Sign in with Google
In short
Turn on Sign in with Google on the Authentication page, create an OAuth client in the Google Cloud Console using the two values Sapilon shows you, then paste the client ID and secret back into Sapilon and publish.
Your app can let people sign in with the Google account they already have, instead of making them invent another password. It takes about ten minutes, and it is a one-time setup.
The arrangement is an exchange between two places. Google needs to know which app is asking and where to send people back to; Sapilon needs the two secrets Google gives you in return. The Authentication page shows you both halves, with the exact values to copy.
Turn it on
Open Explorer → Authentication and tick Sign in with Google. The setup steps appear right underneath, with two values at the top:
- Authorized JavaScript origin — your app’s sign-in address.
- Authorized redirect URI — where Google sends people back to after they approve.
Both have a copy button. You do not have to understand them; you only have to paste them into the right boxes in Google. If they are not shown yet, your project does not have a web address so far — publish to a server first, then come back.
If you moved sign-in to your own web address, you will see two pairs: your own address first, because that is where your app signs people in, and the Sapilon one marked as such underneath. Add both in Google — it accepts several of each, and keeping the Sapilon pair means sign-in still works if you ever move your sign-in address back.
Set it up in Google
You need a Google account. Any Google account works; it does not have to be a paid one, and it does not have to be the account your users will sign in with.
- Open the Google Cloud Console and pick a project, or create one. A Google Cloud “project” is just a folder for settings — it is not related to your Sapilon project.
- Go to APIs & Services → OAuth consent screen. This is the page your users will see when they choose “Sign in with Google”, so fill in your app’s real name, a support email address and your logo. If it says “Test project”, that is what your users will read.
- Go to APIs & Services → Credentials and choose Create credentials → OAuth client ID.
- For application type, pick Web application.
- Paste the origin Sapilon showed you into Authorized JavaScript origins, and the redirect URI into Authorized redirect URIs. They look similar but they are not the same — the redirect URI is longer. If Sapilon showed you two pairs, add both.
- Click Create. Google shows you a Client ID and a Client secret.
Copy both now. Google shows the secret only once; if you lose it you can create another, but you cannot look the old one up again.
Paste them back into Sapilon
Back on the Authentication page, paste the Client ID and Client secret into the two fields and click Save.
The client secret is stored encrypted and is never shown again — not to you, and not on any page. If you need to change it later, use Replace and paste a new one. Remove deletes both values.
Publish
Nothing changes on your live app until you publish. The Google button is added to your sign-in screen as part of publishing, so the next publish is what makes it real.
If you turn Sign in with Google on but do not add the client ID and secret, publishing stops and tells you so, rather than shipping a sign-in screen with a button that cannot work.
Questions people ask
Do I need a separate Google setup for the Rehearsal and Live servers? No. One Google client covers both, because both use the same sign-in address.
Does Sapilon see my Google account? No. The only things that ever reach Sapilon are the client ID and client secret you paste in, and the only place they go is your own app’s sign-in service.
What about Sign in with Apple? Not available yet. Apple’s setup works differently — it uses a key that expires and has to be renewed — so it is being built separately.
Someone signed in with Google — which group are they in? The default group you picked under Groups on the same page, exactly as if they had signed up with an email address.