Sign in with Google
This guide walks you through adding "Sign in with Google" to SupportBot from scratch. Once done, the button can appear on three sign-in screens: Chatwoot (the agent inbox), the Admin Panel, and — optionally — the Dify console. All three use the same Google OAuth client; a single setup on Google's side is enough.
No prior Google Cloud experience needed; it takes about 10 minutes.
1. Create a Google Cloud Project
- Sign in at console.cloud.google.com with your Google account.
- From the project picker in the top bar choose New Project; name it e.g.
SupportBotand hit Create. (An existing project works too.) - Once created, make sure it is selected in the top bar.
2. Configure the OAuth Consent Screen
Before Google can show users the "This app wants access to…" screen, it asks you to describe your app. Done once:
- Left menu → APIs & Services → OAuth consent screen.
- Choose External (the only option unless you use Google Workspace) → Create.
- Fill in the required fields:
- App name:
SupportBot(users see this name on the sign-in screen) - User support email: your email
- Developer contact information: your email
- App name:
- Click through Scopes and the remaining steps with Save and Continue — SupportBot only requests
openid+email, which are not sensitive scopes.
Important — Testing mode: a fresh consent screen starts in Testing status: only Google accounts added under Test users can sign in. You have two options:
- Add your own (and your operators') Gmail addresses to Test users — usually enough for small teams; or
- Publish app to move it to Production. Since
openid/emailare non-sensitive scopes, no Google verification is required and no "unverified app" warning appears.
3. Create an OAuth Client ID
Left menu → APIs & Services → Credentials.
Click + Create Credentials → OAuth client ID.
Application type:
Web application; name: e.g.SupportBot Web.Under Authorized redirect URIs, add BOTH URIs (replace
<your-domain>with your root domain):https://chat.<your-domain>/omniauth/google_oauth2/callback https://dashboard.<your-domain>/api/auth/google/callback https://ai.<your-domain>/console/api/oauth/authorize/googleThese are the return addresses for the Chatwoot, Admin Panel, and Dify console logins respectively. The first two are required; the third is only needed if you also want Google sign-in on the Dify console (step 7). A missing URI makes that screen's sign-in fail with
redirect_uri_mismatch.Hit Create. A dialog shows the Client ID (
....apps.googleusercontent.com) and the Client secret — copy both. (You can also view the secret later on the Credentials page.)
4. Give the Keys to SupportBot
On your server, open infra/.env and fill in the two lines:
GOOGLE_OAUTH_CLIENT_ID=<client-id>.apps.googleusercontent.com
GOOGLE_OAUTH_CLIENT_SECRET=<client-secret>
Then restart the affected services:
cd infra
docker compose up -d chatwoot chatwoot-sidekiq dashboard
That's all — no further configuration. While the keys are empty the buttons never show; fill them in, restart, and both appear.
5. Who Can Sign In?
Google sign-in never creates accounts; it only authenticates existing users:
- Admin Panel: the Google email must match an active operator in the panel's user list. The installation's
ADMIN_EMAILis registered automatically — so ifADMIN_EMAILis a Gmail/Google account, you can sign in right away. - Chatwoot: the Google email must match a user defined in Chatwoot (agent/administrator).
To give a new operator Google sign-in, first add them to the respective system with that email.
6. Try It
- Open
https://dashboard.<your-domain>/login— you should see the "Sign in with Google" button under the form. - Click it and pick your Google account; you are redirected into the panel.
- Verify the same on the
https://chat.<your-domain>sign-in.
Every Google sign-in is written to the audit log (as auth.login_google in the panel).
7. Dify Console (optional)
Dify (ai.<your-domain>) isn't needed day to day; teams that enter it for advanced RAG settings can enable Google there too:
Make sure the third redirect URI from step 3 is registered.
Set
DIFY_ENABLE_SOCIAL_OAUTH_LOGIN=trueininfra/.env(the Google keys were already entered in step 4) and restart Dify:docker compose up -d dify-api dify-webThe Google button appears on the Dify sign-in. The email must match an account registered in Dify — the installation's
ADMIN_EMAILaccount is registered automatically; self-service signup is disabled.
Notes: ai. sits behind Caddy basic-auth (the browser asks once; it doesn't interfere with the Google flow). Dify's flag enables GitHub/Google together; without GitHub keys the GitHub button may show but won't work — ignore it.
Why not full SSO? Dify Community has no OIDC/SSO (an enterprise feature). "Same Google account" gives one identity across all three surfaces; sessions remain separate.
Troubleshooting
| Symptom | Cause / Fix |
|---|---|
Error 400: redirect_uri_mismatch |
One of the two URIs from step 3 is missing, or the domain/protocol doesn't match exactly (https, no www). Open the client under Credentials and check the URIs. |
Access blocked: ... has not completed the verification process |
The app is in Testing mode and the signing-in account is not under Test users. Add the account, or Publish the app (step 2). |
| "This Google account does not match a registered user" | The email is not in the panel's user list. Add the operator with that email (see step 5). |
| The Google button doesn't show | Are both keys filled in infra/.env? Restarted with docker compose up -d dashboard (panel) / chatwoot chatwoot-sidekiq (Chatwoot)? |
| Signed in but bounced back to login | The browser may be blocking cookies; also make sure the server clock is correct (the state cookie is valid for 10 minutes). |