Set Up OAuth for GoogleBeta
Register Google as an OAuth provider so users can authorize Google APIs and Google Workspace MCP services from Haystack Enterprise Platform and use them in their pipelines.
About This Task
The Google template uses Google's OAuth 2.0 endpoints and pre-fills scopes for OpenID Connect (openid, email, profile).
Google Workspace MCP templates (Gmail, Drive, Docs, and others) use the same Google Cloud project and OAuth client. Each template only changes the requested scopes. If you need long-lived access for MCP servers, include offline access in your authorize URL or scopes where Google supports refresh tokens for your app type.
Prerequisites
- Make sure you meet the prerequisites for Configure External Connections.
- You need a Google Cloud project and permission to create OAuth credentials.
Register the redirect URI from the Redirect URL field in the Add OAuth Provider dialog with your identity provider. Keep the default unless you embed the connect flow in your own frontend.
The callback is served by the deepset API, not the web app. On deepset Cloud, the default is https://api.cloud.deepset.ai/api/v2/connections/callback. On other deployments, use your organization's API base URL with the path /api/v2/connections/callback.
Create OAuth Credentials in Google Cloud
- Open the Google Cloud console.
- Select or create a project for this integration.
- Go to APIs & Services > OAuth consent screen and configure the consent screen for your organization (internal or external users, scopes, test users if the app is in testing).
- Go to APIs & Services > Credentials and click Create credentials > OAuth client ID.
- Choose Web application as the application type.
- Under Authorized redirect URIs, add the redirect URI from Haystack Enterprise Platform (see below).
- Click Create and record the Client ID and Client secret.
- Turn on the Google APIs your scopes need, for example Gmail API or Google Drive API, under APIs & Services > Library.
For step-by-step guidance, see Using OAuth 2.0 for Web Server Applications.
Register the Provider in Haystack Enterprise Platform
- Click your profile icon and choose Settings.
- Go to Organization and open Integrations.
- In External Connections, click Add OAuth Provider.
- Select Google or a Google Workspace MCP template (Gmail, Drive, Calendar, and so on).
- Fill in the fields:
- Provider Type — keep the suggested value (for example
googleorgoogle-gmail-mcp). - Display Name — the name users see, for example
GoogleorGmail (MCP). Choose a name that will make it easy for users to identify the provider. - Client ID and Client Secret from Google Cloud.
- Authorization URL and Token URL — usually pre-filled; for MCP templates the authorize URL may include
access_type=offlineandprompt=consentto help you get refresh tokens. - Scopes — review the template list and add or remove scopes for your use case.
- Provider Type — keep the suggested value (for example
- Turn on PKCE Required if your Google OAuth client enforces PKCE (recommended for public clients; optional for confidential web clients). To learn more about PKCE, see Proof Key for Code Exchange (PKCE).
- Click Create.
What To Do Next
Was this page helpful?