ClaireDocs

Ask Claire

Search the project, not the web.

Answers are grounded in Claire’s published documentation and include the source pages used.

⌘/Ctrl + J opens Ask Claire anywhere in docs.

Google OAuth setup

Configure Google sign-in for Claire without committing provider credentials.

CurrentReviewed 2026-08-17View source ↗
The sign-in screen this configuresOpen the mobile gallery →

Google sign-in runs through Supabase Auth. Most of the work is in two consoles, and almost every failure is a redirect URI that does not match exactly.

Prerequisites#

  • A Google Cloud Console account
  • Access to your Supabase project dashboard
  • Claire running locally

Google Cloud Console#

  1. Create or select a project

    In the Google Cloud Console, create a new project or pick an existing one.

  2. Enable the Google+ API

    APIs & Services → Library → search for “Google+ API” → Enable.

  3. Configure the OAuth consent screen

    Choose External for the user type, fill in the app name and support email, and add your own address to the test users.

  4. Create an OAuth client ID

    APIs & Services → Credentials → Create Credentials → OAuth client ID. Application type Web application.

    FieldValue
    Authorized JavaScript originhttps://<your-project-ref>.supabase.co
    Authorized redirect URIhttps://<your-project-ref>.supabase.co/auth/v1/callback
  5. Copy the client ID and secret

    You will paste both into Supabase in the next section.

Supabase#

  1. Open Authentication → Providers and enable Google

  2. Paste the client ID and secret

  3. Configure the redirect URLs

    SettingValue
    Site URLclaire://auth/callback
    Additional redirecthttp://localhost:3000
    Additional redirectclaire://auth/callback
    Additional redirectexp://<your-lan-ip>:8081
  4. Save

Test the integration#

Terminal — mobile
bun run ios

Open the sign-in screen and choose “Sign in with Google”. A browser opens with Google’s login page, and a successful authentication redirects back into the app.

Going to production#

  1. Set the OAuth consent screen to Published in Google Cloud Console.
  2. Add your production domain to the authorized origins and redirect URIs.
  3. Update the Supabase redirect URLs with the production values.
  4. Confirm deep linking is configured in the mobile app.

Troubleshooting#

SymptomCause and fix
Redirect URI mismatchThe app’s redirect URI must match Google’s configuration exactly, and the Supabase URL must be an authorized JavaScript origin.
“User cancelled login”Normal when the browser is closed before authenticating. No action needed.
Deep link does not open the appCheck the claire scheme in app.json; iOS may need associated domains and Android needs the intent filter.
Token missing after redirectThe redirect URL must carry the hash fragment; verify the parsing in googleAuth.ts.

Security notes#