powered by

Social Sign-In

Let users sign in to your application with their Google account. Once configured, the standard login screen gains a 'Sign in with Google' button — no custom auth code required.

How it works

When Google Sign-In is enabled, Anythink handles the full OAuth 2.0 flow:

  1. The user clicks Sign in with Google on your login page
  2. They are redirected to Google's consent screen
  3. Google returns a verified identity token to Anythink
  4. If a user with that email already exists, they are linked automatically
  5. If no account exists, a new user is created and assigned your default role

Only verified Google email addresses are accepted. Unverified addresses are rejected.


Setup

Step 1 — Create OAuth credentials in Google Cloud

  1. Go to console.cloud.google.com/apis/credentials
  2. Click Create Credentials → OAuth 2.0 Client ID
  3. Set Application type to Web application
  4. Add your authorised redirect URI: https://your-domain.com/auth/google/callback
  5. Copy the Client ID and Client Secret

Step 2 — Configure Anythink

  1. In the Breeze dashboard, go to Settings → Social Sign-In
  2. Toggle Enable Google Sign-In to on
  3. Enter your Client ID and Client Secret
  4. Click Save Google OAuth Settings

The client secret is stored encrypted and will be masked (shown as ****) after saving. If you need to update it, enter a new value — entering the masked placeholder will not overwrite the existing secret.


Account linking

If a user previously created an account with their email and password, and later signs in with Google using the same email, Anythink automatically links the accounts. The user can then sign in via either method.


Reusing credentials for integrations

If you also use Google Calendar in the Integrations section, you can tick Reuse Social Sign-In credentials rather than entering a separate set of OAuth credentials. This works when both features are covered by the same Google Cloud OAuth application.


Security considerations

  • Tokens are validated server-side on every request — Anythink never trusts the client alone
  • If you rotate your Google client secret, update it in Settings → Social Sign-In promptly
  • Disabling Google Sign-In immediately prevents all future Google-authenticated logins; existing accounts are not deleted