Developing Authentication via Google Sign-In
Google Sign-In is the most common OAuth provider for mobile apps OAuth 2.0. On Android, it works particularly smoothly through the Credential Manager API (the current approach on modern Android versions); on iOS, it requires the separate GoogleSignIn-iOS SDK and URL Scheme configuration. Complexity: 1 out of 5, but there are a few typical pitfalls that people encounter during first integration. We have implemented Google Sign-In in dozens of projects and know all the nuances — from confusion with Web Client ID to handling missing Google Play Services. Get a consultation on your project — we'll assess the complexity for free.
Current State of the SDK
On Android, the deprecated GoogleSignIn SDK (com.google.android.gms:play-services-auth) is replaced by Credential Manager with GetGoogleIdOption. The old API still works, but Google recommends migration. The new API shows a Bottom Sheet with the device's Google accounts — a native UI without a browser redirect.
| API | Android version | UI | Lifecycle |
|---|---|---|---|
| GoogleSignIn (deprecated) | Android 4.0+ | Browser / WebView | Support ended |
| Credential Manager | Modern versions | Native Bottom Sheet | Active, recommended |
On iOS — GoogleSignIn-iOS SDK (pod GoogleSignIn, SPM google-signin-ios). Requires adding GIDClientID to Info.plist and configuring URL Scheme for redirect after authorization.
Common iOS mistake: forgotten URL Scheme
When configuring GoogleSignIn-iOS, you must add a URL Scheme to Info.plist with the format com.googleusercontent.apps.CLIENT_ID. Without this, authorization opens the browser but cannot return to the app. Solution: add the CFBundleURLTypes key to Info.plist with an array of schemes.
How to Implement Google Sign-In on Android?
// Credential Manager (modern Android versions) val googleIdOption = GetGoogleIdOption.Builder() .setFilterByAuthorizedAccounts(false) .setServerClientId(WEB_CLIENT_ID) // Not Android client ID, but Web client ID .build() val request = GetCredentialRequest.Builder() .addCredentialOption(googleIdOption) .build() val result = credentialManager.getCredential(context, request) val credential = result.credential as? CustomCredential // Process GoogleIdTokenCredential WEB_CLIENT_ID is the client ID for the web application in Google Cloud Console, not for Android. This confusion is a source of the DEVELOPER_ERROR on first run.
ID Token Verification on the Backend
The client passes idToken to the backend. The backend verifies it via the Google tokeninfo endpoint or locally using the google-auth-library. ID Token contains sub (stable Google user ID), email, name, picture. sub is the primary key for user identification; email can change.
Why Google Sign-In is the Standard for Mobile Apps?
A Google account is present for 90% of Android device owners. Integration via OAuth 2.0 provides a single entry point: users authenticate without a password, and you get verified data (email, name). This reduces drop-off at the registration stage by 20–30% compared to an email+password form. Additionally, Google ensures security — ID Token is signed with RSA SHA-256, preventing forgery. It saves up to 40% development time compared to implementing OAuth yourself. Reduces user support costs — fewer forgotten passwords.
How We Integrate Google Sign-In Turnkey
Our team, with 5+ years of experience in mobile development, approaches the task comprehensively:
- Analysis and Design: Determine which scopes are needed (email, profile, plus custom scopes if access to Google Drive, etc., is required). Configure the project in Google Cloud Console (Web Client ID for Android, iOS Client ID, Service Account for backend).
-
Client Integration:
- Android: Connect Credential Manager API, process the result, extract GoogleIdTokenCredential.
- iOS: Configure GoogleSignIn-iOS, handle callback via UIApplication.shared.open + URL Scheme.
- Handle edge case: if Google Play Services are absent (devices without GMS), use a fallback to manual input.
- Server Side: Implement ID Token verification on the backend (Python / JavaScript / Kotlin). Store sub and email, update on each login.
- Testing: Write unit tests on client (mock CredentialManager) and integration tests on backend. Test scenarios: cancellation, invalid token, expiration.
- Deployment and Monitoring: Set up logging of authorizations via Firebase Analytics or Metrica. Add a pre-build screen for users with authorization errors.
| Parameter | Android (Credential Manager) | iOS (GoogleSignIn-iOS) |
|---|---|---|
| Integration complexity | Low (native API) | Medium (URL Scheme configuration, Info.plist) |
| Authorization UI | Native Bottom Sheet | Browser / WebView |
| Requires Google Play Services | Yes | No |
| Offline support | Yes (token cache) | Yes (token cache) |
What's Included in the Work
- Configuration of the project in Google Cloud Console (Client ID for each environment).
- Integration on Android (Credential Manager) and iOS (GoogleSignIn-iOS) with full error handling.
- Backend ID Token verification with API documentation.
- Test environment with authorization simulation capability.
- Migration from the old API (if you already have GoogleSignIn implemented) — without losing user sessions.
- Two weeks of support after delivery — we fix bugs for free.
Timeline: 4–7 business days for basic integration (one client + server). If multiple platforms (Android, iOS, Web) are required, up to 10 days. We'll assess your project in one day.
Our Experience and Guarantees
We've implemented Google Sign-In in 50+ mobile applications — from startups to enterprise solutions (fintech, e-commerce, social networks). Certified engineers (Google Associate Android Developer, Apple iOS Developer). We guarantee the integration works: if critical errors in our part are discovered after delivery, we fix them within 24 hours.
Contact us — get a free consultation on Google Sign-In integration. We'll tell you what pitfalls exist in your project and how to avoid them.







