Install
$ agentstack add skill-khadinakbarlabs-expo-mobile-app-builder-add-google-signin-credential-manager ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
Google Sign-In via Credential Manager
Modern Android auth API (Android 14+, backports to 4.4). Replaces deprecated Google Sign-In SDK.
Install
npx expo install @react-native-google-signin/google-signin
Configure
app.json:
{
"expo": {
"plugins": [
["@react-native-google-signin/google-signin", {
"iosUrlScheme": "com.googleusercontent.apps.YOUR_CLIENT_ID"
}]
]
}
}
SHA-1 setup (CRITICAL)
Add BOTH to Firebase / Google Cloud OAuth:
- Upload key SHA-1 (your keystore)
- Play signing key SHA-1 (from Play Console → App integrity)
Without BOTH: works in dev, breaks in prod.
Implement
import { GoogleSignin, statusCodes } from '@react-native-google-signin/google-signin';
GoogleSignin.configure({
webClientId: 'YOUR_WEB_CLIENT_ID.apps.googleusercontent.com',
});
const signIn = async () => {
try {
await GoogleSignin.hasPlayServices();
const userInfo = await GoogleSignin.signIn();
// userInfo.idToken — send to backend for verification
} catch (e: any) {
if (e.code === statusCodes.SIGN_IN_CANCELLED) return;
throw e;
}
};
Backend verifies idToken
import { OAuth2Client } from 'google-auth-library';
const client = new OAuth2Client();
const ticket = await client.verifyIdToken({ idToken, audience: WEB_CLIENT_ID });
const payload = ticket.getPayload();
// payload.sub = stable Google user ID
Common gotchas
- "DEVELOPER_ERROR" → SHA-1 mismatch
- Two web client IDs (Android client + Web client) — use WEB client ID for
webClientId - Google Play Services missing on emulator → use one with Play services
- Production builds need Play signing SHA-1 added to OAuth credentials
Pair with
add-supabase-auth-android(Supabase handles verify)code-signing-android(SHA-1 extraction)
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: khadinakbarlabs
- Source: khadinakbarlabs/expo-mobile-app-builder
- License: MIT
- Homepage: https://khadinakbar.com
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.