vestibule_google
Google OAuth strategy with verified-email handling, hosted-domain enforcement, and refresh-token guidance.
When to use it
Use Google if users sign in with Google or Google Workspace accounts and your app requires normalized profile data.
Default scopes: openid email profile
Install
Vestibule packages are not available on Hex. Add them from GitHub with the moving v0 tag. Use Gleam 1.18 or later because companion packages use Git path dependencies.
[dependencies]vestibule_google = { git = "https://github.com/tylerbutler/vestibule.git", ref = "v0", path = "packages/vestibule_google" }Setup
- Create a Google Cloud project.
- Configure OAuth consent screen with openid, email, and profile scopes.
- Create a Web application OAuth client ID.
- Add the exact redirect URIs for each environment you demo from (HTTPS when not local).
Usage
import vestibule/configimport vestibule_google
let strategy = vestibule_google.strategy()let client_config = config.new( client_id: "google-client-id", redirect_uri: "http://localhost:8000/auth/google/callback", auth: config.ClientSecret("google-client-secret"), )
let workspace_strategy = vestibule_google.strategy_for_hosted_domain("corp.example")What Vestibule handles
- user_info.email only returns a value when email_verified is true.
- Use config.with_extra_params to request offline access.
- strategy_for_hosted_domain validates the hd claim server-side.
- The hd authorization parameter alone is only an account-picker hint.
What you handle
- Google only returns a refresh token on first consent for a client/user/scope combination.
- Use access_type=offline and prompt=consent when requesting refresh tokens.