Skip to main content
For the complete documentation index for agents and LLMs, see llms.txt.

Set Up OAuth for GoogleBeta

Beta
This is coming — this page describes a feature that's still being rolled out and may not be available to you yet.

Register Google as an OAuth provider so users can authorize Google APIs and Google Workspace MCP services from Haystack Enterprise Platform and use them in their pipelines.


About This Task​

The Google template uses Google's OAuth 2.0 endpoints and pre-fills scopes for OpenID Connect (openid, email, profile).

Google Workspace MCP templates (Gmail, Drive, Docs, and others) use the same Google Cloud project and OAuth client. Each template only changes the requested scopes. If you need long-lived access for MCP servers, include offline access in your authorize URL or scopes where Google supports refresh tokens for your app type.

Prerequisites​

  • Make sure you meet the prerequisites for Configure External Connections.
  • You need a Google Cloud project and permission to create OAuth credentials.
Redirect URL

Register the redirect URI from the Redirect URL field in the Add OAuth Provider dialog with your identity provider. Keep the default unless you embed the connect flow in your own frontend.

The callback is served by the deepset API, not the web app. On deepset Cloud, the default is https://api.cloud.deepset.ai/api/v2/connections/callback. On other deployments, use your organization's API base URL with the path /api/v2/connections/callback.

Create OAuth Credentials in Google Cloud​

  1. Open the Google Cloud console.
  2. Select or create a project for this integration.
  3. Go to APIs & Services > OAuth consent screen and configure the consent screen for your organization (internal or external users, scopes, test users if the app is in testing).
  4. Go to APIs & Services > Credentials and click Create credentials > OAuth client ID.
  5. Choose Web application as the application type.
  6. Under Authorized redirect URIs, add the redirect URI from Haystack Enterprise Platform (see below).
  7. Click Create and record the Client ID and Client secret.
  8. Turn on the Google APIs your scopes need, for example Gmail API or Google Drive API, under APIs & Services > Library.

For step-by-step guidance, see Using OAuth 2.0 for Web Server Applications.

Register the Provider in Haystack Enterprise Platform​

  1. Click your profile icon and choose Settings.
  2. Go to Organization and open Integrations.
  3. In External Connections, click Add OAuth Provider.
  4. Select Google or a Google Workspace MCP template (Gmail, Drive, Calendar, and so on).
  5. Fill in the fields:
    • Provider Type — keep the suggested value (for example google or google-gmail-mcp).
    • Display Name — the name users see, for example Google or Gmail (MCP). Choose a name that will make it easy for users to identify the provider.
    • Client ID and Client Secret from Google Cloud.
    • Authorization URL and Token URL — usually pre-filled; for MCP templates the authorize URL may include access_type=offline and prompt=consent to help you get refresh tokens.
    • Scopes — review the template list and add or remove scopes for your use case.
  6. Turn on PKCE Required if your Google OAuth client enforces PKCE (recommended for public clients; optional for confidential web clients). To learn more about PKCE, see Proof Key for Code Exchange (PKCE).
  7. Click Create.

What To Do Next​