; SKILL.md has 1,538 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~93
When it runs · the whole SKILL.md, loaded when a task matches
~3.1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~17k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:106
    a database or secrets manager; never in `.env` files committed to git

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from VKirill/claude-lane-stack at commit ad5d501, republished under its MIT licence (© VKirill). 1,538 words, ~3,102 tokens.

Download SKILL.mdSave it as .claude/skills/google-cloud-auth/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.
name
google-cloud-auth
description
[RU: oauth google, авторизация гугл, service account, sa key, refresh token, invalid_grant, adc, google cloud auth] Google auth for all Google APIs — OAuth 2.0, Service Account JWT, ADC. Use when: auth setup, invalid_grant, SA key, refresh token, PKCE, gcloud ADC. SKIP: GA4 (→google-analytics); GSC (→google-search-console); GTM (→google-tag-manager).
stacks
google-cloud-auth, oauth2, python, nodejs
tags
google, oauth, auth, service-account, adc, refresh-token
source
vechkasov-global-skills
risk
high-stakes
<!-- versions:start -->

🎯 Version Requirements (June 2026)

Primary pins:

  • google-auth-library (Node): 9.x
  • google-auth (Python): 2.x
  • Node.js: 24.x (Active LTS)
  • Python: 3.14.x

Source of truth: STACK_VERSIONS.md — verified 2026-06-11

<!-- versions:end -->

Usage

Loaded automatically when its description matches the active task. This is the single source of truth for all Google API authentication patterns. Read the section you need, then follow the link to the relevant reference file.

Use this skill when

  • Setting up OAuth 2.0 Authorization Code flow (installed app or web app) for any Google API — GSC, GA4, GTM, YouTube, Drive
  • Configuring a Service Account for server-to-server (backend) access: creating SA, downloading key.json, granting access
  • Understanding Application Default Credentials (ADC) and GOOGLE_APPLICATION_CREDENTIALS env var discovery chain
  • Diagnosing invalid_grant, token_has_been_expired_or_revoked, or 401 Unauthorized on a previously working token
  • Choosing between OAuth user flow and Service Account for a given use case
  • Implementing offline access (access_type=offline) and prompt=consent to force a new refresh token
  • Configuring PKCE for installed apps or web apps that cannot store a client secret securely
  • Setting up domain-wide delegation (DWD) — impersonating G Suite users via a Service Account
  • Reviewing minimum scopes needed for a specific Google API (GSC readonly, GA4 readonly, GTM publish, YouTube, etc.)
  • Auditing OAuth consent screen configuration (redirect URIs, app verification, testing vs production mode)

Do not use this skill when

  • You need to make GA4 Data API calls — auth is covered in context; load google-analytics for request shape, quotas, and FilterExpression DSL
  • You need to query Google Search Console data — load google-search-console for dimensions, filters, and URL Inspection
  • You need GTM container / tag management — load google-tag-manager for resource hierarchy and CRUD operations
  • You need Yandex OAuth (Yandex Metrika, Direct, Webmaster) — different provider; load yandex-metrica, yandex-direct, or yandex-webmaster
  • You need general HTTP transport patterns (retries, backoff, connection pooling) — load httpx (Python) or nodejs

Purpose

Google Cloud Authentication provides the credential foundation for every Google API call. Three patterns cover all use cases: OAuth 2.0 Authorization Code flow for end-user consent (installed apps, web apps), Service Account JWT bearer for backend scripts with no user interaction, and Application Default Credentials (ADC) for environments where credentials are pre-injected (Cloud Run, GKE, Compute Engine, gcloud CLI).

This skill is high-stakes because a wrong auth choice or misconfiguration fails silently — the API returns 401 or 403 with a reason that can be mistaken for a permission issue when it is actually a stale token, missing scope, or a refresh token rotation that was not handled. Every downstream Google skill (GA4, GSC, GTM, YouTube) depends on this skill for its credential bootstrap; errors here block all of them.

Capabilities

OAuth 2.0 Authorization Code flow

OAuth 2.0 is the right choice whenever a real Google user must grant consent — for example, when you need to access a Search Console property that the user owns, or read GA4 data on behalf of a paying customer. The flow has two sub-variants: web application (client secret stored server-side, redirect URI is an https:// URL) and installed application (client secret is embedded in the app binary and treated as non-confidential; redirect URI is urn:ietf:wg:oauth:2.0:oob or http://localhost:PORT). Both variants produce the same token pair — access_token (1-hour TTL) and refresh_token (long-lived). PKCE (code_challenge + code_verifier) is mandatory for public clients (installed apps, SPAs) and recommended for web apps. Redirect URIs must be registered in the Cloud Console OAuth client; unregistered URIs return redirect_uri_mismatch immediately.

Full reference: references/oauth2-user-flow.md

Service Account JWT bearer

A Service Account (SA) is a Google-managed identity that authenticates with a key file rather than a user password. The auth library creates a signed JWT assertion, exchanges it for an access token at https://oauth2.googleapis.com/token, and re-exchanges automatically on expiry. This pattern requires: (1) the SA created in Cloud Console + key.json downloaded, (2) the relevant API enabled in the Cloud project, and (3) the SA email granted access on the target resource — for GA4 via Property Access Management, for GSC via the Search Console UI, for GTM via the GTM account/container settings. Domain-wide delegation (DWD) extends this by allowing the SA to impersonate any user in a G Suite domain; it requires a Super Admin to authorize the SA's client ID in the Admin Console.

Full reference: references/service-account.md

Application Default Credentials (ADC)

ADC is the zero-config credential discovery chain used by all Google client libraries (google-auth, googleapis, google-auth-library). When code calls google.auth.default() or new GoogleAuth(), the library walks a discovery chain: (1) GOOGLE_APPLICATION_CREDENTIALS env var pointing to a key.json, (2) gcloud auth application-default login credentials at ~/.config/gcloud/application_default_credentials.json, (3) the workload identity / metadata server on GCP (Cloud Run, GKE, Compute Engine). ADC is the right pattern for cloud-native services — avoids key file management entirely on GCP. On developer machines, gcloud auth application-default login bootstraps the chain in one command.

Full reference: references/adc.md

Scopes catalog

Google APIs use OAuth scopes to limit what a token can do. Always request minimum scopes — over-requesting triggers a broader OAuth consent screen that users are more likely to reject. The scope is set at the time the refresh_token is minted; changing scope requires a new authorization cycle (or prompt=consent to force re-consent on the same redirect). Different APIs use disjoint scope namespaces: webmasters.* for GSC, analytics.* for GA4, tagmanager.* for GTM, youtube.* / yt-analytics.* for YouTube.

Full reference: references/scopes-catalog.md

Refresh token lifecycle

An access_token expires after 3600 seconds. The refresh_token is long-lived but not eternal — it can be revoked by the user, expire if the app stays in "Testing" mode (7-day refresh token expiry), rotate if the project has enabled refresh token rotation, or be invalidated when prompt=consent mints a new one. The canonical error is invalid_grant. Recovery path: detect invalid_grant in the error response, delete the stored token, and redirect the user to the authorization URL with access_type=offline&prompt=consent to get a fresh pair. Tokens must be persisted in a database or secrets manager, never in files committed to git.

Full reference: references/refresh-tokens.md

Show full SKILL.md (574 more words)Show less
Error patterns

Google API auth errors follow a predictable taxonomy. 401 Unauthorized means the access token is absent, expired, or malformed — always attempt a token refresh before surfacing an error to the user. 403 Forbidden means the token is valid but the identity lacks permission — check scopes first, then check resource-level grants (SA not added to GA4/GSC, wrong GTM role). 429 Too Many Requests on the token endpoint means the refresh loop is running too fast — add exponential backoff with jitter. 500/503 on the token endpoint are transient — retry with backoff. The error body JSON distinguishes reasons (invalid_grant, access_denied, admin_policy_enforced, org_internal) that map to different recovery actions.

Full reference: references/errors.md

Behavioral Traits

  • Always choose the minimum scope set — one scope per API, readonly unless writes are confirmed required
  • Always persist refresh tokens in a database or secrets manager; never in .env files committed to git
  • Always handle invalid_grant with a re-authorization redirect, not a retry loop — retrying does not fix a revoked token
  • Always set access_type=offline and prompt=consent when the intent is to get a refresh token that survives beyond the browser session
  • Always verify the GOOGLE_APPLICATION_CREDENTIALS path resolves before running a service in production
  • Always enable the specific API (e.g., Google Analytics Data API, Tag Manager API) in the Cloud Console project — having a valid key file is necessary but not sufficient
  • For Service Accounts, always confirm the SA email has been granted access at the resource level (not just IAM project level) before debugging API calls

Important Constraints

  • NEVER store key.json files in git repositories — use Secret Manager, Vault, or environment variables injected at runtime
  • NEVER request scopes beyond what the current feature requires — re-request with a new prompt=consent when scope expands
  • NEVER reuse a refresh token after receiving invalid_grant — the token is permanently invalidated; the only recovery is re-authorization
  • NEVER implement domain-wide delegation without a Super Admin reviewing and approving the SA client ID in the Admin Console
  • NEVER call prompt=consent unconditionally on every auth request — only when a refresh token is missing or invalid_grant is received
  • ALWAYS use PKCE for installed apps and SPAs — omitting it on public clients is a security vulnerability
  • ALWAYS rotate SA keys on a schedule (recommended: every 90 days) and immediately on suspected compromise
  • ALWAYS check that the correct API is enabled in the Cloud Console project — a missing API enablement produces a misleading 403 or "API not enabled" error
  • google-analytics — GA4 Data API reporting (auth bootstrap is covered there; load this skill for request shape, quotas, FilterExpression)
  • google-search-console — GSC search analytics, URL Inspection, Sitemaps (depends on this skill for credential setup)
  • google-tag-manager — GTM container / tag management (depends on this skill for credential bootstrap)
  • yandex-metrica — Russian analytics analogue; separate Yandex OAuth, not Google OAuth
  • yandex-webmaster — Yandex Webmaster API; separate Yandex OAuth
  • httpx — Python HTTP transport for raw REST calls with bearer tokens
  • nodejs — Node.js runtime patterns for googleapis library and raw fetch with auth headers
  • postgresql — persistence layer for refresh tokens, token expiry, and audit logs
  • redis — short-lived token caching and rate-limit counters for auth endpoints

API Reference

TopicFile
OAuth 2.0 Authorization Code flow — installed app, web app, PKCE, code exchangereferences/oauth2-user-flow.md
Service Account JWT bearer — key.json, domain-wide delegation, when to prefer SAreferences/service-account.md
Application Default Credentials — discovery chain, gcloud, metadata serverreferences/adc.md
Scopes catalog — minimum scopes for GSC, GA4, GTM, YouTube, Drivereferences/scopes-catalog.md
Refresh token lifecycle — rotation, invalid_grant, offline access, prompt=consentreferences/refresh-tokens.md
Error patterns — 401/403/429/500 shapes, retry policy, backoff windowsreferences/errors.md

© VKirill, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 6 other files (references) in plugins/lane-stack/skills/google/google-cloud-auth of VKirill/claude-lane-stack.

  • SKILL.md
  • references/adc.md
  • references/errors.md
  • references/oauth2-user-flow.md
  • references/refresh-tokens.md
  • references/scopes-catalog.md
  • references/service-account.md

Open the folder on GitHubat commit ad5d501

Compare with similar skills

Google Cloud Auth next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Google Cloud Auth compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Google Cloud Auth this skillVKirill/claude-lane-stack122—~3.1kAutomated safety check: NotesMIT
Atmos Authcloudposse/atmos1.4k—~4.2kAutomated safety check: PassApache-2.0
Managing Cloud Identity With Oktamukul975/Anthropic-Cybersecurity-Skills34k—~3.1kAutomated safety check: PassApache-2.0
Iam Auditbriiirussell/cybersecurity-skills412—~3.1kAutomated safety check: NotesMIT
Dpop Adoptiongoogle/skills21k—~2.8kAutomated safety check: PassApache-2.0
Blog GoogleAgriciDaniel/claude-blog2.3k1 repos~3.3kAutomated safety check: NotesMIT

Similar skills

  • Atmos Auth

    cloudposse/atmos

    Authentication and identity management: providers (SSO/SAML/OIDC/GCP/Atmos Pro), identities, keyring, identity chaining, login/exec/shell/console, and github/sts for private GitHub access

    1.4k GitHub stars~4.2k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Managing Cloud Identity With Okta

    mukul975/Anthropic-Cybersecurity-Skills

    Implement Okta as a centralized cloud identity provider: configure SSO with AWS, Azure, and GCP, deploy phishing-resistant MFA with Okta FastPass, automate user provisioning/deprovisioning, and…

    34k GitHub stars~3.1k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Iam Audit

    briiirussell/cybersecurity-skills

    Audit, design, and migrate Identity and Access Management — cloud provider IAM (AWS, GCP, Azure), identity providers (Okta, Entra ID / Azure AD, Auth0, Google Workspace), application authorization…

    412 GitHub stars~3.1k tokensUpdated 4 mo ago
    Backend & APIsAuto-check: notes
  • Dpop Adoption

    google/skills

    Official

    Implement and debug OAuth 2.0 DPoP (RFC 9449) refresh token sender-constraining for WebCrypto, Node.js ES6, and browser runtimes integrating with Google's OAuth platform.

    21k GitHub stars~2.8k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Blog Google

    AgriciDaniel/claude-blog

    Google API integration for blog performance: PageSpeed Insights, CrUX Core Web Vitals with 25-week history, Search Console performance, URL Inspection, Indexing API, GA4 organic traffic, NLP entity…

    2.3k GitHub starsUsed in 1 repo~3.3k tokens
    Marketing & SEOAuto-check: notes
  • Ga4 Analytics

    sundial-org/awesome-openclaw-skills

    Google Analytics 4, Search Console, and Indexing API toolkit.

    663 GitHub stars~1.6k tokensUpdated 7 mo ago
    Sales & SupportAuto-check: notes

More from VKirill/claude-lane-stack

All 53 skills in this repo
  • UI UX Pro Max

    VKirill/claude-lane-stack

    Lane-stack design + brand intelligence (vendored ui-ux-pro-max).

    122 GitHub stars~4.7k tokensUpdated yesterday
    Auto-check passed
  • App Architect

    VKirill/claude-lane-stack

    Owner-facing architect for a new app or service. An agent skill from VKirill/claude-lane-stack.

    122 GitHub stars~1.2k tokensUpdated yesterday
    Auto-check passed
  • Browser QA

    VKirill/claude-lane-stack

    Live browser QA + Playwright-compatible replay. An agent skill from VKirill/claude-lane-stack.

    122 GitHub stars~2.1k tokensUpdated yesterday
    Auto-check passed
  • Copy Project Life

    VKirill/claude-lane-stack

    Карта файлов копирайта в .agents/copy/: шаблоны, статусы, цепочка audience→headlines→ux.

    122 GitHub stars~534 tokensUpdated yesterday
    Auto-check passed
  • Copy Research

    VKirill/claude-lane-stack

    Dispatch copy-lead helpers: Tavily, Codex luna/terra, grok/X, OpenCode DeepSeek, Cursor Grok 4.6 medium-fast.

    122 GitHub stars~827 tokensUpdated yesterday
    Auto-check passed
  • Docs Maintain

    VKirill/claude-lane-stack

    Keep living docs/ honest after code changes. An agent skill from VKirill/claude-lane-stack.

    122 GitHub stars~459 tokensUpdated yesterday
    Auto-check passed

Categories

Questions about Google Cloud Auth

What does Google Cloud Auth do?

[RU: oauth google, авторизация гугл, service account, sa key, refresh token, invalidgrant, adc, google cloud auth] Google auth for all Google APIs — OAuth 2.0, Service Account JWT, ADC. Google Cloud Auth is an agent skill from VKirill/claude-lane-stack.0, Service Account JWT, ADC.

When should I use Google Cloud Auth?

Google Cloud Auth fits situations like: tasks that involve OAuth and OpenID Connect; tasks that involve Authentication; tasks that involve Go-to-market strategy.

How do I install Google Cloud Auth in Claude Code?

Run `npx skills add VKirill/claude-lane-stack --skill google-cloud-auth -a claude-code`. Or copy the skill folder (plugins/lane-stack/skills/google/google-cloud-auth in VKirill/claude-lane-stack) into .claude/skills/google-cloud-auth in your project. Claude Code loads it when a task matches its description.

How do I install Google Cloud Auth in Codex?

Run `npx skills add VKirill/claude-lane-stack --skill google-cloud-auth -a codex`. Or copy the skill folder (plugins/lane-stack/skills/google/google-cloud-auth in VKirill/claude-lane-stack) into .agents/skills/google-cloud-auth in your project. Codex loads it when a task matches its description.

Can I use Google Cloud Auth in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add VKirill/claude-lane-stack --skill google-cloud-auth -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/google-cloud-auth, .gemini/skills/google-cloud-auth, .github/skills/google-cloud-auth and .opencode/skills/google-cloud-auth in your project.

What does Google Cloud Auth need to run?

Going by SKILL.md and its folder, Google Cloud Auth needs the command-line tools its instructions call (gcloud) and credentials named GOOGLE_APPLICATION_CREDENTIALS. Our summary lists: Python 3; Node.js.

Does Google Cloud Auth access the network?

SKILL.md names 1 domain. In commands or code: oauth2.googleapis.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Google Cloud Auth safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Google Cloud Auth use?

Google Cloud Auth is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Google Cloud Auth use?

About 3.1k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 14k tokens, read only when the agent opens those files.

What are the alternatives to Google Cloud Auth?

Skills that share tags, products or a category with Google Cloud Auth: Atmos Auth (cloudposse/atmos, 1.4k stars), Managing Cloud Identity With Okta (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Iam Audit (briiirussell/cybersecurity-skills, 412 stars) and Dpop Adoption (google/skills, 21k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Google Cloud Auth?

VKirill (a GitHub user) maintains it in VKirill/claude-lane-stack, which has 122 GitHub stars. The repository holds 53 skills in this directory. The repository was last updated on October 6, 2026.

Source: VKirill/claude-lane-stack on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.