# Add Google Signin Credential Manager

> Add Google Sign-In via Credential Manager API (modern Android auth, replaces deprecated Google Sign-In SDK). Use when the user says 'google sign in android', 'credential manager android', 'auth android'.

- **Type:** Skill
- **Install:** `agentstack add skill-khadinakbarlabs-expo-mobile-app-builder-add-google-signin-credential-manager`
- **Verified:** Yes — security-reviewed for prompt injection and unsafe behavior
- **Seller:** [khadinakbarlabs](https://agentstack.voostack.com/s/khadinakbarlabs)
- **Installs:** 0
- **Category:** [Security](https://agentstack.voostack.com/c/security)
- **Latest version:** 0.1.0
- **License:** MIT
- **Upstream author:** [khadinakbarlabs](https://github.com/khadinakbarlabs)
- **Source:** https://github.com/khadinakbarlabs/expo-mobile-app-builder/tree/main/skills/add-google-signin-credential-manager
- **Website:** https://khadinakbar.com

## Install

```sh
agentstack add skill-khadinakbarlabs-expo-mobile-app-builder-add-google-signin-credential-manager
```

Requires the [AgentStack CLI](https://agentstack.voostack.com/docs/cli). Works with Claude Code, Cursor, and any MCP-compatible agent.

## About

# Google Sign-In via Credential Manager

Modern Android auth API (Android 14+, backports to 4.4). Replaces deprecated Google Sign-In SDK.

## Install
```bash
npx expo install @react-native-google-signin/google-signin
```

## Configure
`app.json`:
```json
{
  "expo": {
    "plugins": [
      ["@react-native-google-signin/google-signin", {
        "iosUrlScheme": "com.googleusercontent.apps.YOUR_CLIENT_ID"
      }]
    ]
  }
}
```

## SHA-1 setup (CRITICAL)
Add BOTH to Firebase / Google Cloud OAuth:
- Upload key SHA-1 (your keystore)
- Play signing key SHA-1 (from Play Console → App integrity)

Without BOTH: works in dev, breaks in prod.

## Implement
```tsx
import { GoogleSignin, statusCodes } from '@react-native-google-signin/google-signin';

GoogleSignin.configure({
  webClientId: 'YOUR_WEB_CLIENT_ID.apps.googleusercontent.com',
});

const signIn = async () => {
  try {
    await GoogleSignin.hasPlayServices();
    const userInfo = await GoogleSignin.signIn();
    // userInfo.idToken — send to backend for verification
  } catch (e: any) {
    if (e.code === statusCodes.SIGN_IN_CANCELLED) return;
    throw e;
  }
};
```

## Backend verifies idToken
```ts
import { OAuth2Client } from 'google-auth-library';
const client = new OAuth2Client();
const ticket = await client.verifyIdToken({ idToken, audience: WEB_CLIENT_ID });
const payload = ticket.getPayload();
// payload.sub = stable Google user ID
```

## Common gotchas
- "DEVELOPER_ERROR" → SHA-1 mismatch
- Two web client IDs (Android client + Web client) — use WEB client ID for `webClientId`
- Google Play Services missing on emulator → use one with Play services
- Production builds need Play signing SHA-1 added to OAuth credentials

## Pair with
- `add-supabase-auth-android` (Supabase handles verify)
- `code-signing-android` (SHA-1 extraction)

## Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

- **Author:** [khadinakbarlabs](https://github.com/khadinakbarlabs)
- **Source:** [khadinakbarlabs/expo-mobile-app-builder](https://github.com/khadinakbarlabs/expo-mobile-app-builder)
- **License:** MIT
- **Homepage:** https://khadinakbar.com

Install and usage instructions live in the source repository linked above.

## Pricing

- **Free** — Free

## Security capabilities

Automated source analysis of v0.1.0 — what this tool can access:

- **Network access:** no
- **Filesystem access:** no
- **Shell / process execution:** no
- **Environment & secrets:** no
- **Dynamic code execution:** no

*"Yes" means the capability is present in the source — more access means more to trust, not that it is unsafe.*


## Versions

- **0.1.0** — security scan: passed — Imported from the upstream source.

## Links

- Listing page: https://agentstack.voostack.com/l/skill-khadinakbarlabs-expo-mobile-app-builder-add-google-signin-credential-manager
- Seller: https://agentstack.voostack.com/s/khadinakbarlabs
- Browse the marketplace: https://agentstack.voostack.com/browse

---
Listed on AgentStack — the marketplace for AI agent skills and MCP servers. Every listing is security-reviewed. Creators keep 70%.
