OAuth 2.0 client for Google APIs with multi-account support, PKCE security, and swappable storage backends
npm install @mcp-z/oauth-google keyv keyv-file
/oauth/callback URL. Local HTTP uses the port configured by the server.http://127.0.0.1 for the ephemeral redirect URL.import { LoopbackOAuthProvider } from '@mcp-z/oauth-google';
import Keyv from 'keyv';
import { KeyvFile } from 'keyv-file';
const provider = new LoopbackOAuthProvider({
service: 'gmail',
clientId: process.env.GOOGLE_CLIENT_ID!,
clientSecret: process.env.GOOGLE_CLIENT_SECRET!,
scope: 'https://www.googleapis.com/auth/gmail.modify',
tokenStore: new Keyv({ store: new KeyvFile({ filename: '.tokens/google.json' }) })
});
const accessToken = await provider.getAccessToken();
// Opens the browser for consent when no valid token is stored, then returns a token.
import { ServiceAccountProvider } from '@mcp-z/oauth-google';
const provider = new ServiceAccountProvider({
keyFilePath: '/path/to/service-account.json',
scopes: ['https://www.googleapis.com/auth/drive']
});
const accessToken = await provider.getAccessToken();
The service-account key file must exist and be readable by the process, and the APIs in scopes must be enabled for the Google Cloud project. Loopback OAuth opens a browser for consent (or returns an authorization URL in headless mode) and stores the resulting token.
Use DcrOAuthProvider for bearer validation and createDcrRouter to host DCR endpoints and accept CIMD clients.
The router uses a secure CIMD resolver by default. Pass an optional cimdResolver from
@mcp-z/oauth when local development needs an explicit loopback policy.
import { DcrOAuthProvider, createDcrRouter } from '@mcp-z/oauth-google';
const provider = new DcrOAuthProvider({
clientId: process.env.GOOGLE_CLIENT_ID!,
clientSecret: process.env.GOOGLE_CLIENT_SECRET!,
scope: 'openid email profile',
verifyEndpoint: 'https://your-host.com/oauth/verify'
});
const router = createDcrRouter({
store,
issuerUrl: 'https://your-host.com',
baseUrl: 'https://your-host.com',
scopesSupported: ['openid', 'email', 'profile'],
clientConfig: {
clientId: process.env.GOOGLE_CLIENT_ID!,
clientSecret: process.env.GOOGLE_CLIENT_SECRET!
}
});
For local development only, create a resolver with an explicit HTTP loopback opt-in and pass it
as cimdResolver in the router configuration:
import { createCimdResolver } from '@mcp-z/oauth';
const cimdResolver = createCimdResolver({ allowHttpLoopback: true });
Use parseConfig() and parseDcrConfig() to load CLI + env settings for servers.
schemas - Shared Zod schemas used by toolsEnrichedExtra - Handler extra type with auth context