API provider
Three-legged Google OAuth 2.0. Each end-user logs in with their own Google account; the app acts on their behalf with the scopes they grant. Use these settings: authorizationUrl = https://accounts.google.com/o/oauth2/auth, tokenUrl = https://oauth2.googleapis.com/token; set bonusAccessArgs to &access_type=offline&prompt=consent to obtain refresh tokens, and hosted_domain to restrict logins to a Google Workspace domain.
- API category:
Google - Needs login: Yes, three-legged: each end-user must complete an OAuth-style login flow
Configuration parameters
Required
title: string; required
Human-readable label for this OAuth provider (shown to end-users during login).authorizationUrl: string; required
Provider’s OAuth2 authorization endpoint URL (where users are redirected to log in).$ENV_VARreferences anywhere in the value are resolved from the app’s environment at request time.tokenUrl: string; required
Provider’s OAuth2 token endpoint URL (where authorization codes are exchanged for access tokens).$ENV_VARreferences anywhere in the value are resolved from the app’s environment at request time.clientId: string; required
OAuth client ID issued by the provider when the app was registered. Use$ENV_VAR(the whole value) to load it from an environment variable.clientSecret: string; required
OAuth client secret issued by the provider when the app was registered. Use$ENV_VAR(the whole value) to load it from an environment variable.
Optional
bonusAccessArgs: string; optional
Extra query-string arguments appended to the authorization URL (e.g.&access_type=offline&prompt=consentfor Google refresh tokens).hosted_domain: string; optional
If set, restricts logins to accounts in this domain (e.g. for Google Workspace SSO). Where the app also accepts bearer tokens, it restricts those callers too, matched against the token’shdclaim.defaultExpiration: string; optional
Token expiration in seconds, used as a fallback when the provider does not return one (e.g.1800for Salesforce and QuickBooks).nameForScopeParameter: string; optional
Override the scope-parameter name in the authorization URL (some providers usescopesinstead ofscope).tokenMetadata: string; optional
Provider-specific metadata appended to access tokens, carrying an instance/tenant identifier where the integration needs one (the instance id for Salesforce and ServiceNow, the company Realm ID for QuickBooks). Leave blank for providers that do not need it.resource: string; optional
RFC 8707 resource indicator: the URL of the resource these tokens are for, such as an MCP server’s endpoint. Sent on the authorization request, the code exchange and the refresh grant, so the provider can issue a token audienced to that resource alone. Leave blank unless the provider asks for it; this names a resource this app calls, never an endpoint this app serves.disablePkce: true/false; optional
Set totrueto turn off PKCE (RFC 7636) for this connection, which is otherwise always on. Only for an authorization server that rejects thecode_challengeparameter instead of ignoring it, as RFC 6749 requires of parameters it does not recognize; turning PKCE off gives up the protection against a stolen authorization code, so leave this unset unless logins fail without it.mcp_issuer: string; optional
Issuer an inbound ID token must name in itsissclaim, and the authorization server advertised to callers. For Google,https://accounts.google.com. Set together with the othermcp_settings.mcp_jwks_uri: string; optional
JWKS endpoint whose keys sign those ID tokens. For Google,https://www.googleapis.com/oauth2/v3/certs. Set together with the othermcp_settings.mcp_audience: string; optional
Comma-separated audiences this app accepts, matched against the token’saudclaim. Where the provider mints no custom audience, as Google does not, these are the callers’ OAuth client IDs rather than this app. Set together with the othermcp_settings.mcp_resource: string; optional
This app’s own MCP endpoint URL, advertised in the protected-resource metadata document and used as that endpoint’s trusted origin. Set together with the othermcp_settings.
What components can use this API
Concepts:
Ingredients:
Call API endpoint(informIngredients)Call API endpoint(inrowActionsIngredients)Call list API endpoint(inrowActionsIngredients)Draft Gmail(inrowActionsIngredients)Load list column from API endpoint(inrowActionsIngredients)Paginated API GET(inrowActionsIngredients)Render as file link(incustomShowIngredientsList)Render as image(incustomShowIngredientsList)Send Gmail(inrowActionsIngredients)Set via API call(insetterIngredientsList)