Atmos Auth
cloudposse/atmos
Authentication and identity management: providers (SSO/SAML/OIDC/GCP/Atmos Pro), identities, keyring, identity chaining, login/exec/shell/console, and github/sts for private GitHub access
[RU: oauth google, авторизация гугл, service account, sa key, refresh token, invalidgrant, adc, google cloud auth] Google auth for all Google APIs — OAuth 2.0, Service Account JWT, ADC.
$ npx skills add VKirill/claude-lane-stack --skill google-cloud-auth -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install VKirill/claude-lane-stack google-cloud-auth --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/VKirill/claude-lane-stack.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/lane-stack/skills/google/google-cloud-auth .claude/skills/google-cloud-auth && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "google-cloud-auth" agent skill from https://github.com/VKirill/claude-lane-stack/tree/main/plugins/lane-stack/skills/google/google-cloud-auth into .claude/skills/google-cloud-auth/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "google-cloud-auth", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/VKirill/claude-lane-stack/tree/main/plugins/lane-stack/skills/google/google-cloud-authType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add VKirill/claude-lane-stack --skill google-cloud-auth -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install VKirill/claude-lane-stack google-cloud-auth --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/VKirill/claude-lane-stack.git skills-src && mkdir -p .agents/skills && cp -r skills-src/plugins/lane-stack/skills/google/google-cloud-auth .agents/skills/google-cloud-auth && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "google-cloud-auth" agent skill from https://github.com/VKirill/claude-lane-stack/tree/main/plugins/lane-stack/skills/google/google-cloud-auth into .agents/skills/google-cloud-auth/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "google-cloud-auth", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add VKirill/claude-lane-stack --skill google-cloud-auth -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install VKirill/claude-lane-stack google-cloud-auth --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/VKirill/claude-lane-stack.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/plugins/lane-stack/skills/google/google-cloud-auth .cursor/skills/google-cloud-auth && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "google-cloud-auth" agent skill from https://github.com/VKirill/claude-lane-stack/tree/main/plugins/lane-stack/skills/google/google-cloud-auth into .cursor/skills/google-cloud-auth/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "google-cloud-auth", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/VKirill/claude-lane-stack.git --path plugins/lane-stack/skills/google/google-cloud-auth--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add VKirill/claude-lane-stack --skill google-cloud-auth -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install VKirill/claude-lane-stack google-cloud-auth --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/VKirill/claude-lane-stack.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/plugins/lane-stack/skills/google/google-cloud-auth .gemini/skills/google-cloud-auth && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "google-cloud-auth" agent skill from https://github.com/VKirill/claude-lane-stack/tree/main/plugins/lane-stack/skills/google/google-cloud-auth into .gemini/skills/google-cloud-auth/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "google-cloud-auth", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install VKirill/claude-lane-stack google-cloud-authInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add VKirill/claude-lane-stack --skill google-cloud-auth -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/VKirill/claude-lane-stack.git skills-src && mkdir -p .github/skills && cp -r skills-src/plugins/lane-stack/skills/google/google-cloud-auth .github/skills/google-cloud-auth && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "google-cloud-auth" agent skill from https://github.com/VKirill/claude-lane-stack/tree/main/plugins/lane-stack/skills/google/google-cloud-auth into .github/skills/google-cloud-auth/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "google-cloud-auth", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add VKirill/claude-lane-stack --skill google-cloud-auth -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install VKirill/claude-lane-stack google-cloud-auth --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/VKirill/claude-lane-stack.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/plugins/lane-stack/skills/google/google-cloud-auth .opencode/skills/google-cloud-auth && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "google-cloud-auth" agent skill from https://github.com/VKirill/claude-lane-stack/tree/main/plugins/lane-stack/skills/google/google-cloud-auth into .opencode/skills/google-cloud-auth/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "google-cloud-auth", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
google-cloud-auth[RU: oauth google, авторизация гугл, service account, sa key, refresh token, invalidgrant, adc, google cloud auth] Google auth for all Google APIs — OAuth 2.0, Service Account JWT, ADC.
Google Cloud Auth is an agent skill from VKirill/claude-lane-stack. [RU: oauth google, авторизация гугл, service account, sa key, refresh token, invalidgrant, adc, google cloud auth] Google auth for all Google APIs — OAuth 2.0, Service Account JWT, ADC. Use when: auth setup, invalidgrant, SA key, refresh token, PKCE, gcloud ADC. SKIP: GA4 (→google-analytics); GSC (→google-search-console); GTM (→google-tag-manager).
Its SKILL.md is about 3.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including reference files (for example `references/adc.md`, `references/errors.md` and `references/oauth2-user-flow.md`).
It sits in Backend & APIs, covering OAuth and OpenID Connect, Authentication and Go-to-market strategy. It works with Google Cloud, Google Analytics and Google Search Console. The repository describes itself as: Multi-agent AI coding factory for one person — Claude Code PM + Codex/Qwen/Grok/Kimi/AGY writers, durable conveyor, auto-merge to main. The licence is MIT.
Read from SKILL.md and the folder at commit ad5d501. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
gcloudFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
oauth2.googleapis.comFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
GOOGLE_APPLICATION_CREDENTIALSFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Google Cloud Auth loads about 3.1k tokens when it runs, and up to ~17k if it reads all its reference files. Until then it costs about 93 tokens; SKILL.md has 1,538 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
a database or secrets manager; never in `.env` files committed to gitAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from VKirill/claude-lane-stack at commit ad5d501, republished under its MIT licence (© VKirill). 1,538 words, ~3,102 tokens.
.claude/skills/google-cloud-auth/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.<!-- versions:start -->
Primary pins:
9.x2.x24.x (Active LTS)3.14.xSource of truth: STACK_VERSIONS.md — verified 2026-06-11
<!-- versions:end -->
Loaded automatically when its description matches the active task. This is the single source of truth for all Google API authentication patterns. Read the section you need, then follow the link to the relevant reference file.
GOOGLE_APPLICATION_CREDENTIALS env var discovery chaininvalid_grant, token_has_been_expired_or_revoked, or 401 Unauthorized on a previously working tokenaccess_type=offline) and prompt=consent to force a new refresh tokengoogle-analytics for request shape, quotas, and FilterExpression DSLgoogle-search-console for dimensions, filters, and URL Inspectiongoogle-tag-manager for resource hierarchy and CRUD operationsyandex-metrica, yandex-direct, or yandex-webmasterhttpx (Python) or nodejsGoogle Cloud Authentication provides the credential foundation for every Google API call. Three patterns cover all use cases: OAuth 2.0 Authorization Code flow for end-user consent (installed apps, web apps), Service Account JWT bearer for backend scripts with no user interaction, and Application Default Credentials (ADC) for environments where credentials are pre-injected (Cloud Run, GKE, Compute Engine, gcloud CLI).
This skill is high-stakes because a wrong auth choice or misconfiguration fails silently — the API returns 401 or 403 with a reason that can be mistaken for a permission issue when it is actually a stale token, missing scope, or a refresh token rotation that was not handled. Every downstream Google skill (GA4, GSC, GTM, YouTube) depends on this skill for its credential bootstrap; errors here block all of them.
OAuth 2.0 is the right choice whenever a real Google user must grant consent — for example, when you need to access a Search Console property that the user owns, or read GA4 data on behalf of a paying customer. The flow has two sub-variants: web application (client secret stored server-side, redirect URI is an https:// URL) and installed application (client secret is embedded in the app binary and treated as non-confidential; redirect URI is urn:ietf:wg:oauth:2.0:oob or http://localhost:PORT). Both variants produce the same token pair — access_token (1-hour TTL) and refresh_token (long-lived). PKCE (code_challenge + code_verifier) is mandatory for public clients (installed apps, SPAs) and recommended for web apps. Redirect URIs must be registered in the Cloud Console OAuth client; unregistered URIs return redirect_uri_mismatch immediately.
Full reference: references/oauth2-user-flow.md
A Service Account (SA) is a Google-managed identity that authenticates with a key file rather than a user password. The auth library creates a signed JWT assertion, exchanges it for an access token at https://oauth2.googleapis.com/token, and re-exchanges automatically on expiry. This pattern requires: (1) the SA created in Cloud Console + key.json downloaded, (2) the relevant API enabled in the Cloud project, and (3) the SA email granted access on the target resource — for GA4 via Property Access Management, for GSC via the Search Console UI, for GTM via the GTM account/container settings. Domain-wide delegation (DWD) extends this by allowing the SA to impersonate any user in a G Suite domain; it requires a Super Admin to authorize the SA's client ID in the Admin Console.
Full reference: references/service-account.md
ADC is the zero-config credential discovery chain used by all Google client libraries (google-auth, googleapis, google-auth-library). When code calls google.auth.default() or new GoogleAuth(), the library walks a discovery chain: (1) GOOGLE_APPLICATION_CREDENTIALS env var pointing to a key.json, (2) gcloud auth application-default login credentials at ~/.config/gcloud/application_default_credentials.json, (3) the workload identity / metadata server on GCP (Cloud Run, GKE, Compute Engine). ADC is the right pattern for cloud-native services — avoids key file management entirely on GCP. On developer machines, gcloud auth application-default login bootstraps the chain in one command.
Full reference: references/adc.md
Google APIs use OAuth scopes to limit what a token can do. Always request minimum scopes — over-requesting triggers a broader OAuth consent screen that users are more likely to reject. The scope is set at the time the refresh_token is minted; changing scope requires a new authorization cycle (or prompt=consent to force re-consent on the same redirect). Different APIs use disjoint scope namespaces: webmasters.* for GSC, analytics.* for GA4, tagmanager.* for GTM, youtube.* / yt-analytics.* for YouTube.
Full reference: references/scopes-catalog.md
An access_token expires after 3600 seconds. The refresh_token is long-lived but not eternal — it can be revoked by the user, expire if the app stays in "Testing" mode (7-day refresh token expiry), rotate if the project has enabled refresh token rotation, or be invalidated when prompt=consent mints a new one. The canonical error is invalid_grant. Recovery path: detect invalid_grant in the error response, delete the stored token, and redirect the user to the authorization URL with access_type=offline&prompt=consent to get a fresh pair. Tokens must be persisted in a database or secrets manager, never in files committed to git.
Full reference: references/refresh-tokens.md
Google API auth errors follow a predictable taxonomy. 401 Unauthorized means the access token is absent, expired, or malformed — always attempt a token refresh before surfacing an error to the user. 403 Forbidden means the token is valid but the identity lacks permission — check scopes first, then check resource-level grants (SA not added to GA4/GSC, wrong GTM role). 429 Too Many Requests on the token endpoint means the refresh loop is running too fast — add exponential backoff with jitter. 500/503 on the token endpoint are transient — retry with backoff. The error body JSON distinguishes reasons (invalid_grant, access_denied, admin_policy_enforced, org_internal) that map to different recovery actions.
Full reference: references/errors.md
readonly unless writes are confirmed required.env files committed to gitinvalid_grant with a re-authorization redirect, not a retry loop — retrying does not fix a revoked tokenaccess_type=offline and prompt=consent when the intent is to get a refresh token that survives beyond the browser sessionGOOGLE_APPLICATION_CREDENTIALS path resolves before running a service in productionprompt=consent when scope expandsinvalid_grant — the token is permanently invalidated; the only recovery is re-authorizationprompt=consent unconditionally on every auth request — only when a refresh token is missing or invalid_grant is receivedgoogle-analytics — GA4 Data API reporting (auth bootstrap is covered there; load this skill for request shape, quotas, FilterExpression)google-search-console — GSC search analytics, URL Inspection, Sitemaps (depends on this skill for credential setup)google-tag-manager — GTM container / tag management (depends on this skill for credential bootstrap)yandex-metrica — Russian analytics analogue; separate Yandex OAuth, not Google OAuthyandex-webmaster — Yandex Webmaster API; separate Yandex OAuthhttpx — Python HTTP transport for raw REST calls with bearer tokensnodejs — Node.js runtime patterns for googleapis library and raw fetch with auth headerspostgresql — persistence layer for refresh tokens, token expiry, and audit logsredis — short-lived token caching and rate-limit counters for auth endpoints| Topic | File |
|---|---|
| OAuth 2.0 Authorization Code flow — installed app, web app, PKCE, code exchange | references/oauth2-user-flow.md |
| Service Account JWT bearer — key.json, domain-wide delegation, when to prefer SA | references/service-account.md |
| Application Default Credentials — discovery chain, gcloud, metadata server | references/adc.md |
| Scopes catalog — minimum scopes for GSC, GA4, GTM, YouTube, Drive | references/scopes-catalog.md |
| Refresh token lifecycle — rotation, invalid_grant, offline access, prompt=consent | references/refresh-tokens.md |
| Error patterns — 401/403/429/500 shapes, retry policy, backoff windows | references/errors.md |
© VKirill, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 6 other files (references) in plugins/lane-stack/skills/google/google-cloud-auth of VKirill/claude-lane-stack.
Open the folder on GitHubat commit ad5d501
Google Cloud Auth next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Google Cloud Auth this skillVKirill/claude-lane-stack | 122 | — | ~3.1k | Automated safety check: Notes | MIT | |
| Atmos Authcloudposse/atmos | 1.4k | — | ~4.2k | Automated safety check: Pass | Apache-2.0 | |
| Managing Cloud Identity With Oktamukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | |
| Iam Auditbriiirussell/cybersecurity-skills | 412 | — | ~3.1k | Automated safety check: Notes | MIT | |
| Dpop Adoptiongoogle/skills | 21k | — | ~2.8k | Automated safety check: Pass | Apache-2.0 | |
| Blog GoogleAgriciDaniel/claude-blog | 2.3k | 1 repos | ~3.3k | Automated safety check: Notes | MIT |
cloudposse/atmos
Authentication and identity management: providers (SSO/SAML/OIDC/GCP/Atmos Pro), identities, keyring, identity chaining, login/exec/shell/console, and github/sts for private GitHub access
mukul975/Anthropic-Cybersecurity-Skills
Implement Okta as a centralized cloud identity provider: configure SSO with AWS, Azure, and GCP, deploy phishing-resistant MFA with Okta FastPass, automate user provisioning/deprovisioning, and…
briiirussell/cybersecurity-skills
Audit, design, and migrate Identity and Access Management — cloud provider IAM (AWS, GCP, Azure), identity providers (Okta, Entra ID / Azure AD, Auth0, Google Workspace), application authorization…
google/skills
Implement and debug OAuth 2.0 DPoP (RFC 9449) refresh token sender-constraining for WebCrypto, Node.js ES6, and browser runtimes integrating with Google's OAuth platform.
AgriciDaniel/claude-blog
Google API integration for blog performance: PageSpeed Insights, CrUX Core Web Vitals with 25-week history, Search Console performance, URL Inspection, Indexing API, GA4 organic traffic, NLP entity…
sundial-org/awesome-openclaw-skills
Google Analytics 4, Search Console, and Indexing API toolkit.
VKirill/claude-lane-stack
Lane-stack design + brand intelligence (vendored ui-ux-pro-max).
VKirill/claude-lane-stack
Owner-facing architect for a new app or service. An agent skill from VKirill/claude-lane-stack.
VKirill/claude-lane-stack
Live browser QA + Playwright-compatible replay. An agent skill from VKirill/claude-lane-stack.
VKirill/claude-lane-stack
Карта файлов копирайта в .agents/copy/: шаблоны, статусы, цепочка audience→headlines→ux.
VKirill/claude-lane-stack
Dispatch copy-lead helpers: Tavily, Codex luna/terra, grok/X, OpenCode DeepSeek, Cursor Grok 4.6 medium-fast.
VKirill/claude-lane-stack
Keep living docs/ honest after code changes. An agent skill from VKirill/claude-lane-stack.
Categories
[RU: oauth google, авторизация гугл, service account, sa key, refresh token, invalidgrant, adc, google cloud auth] Google auth for all Google APIs — OAuth 2.0, Service Account JWT, ADC. Google Cloud Auth is an agent skill from VKirill/claude-lane-stack.0, Service Account JWT, ADC.
Google Cloud Auth fits situations like: tasks that involve OAuth and OpenID Connect; tasks that involve Authentication; tasks that involve Go-to-market strategy.
Run `npx skills add VKirill/claude-lane-stack --skill google-cloud-auth -a claude-code`. Or copy the skill folder (plugins/lane-stack/skills/google/google-cloud-auth in VKirill/claude-lane-stack) into .claude/skills/google-cloud-auth in your project. Claude Code loads it when a task matches its description.
Run `npx skills add VKirill/claude-lane-stack --skill google-cloud-auth -a codex`. Or copy the skill folder (plugins/lane-stack/skills/google/google-cloud-auth in VKirill/claude-lane-stack) into .agents/skills/google-cloud-auth in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add VKirill/claude-lane-stack --skill google-cloud-auth -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/google-cloud-auth, .gemini/skills/google-cloud-auth, .github/skills/google-cloud-auth and .opencode/skills/google-cloud-auth in your project.
Going by SKILL.md and its folder, Google Cloud Auth needs the command-line tools its instructions call (gcloud) and credentials named GOOGLE_APPLICATION_CREDENTIALS. Our summary lists: Python 3; Node.js.
SKILL.md names 1 domain. In commands or code: oauth2.googleapis.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Google Cloud Auth is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.1k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 14k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Google Cloud Auth: Atmos Auth (cloudposse/atmos, 1.4k stars), Managing Cloud Identity With Okta (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Iam Audit (briiirussell/cybersecurity-skills, 412 stars) and Dpop Adoption (google/skills, 21k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
VKirill (a GitHub user) maintains it in VKirill/claude-lane-stack, which has 122 GitHub stars. The repository holds 53 skills in this directory. The repository was last updated on October 6, 2026.
Source: VKirill/claude-lane-stack on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.