ToolUp.AuthProviders.GoogleIdentity.Client 0.25.1

Prefix Reserved
dotnet add package ToolUp.AuthProviders.GoogleIdentity.Client --version 0.25.1
                    
NuGet\Install-Package ToolUp.AuthProviders.GoogleIdentity.Client -Version 0.25.1
                    
This command is intended to be used within the Package Manager Console in Visual Studio, as it uses the NuGet module's version of Install-Package.
<PackageReference Include="ToolUp.AuthProviders.GoogleIdentity.Client" Version="0.25.1" />
                    
For projects that support PackageReference, copy this XML node into the project file to reference the package.
<PackageVersion Include="ToolUp.AuthProviders.GoogleIdentity.Client" Version="0.25.1" />
                    
Directory.Packages.props
<PackageReference Include="ToolUp.AuthProviders.GoogleIdentity.Client" />
                    
Project file
For projects that support Central Package Management (CPM), copy this XML node into the solution Directory.Packages.props file to version the package.
paket add ToolUp.AuthProviders.GoogleIdentity.Client --version 0.25.1
                    
#r "nuget: ToolUp.AuthProviders.GoogleIdentity.Client, 0.25.1"
                    
#r directive can be used in F# Interactive and Polyglot Notebooks. Copy this into the interactive tool or source code of the script to reference the package.
#:package ToolUp.AuthProviders.GoogleIdentity.Client@0.25.1
                    
#:package directive can be used in C# file-based apps starting in .NET 10 preview 4. Copy this into a .cs file before any lines of code to reference the package.
#addin nuget:?package=ToolUp.AuthProviders.GoogleIdentity.Client&version=0.25.1
                    
Install as a Cake Addin
#tool nuget:?package=ToolUp.AuthProviders.GoogleIdentity.Client&version=0.25.1
                    
Install as a Cake Tool

ToolUp.AuthProviders.GoogleIdentity.Client

Client-side Google Identity Services (GIS) sign-in UI for ToolUp.Platform: Google's rendered branded button, an opt-in One Tap prompt, and a credential bridge that admits the returned id_token to the same OIDC token store the redirect flow writes.

When to bother

You do not need this package to sign in with Google. ToolUp.AuthProviders.Oidc.Client plus OidcPresets.google is a complete, functional Google sign-in — redirect, PKCE, callback, session, sign-out. This companion exists for two things that specifically require loading Google's own JavaScript library:

  • The branded button. Google's brand guidelines ask for their rendered button rather than a look-alike, and the rendered button only comes from the GIS library.
  • One Tap. The prompt that offers a returning visitor their Google account without a click.

If you want neither, compose the redirect flow and skip this package entirely — a deployment that does not compose it carries zero GIS bytes.

Composition

open ToolUp.AuthProviders.GoogleIdentity.GoogleIdentityConfig
open ToolUp.AuthProviders.GoogleIdentity

let googleUi =
    GoogleIdentityUIConfig.create "1234567890-abcdefg.apps.googleusercontent.com"

Client.run
    { ClientConfig.defaults with
        AppName = "MyApp"
        AuthUI = GoogleIdentityRegister.authUI googleUi
        Handlers = {
            ClientHandlerRegistry.empty with
                AuthUIHandlers = [ GoogleIdentityRegister.handler ]
                SignOutHandler = Some(GoogleIdentityRegister.signOutHandler googleUi)
        } }
    modules

One Tap is off unless asked for — auto-prompting a deployment's users is a product decision the SDK does not make on its behalf:

let withOneTap = GoogleIdentityUIConfig.withOneTap googleUi

Content-Security-Policy

The library is fetched from accounts.google.com, so a deployment with security hardening on must widen its policy or the button silently never renders — the browser blocks the fetch and the script tag simply errors. Composition, not a hand-edited header, is the supported way:

ServerApp.empty
|> ServerApp.withCspContributor (GoogleIdentityServicesCspContributor())
|> ServerApp.withConfigValidator (
    GoogleIdentityCspValidator.GoogleIdentityCspValidator(serverConfig, services) :> IConfigValidator)

The second line is a preflight: registering it declares "this deployment renders the Google button", and it warns at startup if no contributor covers Google's origins. Nothing on the server can observe a client-tier composition by itself, which is why the registration is explicit — and why a redirect-flow deployment, which needs none of these origins, is never nagged.

What the session is

GIS returns exactly one value: an id_token JWT signed by Google. There is no access token and no refresh token — the credential flow has no token endpoint to exchange against.

The bridge validates the credential's iss / aud / exp (and nonce, when one was configured) and then stores it through OidcTokenStore.persistTokens, i.e. the same slot the redirect flow writes and the same bearer every API request carries. classifyStoredToken, signOut and the pre-expiry refresh timer all operate on the projected OidcUIConfig, so a GIS session and a redirect-flow session are the same session to everything downstream.

Two consequences follow from Google's flow rather than from this code:

  1. The bearer is a real JWT, so classifyStoredToken reports FreshJwt where the Google redirect flow reports OpaqueToken (Google's access tokens are always opaque). The server validates it against Google's JWKS with no extra wiring.
  2. There is no refresh token, so the session cannot be renewed silently. The refresh timer arms as usual, finds nothing to refresh at expiry, and the shell returns to the sign-in screen — a re-prompt roughly hourly. A deployment needing long-lived sessions uses the redirect flow with access_type=offline, which is where Google issues refresh tokens.

Packaging

Client-tier Fable source-in-nupkg: the .fs files ship under fable/ and compile as part of the consumer's Fable project. No npm dependency — the GIS library is loaded at runtime from Google's origin, which is what Google requires for the credential flow.

Product Compatible and additional computed target framework versions.
.NET net10.0 is compatible.  net10.0-android was computed.  net10.0-browser was computed.  net10.0-ios was computed.  net10.0-maccatalyst was computed.  net10.0-macos was computed.  net10.0-tvos was computed.  net10.0-windows was computed. 
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.

NuGet packages

This package is not used by any NuGet packages.

GitHub repositories

This package is not used by any popular GitHub repositories.

Version Downloads Last Updated
0.25.1 0 10/9/2026
0.24.1 68 10/6/2026
0.23.0 99 9/23/2026