Implementing Google Sign-In in an Android App With Kotlin
Google Sign-In gives Android users a familiar way to access an app without creating another password. A well-designed integration can authenticate a Google account, obtain an identity token, and pass that token to a backend or Firebase Authentication for secure session management.
For modern Android projects, Google recommends Credential Manager rather than the older GoogleSignInClient flow. This approach supports Google accounts alongside passkeys and passwords, making it a practical foundation for new applications targeting users in Sydney, Melbourne, Brisbane, and regional Australia.
Choose The Authentication Architecture
There are two common designs for Google authentication. Firebase Authentication is the quickest option for many tutorial projects because it validates the Google ID token, creates a user record, and maintains the signed-in session. A custom backend is more flexible when the app already uses its own accounts, database, or API gateway.
The Android application should never treat a Google profile name or email address as proof of authentication. It should receive an ID token and send that token over HTTPS to Firebase or your server. The server then verifies the token issuer, audience, expiry time, and subject identifier before creating an application session.
This separation is important for an Australian marketplace, booking app, or community service handling personal information under the Privacy Act and Australian Privacy Principles. Store only the profile details your feature genuinely needs, and explain the collection and use of account data in the app’s privacy notice.
Configure Google Cloud And Firebase
Create or select a project in the Firebase Console, add an Android app, and enter the application’s exact package name. Download google-services.json and place it in the app directory. The package name and signing certificate must match the build you install on a device.
In Firebase Authentication, open the Sign-in providers page and enable Google. Firebase will generate or display the web client ID needed by Credential Manager. During development, add the SHA-1 and SHA-256 fingerprints for your debug keystore. Add the release certificate fingerprints before publishing to Google Play.
The release configuration deserves careful attention. An app installed through Google Play may use Play App Signing, so its certificate fingerprint can differ from the upload key. If the fingerprints do not match, sign-in may work on an emulator but fail in a production build downloaded by a user in Perth or Canberra.
Add Dependencies And A Sign-In Button
Use current AndroidX libraries in the module-level Gradle file. Versions change over time, so check the official release notes before copying a version into a production project.
dependencies {
implementation(platform("com.google.firebase:firebase-bom:VERSION"))
implementation("com.google.firebase:firebase-auth")
implementation("androidx.credentials:credentials:VERSION")
implementation("androidx.credentials:credentials-play-services-auth:VERSION")
}
A simple layout can contain a Button or SignInButton, a progress indicator, and a text view for status messages. Keep the interaction clear: disable the button while the credential request is running, show a useful error, and restore the button when the operation finishes.
For a beginner-friendly walkthrough of Android UI and project structure, these Android tutorials provide useful background on activities, layouts, dialogs, and list-based screens. The sign-in control can then be placed on a welcome screen, account page, or checkout flow without mixing authentication code into the view layout.
Request A Google Credential
Create a CredentialManager instance in the activity or view model. The request uses GetGoogleIdOption, which asks Google Play services to return an ID credential. Replace the placeholder web client ID with the value generated for the Firebase project.
private val credentialManager by lazy {
CredentialManager.create(this)
}
private fun createGoogleRequest(): GetCredentialRequest {
val googleOption = GetGoogleIdOption.Builder()
.setServerClientId(getString(R.string.default_web_client_id))
.setFilterByAuthorizedAccounts(false)
.setAutoSelectEnabled(false)
.build()
return GetCredentialRequest.Builder()
.addCredentialOption(googleOption)
.build()
}
Call the request from a coroutine because credential retrieval is asynchronous. The first attempt may display an account chooser, while a returning user may receive a faster account selection. Setting setFilterByAuthorizedAccounts(false) allows new users to choose an account as well as returning users.
lifecycleScope.launch {
try {
val result = credentialManager.getCredential(
context = this@MainActivity,
request = createGoogleRequest()
)
handleCredential(result.credential)
} catch (error: GetCredentialException) {
showMessage("Google sign-in could not be completed")
}
}
Exchange The Token With Firebase
The returned credential must be converted into a Google ID token. Confirm its type before using it, because Credential Manager can support several credential formats. Then create a Firebase credential and pass it to Firebase Authentication.
private fun handleCredential(credential: Credential) {
if (credential is CustomCredential &&
credential.type == GoogleIdTokenCredential.TYPE_GOOGLE_ID_TOKEN_CREDENTIAL
) {
val googleCredential =
GoogleIdTokenCredential.createFrom(credential.data)
val firebaseCredential = GoogleAuthProvider
.getCredential(googleCredential.idToken, null)
FirebaseAuth.getInstance()
.signInWithCredential(firebaseCredential)
.addOnCompleteListener { task ->
if (task.isSuccessful) {
val user = FirebaseAuth.getInstance().currentUser
showMessage("Welcome ${user?.displayName.orEmpty()}")
} else {
showMessage("Authentication failed")
}
}
}
}
Do not save the ID token in ordinary SharedPreferences, logcat, analytics events, or crash reports. Firebase manages the authenticated session, while your application can observe FirebaseAuth.getInstance().currentUser when the activity starts. A sign-out action should call FirebaseAuth.getInstance().signOut() and clear any app-specific cached data.
If your app has a custom API, obtain the token and send it in an HTTPS request such as Authorization: Bearer <token>. The API must validate it server-side using Google’s supported libraries. A client-side check of the token’s contents is useful for display, but it is not an acceptable security boundary.
Test Error States And User Experience
Test with an emulator and at least one physical Android phone. Check a fresh account, a returning account, cancellation from the account chooser, no network connection, an expired session, and a build signed with the release certificate. Testing on both Wi-Fi and mobile data is worthwhile because users may switch networks while commuting or travelling through regional areas.
Australian users commonly expect short, direct interface messages rather than technical exception text. “Sign-in cancelled” and “Check your connection and try again” are clearer than a raw status code. If the app serves customers across Australian time zones, avoid assuming the device’s locale or clock is UTC when recording account activity.
The following choices help match the implementation to the application’s requirements:
| Approach | Best for | Main advantage | Important consideration |
|---|---|---|---|
| Credential Manager with Firebase | New Android apps and prototypes | Fast setup and managed sessions | Requires correct Firebase and certificate configuration |
| Credential Manager with a custom API | Apps with an existing backend | Full control over users and authorisation | The server must verify every ID token |
| Legacy GoogleSignInClient | Maintaining an older application | Minimal changes to existing code | Less suitable for new projects and future credential features |
| Email and password only | Apps avoiding federated login | Complete control over account creation | Adds password recovery and security responsibilities |
| Google sign-in plus passkeys | Apps requiring several secure options | Flexible experience for returning users | Requires extra UX and credential-state testing |
Before publishing, review the app’s data safety declarations, privacy policy, consent wording, and account deletion process. A dependable Google sign-in flow should leave users with a valid authenticated session, a clear path to sign out, and no unnecessary exposure of identity data. For additional project examples and practical development references, browse mobile project resources alongside the Android implementation.