# Google OAuth Setup for Android APK ## Step 1: Create a Google Cloud Project 1. Go to https://console.cloud.google.com/ 2. Click **Select a project** → **New Project** 3. Name it and click **Create** ## Step 2: Enable the Photos Picker API 1. Go to **APIs & Services** → **Library** 2. Search for **Photos Picker API** → **Enable** it 3. ⚠️ This step is **required** — without it, all Picker API calls fail 4. (The old "Photos Library API" is deprecated and no longer works) ## Step 3: Configure the OAuth Consent Screen 1. Go to **APIs & Services** → **OAuth consent screen** 2. Choose **External** → **Create** 3. Fill in: - **App name**: MASS Photo App - **User support email**: your email - **Developer contact**: your email 4. **Scopes** → Add or Remove Scopes → add these: - `openid` - `https://www.googleapis.com/auth/photospicker.mediaitems.readonly` - `https://www.googleapis.com/auth/userinfo.email` - `https://www.googleapis.com/auth/userinfo.profile` 5. **Test users** → **Add your Google account email address** - ⚠️ This is **critical** — if your email is not listed as a test user, Google will silently strip the Photos Picker scope from the granted token. ## Step 4: Create an Android OAuth Client ID 1. Go to **APIs & Services** → **Credentials** 2. **+ Create Credentials** → **OAuth client ID** 3. Application type: **Android** 4. Package name: `com.bobthebob.massphotoapp` 5. SHA-1 certificate fingerprint: get it by running `eas credentials --platform android` 6. Click **Create** and copy the **Client ID** 7. Open `src/AUTH/GoogleAUTH.js` and set `ANDROID_CLIENT_ID` to the copied value ## How it works - The **Android client ID** is used for both the authorization request and the token exchange. Google verifies the request using the app's package name + SHA-1 signing certificate, so no redirect URI registration is needed. - The redirect goes to `com.bobthebob.massphotoapp:/oauthredirect` which Android routes back into the app via the intent filter in `app.json`. - Android clients are public (no `client_secret` required). PKCE `code_verifier` is used to secure the authorization code exchange. ## Testing the API with OAuth Playground 1. Go to https://developers.google.com/oauthplayground 2. Click the gear icon → check "Use your own OAuth credentials" 3. You will need a **Web application** client for the playground only (the playground cannot use Android clients). Create one in the console if needed, add `https://developers.google.com/oauthplayground` to its redirect URIs. 4. Select Photos Library API scopes and authorize 5. Copy the access token and run: `node TEST/testGooglePhotosAPI.js `