---
description: Capacitor plugin to sign in with Google on Android, iOS, and Web. Supports ID tokens, OAuth scopes, and user profile retrieval.
title: Capacitor Google Sign-In Plugin for Android, iOS & Web - Capawesome
image: https://capawesome.io/docs/assets/images/social/sdks/capacitor/google-sign-in.png
---

<!doctype html> 

[Skip to content ](#capacitor-google-sign-in-plugin) 

[🖥️ Introducing the **Capacitor Electron Platform** — build desktop apps for macOS, Windows, and Linux. Free & open source. ](/blog/announcing-the-capacitor-electron-platform/) 

* [ SDKs ](/docs/sdks/)
* [ Formbricks ](/docs/sdks/capacitor/formbricks/)
* [ Geocoder ](/docs/sdks/capacitor/geocoder/)
* Google Sign-In [ Google Sign-In ](/docs/sdks/capacitor/google-sign-in/)
* [ iOS ](#ios)
* [ Configuration ](#configuration)
* [ Usage ](#usage)
* [ API ](#api)
* [ Security ](#security)
* [ FAQ ](#faq)
* [ Related Plugins ](#related-plugins)
* [ Newsletter ](#newsletter)
* [ Changelog ](#changelog)
* [ License ](#license)
* [ Grafana Faro ](/docs/sdks/capacitor/grafana-faro/)
* [ Gyroscope ](/docs/sdks/capacitor/gyroscope/)
* [ Haptics ](/docs/sdks/capacitor/haptics/)
* [ Home Indicator ](/docs/sdks/capacitor/home-indicator/)
* [ In-App Browser ](/docs/sdks/capacitor/in-app-browser/)
* [ Install Referrer ](/docs/sdks/capacitor/install-referrer/)
* [ Intercom ](/docs/sdks/capacitor/intercom/)
* [ Intune ](/docs/sdks/capacitor/intune/)
* [ Keep Awake ](/docs/sdks/capacitor/keep-awake/)
* [ libSQL ](/docs/sdks/capacitor/libsql/)
* [ Light Sensor ](/docs/sdks/capacitor/light-sensor/)
* [ Live Update ](/docs/sdks/capacitor/live-update/)
* [ Localization ](/docs/sdks/capacitor/localization/)
* [ Mail Composer ](/docs/sdks/capacitor/mail-composer/)
* [ Managed Configurations ](/docs/sdks/capacitor/managed-configurations/)
* [ Maps Launcher ](/docs/sdks/capacitor/maps-launcher/)
* [ Media Session ](/docs/sdks/capacitor/media-session/)
* [ ML Kit ](/docs/sdks/capacitor/mlkit/)
* [ Navigation Bar ](/docs/sdks/capacitor/navigation-bar/)
* [ Network ](/docs/sdks/capacitor/network/)
* [ NFC ](/docs/sdks/capacitor/nfc/)
* [ Node.js ](/docs/sdks/capacitor/nodejs/)
* [ OAuth ](/docs/sdks/capacitor/oauth/)
* [ Passkeys ](/docs/sdks/capacitor/passkeys/)
* [ Password Autofill ](/docs/sdks/capacitor/password-autofill/)
* [ PDF Generator ](/docs/sdks/capacitor/pdf-generator/)
* [ PDF Viewer ](/docs/sdks/capacitor/pdf-viewer/)
* [ Pedometer ](/docs/sdks/capacitor/pedometer/)
* [ Permissions ](/docs/sdks/capacitor/permissions/)
* [ Phone Dialer ](/docs/sdks/capacitor/phone-dialer/)
* [ Photo Editor ](/docs/sdks/capacitor/photo-editor/)
* [ Photo Manipulator ](/docs/sdks/capacitor/photo-manipulator/)
* [ PixLive ](/docs/sdks/capacitor/pixlive/)
* [ PostHog ](/docs/sdks/capacitor/posthog/)
* [ Printer ](/docs/sdks/capacitor/printer/)
* [ Privacy Screen ](/docs/sdks/capacitor/privacy-screen/)
* [ Proximity Sensor ](/docs/sdks/capacitor/proximity-sensor/)
* [ Purchases ](/docs/sdks/capacitor/purchases/)
* [ RealtimeKit ](/docs/sdks/capacitor/realtimekit/)
* [ Root Detection ](/docs/sdks/capacitor/root-detection/)
* [ Screen Brightness ](/docs/sdks/capacitor/screen-brightness/)
* [ Screen Orientation ](/docs/sdks/capacitor/screen-orientation/)
* [ Screen Reader ](/docs/sdks/capacitor/screen-reader/)
* [ Screenshot ](/docs/sdks/capacitor/screenshot/)
* [ Secure Preferences ](/docs/sdks/capacitor/secure-preferences/)
* [ Settings Launcher ](/docs/sdks/capacitor/settings-launcher/)
* [ Shake ](/docs/sdks/capacitor/shake/)
* [ Silent Mode ](/docs/sdks/capacitor/silent-mode/)
* [ SIM ](/docs/sdks/capacitor/sim/)
* [ SMS Composer ](/docs/sdks/capacitor/sms-composer/)
* [ Speech Recognition ](/docs/sdks/capacitor/speech-recognition/)
* [ Speech Synthesis ](/docs/sdks/capacitor/speech-synthesis/)
* [ Share Target ](/docs/sdks/capacitor/share-target/)
* [ Square Mobile Payments ](/docs/sdks/capacitor/square-mobile-payments/)
* [ SQLite ](/docs/sdks/capacitor/sqlite/)
* [ Superwall ](/docs/sdks/capacitor/superwall/)
* [ System WebView ](/docs/sdks/capacitor/system-webview/)
* [ Tauri ](/docs/sdks/capacitor/tauri/)
* [ Text Interaction ](/docs/sdks/capacitor/text-interaction/)
* [ Text Zoom ](/docs/sdks/capacitor/text-zoom/)
* [ Thermal State ](/docs/sdks/capacitor/thermal-state/)
* [ Toast ](/docs/sdks/capacitor/toast/)
* [ Torch ](/docs/sdks/capacitor/torch/)
* [ Vault ](/docs/sdks/capacitor/vault/)
* [ Volume ](/docs/sdks/capacitor/volume/)
* [ Wallet ](/docs/sdks/capacitor/wallet/)
* [ Wifi ](/docs/sdks/capacitor/wifi/)
* [ YouTube Player ](/docs/sdks/capacitor/youtube-player/)
* [ Zip ](/docs/sdks/capacitor/zip/)
* [ Cordova ](/docs/sdks/cordova/)
* [ Cloud ](/docs/cloud/)
* [ Integrations ](/docs/cloud/live-updates/integrations/)
* Concepts
* Reference
* [ Troubleshooting ](/docs/cloud/live-updates/troubleshooting/)
* [ FAQ ](/docs/cloud/live-updates/faq/)
* [ Native Builds ](/docs/cloud/native-builds/)
* [ Set Up Environments ](/docs/cloud/native-builds/environments/)
* [ Overwrite Native Configurations ](/docs/cloud/native-builds/native-configurations/)
* [ Auto-Increment Build Numbers ](/docs/cloud/native-builds/auto-incrementing-build-numbers/)
* [ Configure the Web Build Script ](/docs/cloud/native-builds/web-build-script/)
* [ Build from a Monorepo ](/docs/cloud/native-builds/monorepo/)
* [ Use pnpm, Yarn, or bun ](/docs/cloud/native-builds/package-managers/)
* [ Install Private npm Packages ](/docs/cloud/native-builds/npm-private-registry/)
* [ Override the Java Version ](/docs/cloud/native-builds/override-java-version/)
* [ Custom iOS Provisioning Profiles ](/docs/cloud/native-builds/custom-ios-provisioning-profiles/)
* [ Build without Git ](/docs/cloud/native-builds/build-without-git/)
* [ Access Git Behind a Firewall ](/docs/cloud/native-builds/firewall-access/)
* [ Integrations ](/docs/cloud/native-builds/integrations/)
* Reference
* [ Troubleshooting ](/docs/cloud/native-builds/troubleshooting/)
* [ FAQ ](/docs/cloud/native-builds/faq/)
* [ App Store Publishing ](/docs/cloud/app-store-publishing/)
* [ Submit a Build ](/docs/cloud/app-store-publishing/submit-a-build/)
* [ Submit Automatically After a Build ](/docs/cloud/app-store-publishing/submit-automatically/)
* [ Troubleshooting ](/docs/cloud/app-store-publishing/troubleshooting/)
* [ FAQ ](/docs/cloud/app-store-publishing/faq/)
* [ Automations ](/docs/cloud/automations/)
* [ Reference ](/docs/cloud/automations/reference/)
* [ Troubleshooting ](/docs/cloud/automations/troubleshooting/)
* [ FAQ ](/docs/cloud/automations/faq/)
* [ Assist ](/docs/cloud/assist/)
* [ CLI ](/docs/cloud/cli/)
* APIs and SDKs
* [ Webhooks ](/docs/cloud/webhooks/)
* [ Integrations ](/docs/cloud/integrations/)
* Account
* [ Organization ](/docs/cloud/organizations/)
* [ Two-Factor Enforcement ](/docs/cloud/organizations/two-factor-authentication/)
* [ Audit Logs ](/docs/cloud/organizations/audit-logs/)
* [ Billing ](/docs/cloud/organizations/billing/)
* [ License Keys ](/docs/cloud/license-keys/)
* [ AI ](/docs/ai/)
* [ Insiders ](/docs/insiders/)
* [ Billing & Plans ](/docs/insiders/billing-and-plans/)
* [ FAQ ](/docs/insiders/faq/)
* [ License ](https://capawesome.io/legal/eula/)
* [ Support ](/docs/support/)
* [ Contributing ](/docs/contributing/)
* Contributing code
* [ Code of Conduct ](/docs/contributing/code-of-conduct/)
* [ Questions ](https://docs.github.com/en/discussions/collaborating-with-your-community-using-discussions/participating-in-a-discussion#creating-a-discussion)
* [ Blog ](/blog/)
* Categories

* [ iOS ](#ios)
* [ Configuration ](#configuration)
* [ Usage ](#usage)
* [ API ](#api)
* [ Security ](#security)
* [ FAQ ](#faq)
* [ Related Plugins ](#related-plugins)
* [ Newsletter ](#newsletter)
* [ Changelog ](#changelog)
* [ License ](#license)

# Capacitor Google Sign-In Plugin[¶](#capacitor-google-sign-in-plugin "Permanent link")

Unofficial Capacitor plugin to sign-in with Google.[1](#fn:1)

[ ![Deliver Live Updates to your Capacitor app with Capawesome Cloud](../../../assets/external/cloud.capawesome.io/assets/banners/cloud-build-and-deploy-capacitor-apps.69628c3f.png) ](https://cloud.capawesome.io/) 

## Features[¶](#features "Permanent link")

The Capacitor Google Sign-In plugin is one of the most complete Google authentication solutions for Capacitor apps. Here are some of the key features:

* 🖥️ **Cross-platform**: Supports Android, iOS, and Web.
* 🔐 **Authentication**: Sign in users with their Google account and receive an ID token (JWT).
* 🔑 **Authorization**: Optionally request OAuth scopes to get an access token and server auth code.
* 👤 **User Profile**: Retrieve the user's email, display name, profile picture, and more.
* 🛡️ **Nonce Support**: Prevent replay attacks with a custom nonce on Android and Web.
* 🪶 **Lightweight**: Just a single dependency and zero unnecessary bloat.
* 🚨 **Error Codes**: Provides detailed error codes for better error handling.
* 🤝 **Compatibility**: Compatible with the [Apple Sign-In](https://capawesome.io/docs/sdks/capacitor/apple-sign-in/) and [OAuth](https://capawesome.io/docs/sdks/capacitor/oauth/) plugins.
* 📦 **CocoaPods & SPM**: Supports CocoaPods and Swift Package Manager for iOS.
* 🔁 **Up-to-date**: Always supports the latest Capacitor version.

Missing a feature? Just [open an issue](https://github.com/capawesome-team/capacitor-plugins/issues) and we'll take a look!

## Use Cases[¶](#use-cases "Permanent link")

The Google Sign-In plugin is typically used wherever users should sign in with their existing Google account, for example:

* **Social login**: Let users sign in to your app with their Google account instead of creating a new password.
* **Backend authentication**: Send the ID token (JWT) to your backend to verify the user's identity.
* **Google API access**: Request OAuth scopes to receive an access token for accessing Google APIs on behalf of the user.
* **Server-side API access**: Exchange the server auth code on your backend for access and refresh tokens.
* **Profile pre-filling**: Use the user's email, display name, and profile picture to pre-fill their profile in your app.

## Compatibility[¶](#compatibility "Permanent link")

| Plugin Version | Capacitor Version | Status         |
| -------------- | ----------------- | -------------- |
| 0.1.x          | \>=8.x.x          | Active support |

## Guides[¶](#guides "Permanent link")

* [How to Sign In with Google using Capacitor](https://capawesome.io/blog/how-to-sign-in-with-google-using-capacitor/)

## Installation[¶](#installation "Permanent link")

You can use our **AI-Assisted Setup** to install the plugin. Add the [Capawesome Skills](https://github.com/capawesome-team/skills) to your AI tool using the following command:

`[](#%5F%5Fcodelineno-0-1)npx skills add capawesome-team/skills --skill capacitor-plugins
`

Then use the following prompt:

`` [](#%5F%5Fcodelineno-1-1) Use the `capacitor-plugins` skill from `capawesome-team/skills` to install the `@capawesome/capacitor-google-sign-in` plugin in my project.
 ``

If you prefer **Manual Setup**, install the plugin by running the following commands and follow the platform-specific instructions below:

`[](#%5F%5Fcodelineno-2-1)npm install @capawesome/capacitor-google-sign-in
[](#%5F%5Fcodelineno-2-2)npx cap sync
`

### Android[¶](#android "Permanent link")

#### Variables[¶](#variables "Permanent link")

This plugin will use the following project variables (defined in your app's `variables.gradle` file):

* `$androidxCredentialsVersion` version of `androidx.credentials:credentials` (default: `1.5.0`)
* `$googleIdVersion` version of `com.google.android.libraries.identity.googleid:googleid` (default: `1.1.1`)
* `$playServicesAuthVersion` version of `com.google.android.gms:play-services-auth` (default: `21.5.0`)

### iOS[¶](#ios "Permanent link")

Add the `GIDClientID` key to the `ios/App/App/Info.plist` file with your iOS client ID from the Google Cloud Console:

`[](#%5F%5Fcodelineno-3-1)<key>GIDClientID</key>
[](#%5F%5Fcodelineno-3-2)<string>YOUR_IOS_CLIENT_ID</string>
`

You also need to add the URL scheme for your iOS client ID to the `ios/App/App/Info.plist` file:

`[](#%5F%5Fcodelineno-4-1)<key>CFBundleURLTypes</key>
[](#%5F%5Fcodelineno-4-2)<array>
[](#%5F%5Fcodelineno-4-3)  <dict>
[](#%5F%5Fcodelineno-4-4)    <key>CFBundleURLSchemes</key>
[](#%5F%5Fcodelineno-4-5)    <array>
[](#%5F%5Fcodelineno-4-6)      <string>com.googleusercontent.apps.YOUR_IOS_CLIENT_ID</string>
[](#%5F%5Fcodelineno-4-7)    </array>
[](#%5F%5Fcodelineno-4-8)  </dict>
[](#%5F%5Fcodelineno-4-9)</array>
`

Replace `YOUR_IOS_CLIENT_ID` with the reversed client ID from the Google Cloud Console (e.g. `com.googleusercontent.apps.123456789-abc`).

## Configuration[¶](#configuration "Permanent link")

No configuration required for this plugin.

## Usage[¶](#usage "Permanent link")

The following examples show how to initialize the plugin, sign in and sign out a user, and complete the sign-in flow on the Web.

### Initialize the plugin[¶](#initialize-the-plugin "Permanent link")

Call `initialize(...)` once before all other methods. The `clientId` must be a **web client ID** from the Google Cloud Console on all platforms, even on Android and iOS. Optionally provide `scopes` to also request authorization, which enables the access token and server auth code in the sign-in result:

`[](#%5F%5Fcodelineno-5-1)import { GoogleSignIn } from '@capawesome/capacitor-google-sign-in';
[](#%5F%5Fcodelineno-5-2)
[](#%5F%5Fcodelineno-5-3)const initialize = async () => {
[](#%5F%5Fcodelineno-5-4)  await GoogleSignIn.initialize({
[](#%5F%5Fcodelineno-5-5)    clientId: '123456789-abc.apps.googleusercontent.com',
[](#%5F%5Fcodelineno-5-6)    scopes: ['https://www.googleapis.com/auth/userinfo.profile'],
[](#%5F%5Fcodelineno-5-7)  });
[](#%5F%5Fcodelineno-5-8)};
`

### Sign in a user[¶](#sign-in-a-user "Permanent link")

Start the Google Sign-In flow and retrieve the ID token (JWT) and the user's profile. Note that on Web, this redirects to the Google OAuth authorization page and the promise never resolves:

`[](#%5F%5Fcodelineno-6-1)import { GoogleSignIn } from '@capawesome/capacitor-google-sign-in';
[](#%5F%5Fcodelineno-6-2)
[](#%5F%5Fcodelineno-6-3)const signIn = async () => {
[](#%5F%5Fcodelineno-6-4)  const result = await GoogleSignIn.signIn();
[](#%5F%5Fcodelineno-6-5)  console.log(result.idToken);
[](#%5F%5Fcodelineno-6-6)  console.log(result.userId);
[](#%5F%5Fcodelineno-6-7)  console.log(result.email);
[](#%5F%5Fcodelineno-6-8)  console.log(result.displayName);
[](#%5F%5Fcodelineno-6-9)  console.log(result.accessToken);
[](#%5F%5Fcodelineno-6-10)  console.log(result.serverAuthCode);
[](#%5F%5Fcodelineno-6-11)};
`

### Complete the sign-in flow on the Web[¶](#complete-the-sign-in-flow-on-the-web "Permanent link")

On Web, the app is redirected back to the `redirectUrl` after the user signs in. Call `handleRedirectCallback()` there to exchange the authorization code for tokens and complete the sign-in flow. Only available on Web:

`[](#%5F%5Fcodelineno-7-1)import { GoogleSignIn } from '@capawesome/capacitor-google-sign-in';
[](#%5F%5Fcodelineno-7-2)import { Capacitor } from '@capacitor/core';
[](#%5F%5Fcodelineno-7-3)
[](#%5F%5Fcodelineno-7-4)const handleRedirectCallback = async () => {
[](#%5F%5Fcodelineno-7-5)  if (Capacitor.getPlatform() !== 'web') {
[](#%5F%5Fcodelineno-7-6)    return;
[](#%5F%5Fcodelineno-7-7)  }
[](#%5F%5Fcodelineno-7-8)  const result = await GoogleSignIn.handleRedirectCallback();
[](#%5F%5Fcodelineno-7-9)  console.log(result.idToken);
[](#%5F%5Fcodelineno-7-10)  console.log(result.userId);
[](#%5F%5Fcodelineno-7-11)  console.log(result.email);
[](#%5F%5Fcodelineno-7-12)  console.log(result.displayName);
[](#%5F%5Fcodelineno-7-13)  console.log(result.accessToken);
[](#%5F%5Fcodelineno-7-14)  console.log(result.serverAuthCode);
[](#%5F%5Fcodelineno-7-15)};
`

### Sign out a user[¶](#sign-out-a-user "Permanent link")

Sign out the current user:

`[](#%5F%5Fcodelineno-8-1)import { GoogleSignIn } from '@capawesome/capacitor-google-sign-in';
[](#%5F%5Fcodelineno-8-2)
[](#%5F%5Fcodelineno-8-3)const signOut = async () => {
[](#%5F%5Fcodelineno-8-4)  await GoogleSignIn.signOut();
[](#%5F%5Fcodelineno-8-5)};
`

## API[¶](#api "Permanent link")

* [handleRedirectCallback()](#handleredirectcallback)
* [initialize(...)](#initialize)
* [signIn(...)](#signin)
* [signOut()](#signout)
* [Interfaces](#interfaces)

### handleRedirectCallback()[¶](#handleredirectcallback "Permanent link")

`[](#%5F%5Fcodelineno-9-1)handleRedirectCallback() => Promise<SignInResult>
`

Handle the redirect callback from the OAuth provider.

This method must be called when the app is redirected back from the OAuth provider. It exchanges the authorization code for tokens and returns the sign-in result.

Only available on Web.

**Returns:** `Promise<[SignInResult](#signinresult)>`

**Since:** 0.1.0

---

### initialize(...)[¶](#initialize "Permanent link")

`[](#%5F%5Fcodelineno-10-1)initialize(options: InitializeOptions) => Promise<void>
`

Initialize the Google Sign-In plugin.

This method must be called once before all other methods.

| Param       | Type                                    |
| ----------- | --------------------------------------- |
| **options** | [InitializeOptions](#initializeoptions) |

**Since:** 0.1.0

---

### signIn(...)[¶](#signin "Permanent link")

`[](#%5F%5Fcodelineno-11-1)signIn(options?: SignInOptions | undefined) => Promise<SignInResult>
`

Start the Google Sign-In flow.

On Web, this redirects to the Google OAuth authorization page. The promise will never resolve on Web. After the user signs in, the app will be redirected back to the `redirectUrl`. Use `handleRedirectCallback()` to complete the sign-in flow.

| Param       | Type                            |
| ----------- | ------------------------------- |
| **options** | [SignInOptions](#signinoptions) |

**Returns:** `Promise<[SignInResult](#signinresult)>`

**Since:** 0.1.0

---

### signOut()[¶](#signout "Permanent link")

`[](#%5F%5Fcodelineno-12-1)signOut() => Promise<void>
`

Sign out the current user.

On Android, this clears the credential state. On iOS, this signs out from the Google Sign-In SDK. On Web, this is a no-op.

**Since:** 0.1.0

---

### Interfaces[¶](#interfaces "Permanent link")

#### SignInResult[¶](#signinresult "Permanent link")

| Prop               | Type           | Description                                                                                                                                                             | Since |
| ------------------ | -------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----- |
| **idToken**        | string         | The ID token (JWT) returned by Google. This token can be sent to your backend for verification.                                                                         | 0.1.0 |
| **userId**         | string         | The unique identifier of the user's Google Account.                                                                                                                     | 0.1.0 |
| **email**          | string \| null | The user's email address.                                                                                                                                               | 0.1.0 |
| **displayName**    | string \| null | The user's display name (full name).                                                                                                                                    | 0.1.0 |
| **givenName**      | string \| null | The user's given name (first name).                                                                                                                                     | 0.1.0 |
| **familyName**     | string \| null | The user's family name (last name).                                                                                                                                     | 0.1.0 |
| **imageUrl**       | string \| null | The URL of the user's profile picture.                                                                                                                                  | 0.1.0 |
| **accessToken**    | string \| null | The access token for accessing Google APIs. Only available when scopes are configured in initialize().                                                                  | 0.1.0 |
| **serverAuthCode** | string \| null | The server auth code that can be exchanged on your backend for access and refresh tokens. Only available on Android and iOS when scopes are configured in initialize(). | 0.1.0 |

#### InitializeOptions[¶](#initializeoptions "Permanent link")

| Prop            | Type       | Description                                                                                                                                                                                                                                                                                                                                                                                          | Since |
| --------------- | ---------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----- |
| **clientId**    | string     | The web client ID from Google Cloud Console. On Android, this is passed as the server client ID to the Credential Manager API and the AuthorizationClient API. On iOS, this is used as the server client ID for the Google Sign-In SDK. On Web, this is used to initialize the Google Sign-In JavaScript API. **Attention**: This must be a web client ID on all platforms, even on Android and iOS. | 0.1.0 |
| **redirectUrl** | string     | The URL to redirect to after the OAuth flow. Only available on Web.                                                                                                                                                                                                                                                                                                                                  | 0.1.0 |
| **scopes**      | string\[\] | The OAuth scopes to request. If provided, the plugin will request authorization in addition to authentication. This enables accessToken and serverAuthCode in the sign-in result.                                                                                                                                                                                                                    | 0.1.0 |

#### SignInOptions[¶](#signinoptions "Permanent link")

| Prop      | Type   | Description                                                           | Since |
| --------- | ------ | --------------------------------------------------------------------- | ----- |
| **nonce** | string | A nonce to prevent replay attacks. Only available on Android and Web. | 0.1.0 |

## Security[¶](#security "Permanent link")

This plugin handles the OAuth flow and returns tokens to your app. To keep your integration secure, be aware of the following:

* **Server-side token verification is required.** The `idToken` (JWT) is **not** verified client-side. Your backend **must** verify the JWT signature using [Google's public keys](https://www.googleapis.com/oauth2/v3/certs) before trusting any claims (e.g. `userId`, `email`). Never use client-side token data for authorization decisions without server-side verification.
* **Exchange `serverAuthCode` on your backend.** If you use scopes, send the `serverAuthCode` to your backend and exchange it there for access and refresh tokens. Never exchange it client-side, as this would expose your client secret.

## FAQ[¶](#faq "Permanent link")

### What's the difference between this plugin and other Google Sign-In plugins?[¶](#whats-the-difference-between-this-plugin-and-other-google-sign-in-plugins "Permanent link")

This plugin is purpose-built for Google Sign-In and focuses on providing a clean and modern API with the latest platform features. Here are some of the key differences:

* **Cross-platform**: Supports Android, iOS, and Web.
* **Lightweight**: No unnecessary dependencies. Just Google Sign-In, nothing else.
* **No deprecated APIs**: Uses the latest platform APIs (Credential Manager on Android, Google Sign-In SDK on iOS).
* **Authentication + Authorization**: Supports both authentication (ID tokens) and authorization (access tokens, server auth codes) in a single flow.
* **Error codes**: Provides typed error codes for proper error handling.
* **Redirect flow on Web**: Uses a redirect-based OAuth flow instead of popups, resulting in a more reliable and user-friendly experience.

### Why do I need a web client ID on Android and iOS?[¶](#why-do-i-need-a-web-client-id-on-android-and-ios "Permanent link")

The `clientId` option must be a web client ID from the Google Cloud Console on all platforms. On Android, it is passed as the server client ID to the Credential Manager API and the AuthorizationClient API. On iOS, it is used as the server client ID for the Google Sign-In SDK. On iOS, you additionally configure your iOS client ID via the `GIDClientID` key in the `Info.plist` file, see the [Installation](#installation) section.

### Why does the `signIn` promise never resolve on the Web?[¶](#why-does-the-signin-promise-never-resolve-on-the-web "Permanent link")

On Web, the plugin uses a redirect-based OAuth flow. The `signIn(...)` method redirects to the Google OAuth authorization page, so the promise never resolves. After the user signs in, the app is redirected back to the `redirectUrl` and you must call `handleRedirectCallback()` to complete the sign-in flow, see the [usage example](#complete-the-sign-in-flow-on-the-web) above.

### How do I get an access token for Google APIs?[¶](#how-do-i-get-an-access-token-for-google-apis "Permanent link")

Configure the `scopes` option in the `initialize(...)` method. The plugin then requests authorization in addition to authentication, which enables the `accessToken` and `serverAuthCode` properties in the sign-in result. If you need access and refresh tokens on your backend, exchange the `serverAuthCode` there, never client-side, as described in the [Security](#security) section.

## Related Plugins[¶](#related-plugins "Permanent link")

* [Apple Sign-In](https://capawesome.io/docs/sdks/capacitor/apple-sign-in/): Sign in users with their Apple account.
* [Facebook Sign-In](https://capawesome.io/docs/sdks/capacitor/facebook-sign-in/): Sign in users with their Facebook account.
* [OAuth](https://capawesome.io/docs/sdks/capacitor/oauth/): Communicate with any OAuth 2.0 and OpenID Connect provider.
* [Passkeys](https://capawesome.io/docs/sdks/capacitor/passkeys/): Create and authenticate with passkeys based on the WebAuthn standard.

## Newsletter[¶](#newsletter "Permanent link")

Stay up to date with the latest news and updates about the Capawesome, Capacitor, and Ionic ecosystem by subscribing to our [Capawesome Newsletter](https://cloud.capawesome.io/newsletter/).

## Changelog[¶](#changelog "Permanent link")

See [CHANGELOG.md](https://github.com/capawesome-team/capacitor-plugins/blob/main/packages/google-sign-in/CHANGELOG.md).

## License[¶](#license "Permanent link")

See [LICENSE](https://github.com/capawesome-team/capacitor-plugins/blob/main/packages/google-sign-in/LICENSE).

---

1. This project is not affiliated with, endorsed by, sponsored by, or approved by Google Inc. or any of their affiliates or subsidiaries. [↩](#fnref:1 "Jump back to footnote 1 in the text")

July 8, 2026 

Back to top

```json
{"@context": "https://schema.org", "@graph": [{"@type": "TechArticle", "@id": "https://capawesome.io/docs/sdks/capacitor/google-sign-in/#article", "headline": "Capacitor Google Sign-In Plugin for Android, iOS & Web", "name": "Capacitor Google Sign-In Plugin for Android, iOS & Web", "description": "Capacitor plugin to sign in with Google on Android, iOS, and Web. Supports ID tokens, OAuth scopes, and user profile retrieval.", "inLanguage": "en", "url": "https://capawesome.io/docs/sdks/capacitor/google-sign-in/", "mainEntityOfPage": "https://capawesome.io/docs/sdks/capacitor/google-sign-in/", "author": {"@type": "Organization", "name": "Capawesome", "url": "https://capawesome.io", "logo": {"@type": "ImageObject", "url": "https://capawesome.io/assets/images/logo.svg"}}, "publisher": {"@type": "Organization", "name": "Capawesome", "url": "https://capawesome.io", "logo": {"@type": "ImageObject", "url": "https://capawesome.io/assets/images/logo.svg"}}, "about": {"@id": "https://capawesome.io/docs/sdks/capacitor/google-sign-in/#software"}}, {"@type": "SoftwareSourceCode", "@id": "https://capawesome.io/docs/sdks/capacitor/google-sign-in/#software", "name": "Capacitor Google Sign-In Plugin for Android, iOS & Web", "description": "Capacitor plugin to sign in with Google on Android, iOS, and Web. Supports ID tokens, OAuth scopes, and user profile retrieval.", "url": "https://capawesome.io/docs/sdks/capacitor/google-sign-in/", "programmingLanguage": "TypeScript", "runtimePlatform": "Capacitor", "codeRepository": "https://github.com/capawesome-team", "author": {"@type": "Organization", "name": "Capawesome", "url": "https://capawesome.io", "logo": {"@type": "ImageObject", "url": "https://capawesome.io/assets/images/logo.svg"}}, "publisher": {"@type": "Organization", "name": "Capawesome", "url": "https://capawesome.io", "logo": {"@type": "ImageObject", "url": "https://capawesome.io/assets/images/logo.svg"}}}]}
{"@context": "https://schema.org", "@type": "FAQPage", "mainEntity": [{"@type": "Question", "name": "What's the difference between this plugin and other Google Sign-In plugins?", "acceptedAnswer": {"@type": "Answer", "text": "This plugin is purpose-built for Google Sign-In and focuses on providing a clean and modern API with the latest platform features. Here are some of the key differences: Cross-platform: Supports Android, iOS, and Web. Lightweight: No unnecessary dependencies. Just Google Sign-In, nothing else. No deprecated APIs: Uses the latest platform APIs (Credential Manager on Android, Google Sign-In SDK on iOS). Authentication + Authorization: Supports both authentication (ID tokens) and authorization (access tokens, server auth codes) in a single flow. Error codes: Provides typed error codes for proper error handling. Redirect flow on Web: Uses a redirect-based OAuth flow instead of popups, resulting in a more reliable and user-friendly experience."}}, {"@type": "Question", "name": "Why do I need a web client ID on Android and iOS?", "acceptedAnswer": {"@type": "Answer", "text": "The clientId option must be a web client ID from the Google Cloud Console on all platforms. On Android, it is passed as the server client ID to the Credential Manager API and the AuthorizationClient API. On iOS, it is used as the server client ID for the Google Sign-In SDK. On iOS, you additionally configure your iOS client ID via the GIDClientID key in the Info.plist file, see the Installation section."}}, {"@type": "Question", "name": "Why does the signIn promise never resolve on the Web?", "acceptedAnswer": {"@type": "Answer", "text": "On Web, the plugin uses a redirect-based OAuth flow. The signIn(...) method redirects to the Google OAuth authorization page, so the promise never resolves. After the user signs in, the app is redirected back to the redirectUrl and you must call handleRedirectCallback() to complete the sign-in flow, see the usage example above."}}, {"@type": "Question", "name": "How do I get an access token for Google APIs?", "acceptedAnswer": {"@type": "Answer", "text": "Configure the scopes option in the initialize(...) method. The plugin then requests authorization in addition to authentication, which enables the accessToken and serverAuthCode properties in the sign-in result. If you need access and refresh tokens on your backend, exchange the serverAuthCode there, never client-side, as described in the Security section."}}], "url": "https://capawesome.io/docs/sdks/capacitor/google-sign-in/"}
```
