<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Authentication on Marketing Toolbox</title><link>https://marketing-toolbox.org/auth/</link><description>Recent content in Authentication on Marketing Toolbox</description><generator>Hugo</generator><language>en</language><atom:link href="https://marketing-toolbox.org/auth/index.xml" rel="self" type="application/rss+xml"/><item><title>Desktop OAuth setup</title><link>https://marketing-toolbox.org/auth/desktop-oauth/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://marketing-toolbox.org/auth/desktop-oauth/</guid><description>&lt;h1 id="desktop-oauth-setup"&gt;Desktop OAuth setup&lt;a class="anchor" href="#desktop-oauth-setup"&gt;&lt;/a&gt;&lt;/h1&gt;&#10;&lt;p&gt;Use a Google Cloud &lt;strong&gt;Desktop app&lt;/strong&gt; client for native OAuth. The CLI owns its loopback callback; do not create a Web application or enter redirect URIs.&lt;/p&gt;&#10;&lt;h2 id="configure-a-cloud-project"&gt;Configure a Cloud project&lt;a class="anchor" href="#configure-a-cloud-project"&gt;&lt;/a&gt;&lt;/h2&gt;&#10;&lt;ol&gt;&#10;&lt;li&gt;&lt;a href="https://console.cloud.google.com/projectcreate"&gt;Create or select a Cloud project&lt;/a&gt;.&lt;/li&gt;&#10;&lt;li&gt;In the &lt;a href="https://console.cloud.google.com/apis/library"&gt;API Library&lt;/a&gt;, enable only the APIs you need:&#10;&lt;ul&gt;&#10;&lt;li&gt;&lt;a href="https://console.cloud.google.com/apis/library/analyticsdata.googleapis.com"&gt;Google Analytics Data API&lt;/a&gt; for &lt;code&gt;ga4datactl&lt;/code&gt;.&lt;/li&gt;&#10;&lt;li&gt;&lt;a href="https://console.cloud.google.com/apis/library/analyticsadmin.googleapis.com"&gt;Google Analytics Admin API&lt;/a&gt; for &lt;code&gt;ga4adminctl&lt;/code&gt;.&lt;/li&gt;&#10;&lt;li&gt;&lt;a href="https://console.cloud.google.com/apis/library/tagmanager.googleapis.com"&gt;Tag Manager API&lt;/a&gt; for &lt;code&gt;gtmctl&lt;/code&gt;.&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;/li&gt;&#10;&lt;li&gt;In &lt;a href="https://console.developers.google.com/auth/overview"&gt;Google Auth Platform&lt;/a&gt;, complete &lt;strong&gt;Branding&lt;/strong&gt; with an app name, support email, and contact email.&lt;/li&gt;&#10;&lt;li&gt;Under &lt;strong&gt;Audience&lt;/strong&gt;, choose &lt;strong&gt;External&lt;/strong&gt; for a personal project or users outside a Google Workspace organization. Choose &lt;strong&gt;Internal&lt;/strong&gt; only for eligible organization-only users. For an External app in &lt;strong&gt;Testing&lt;/strong&gt;, add each signing-in account as a test user.&lt;/li&gt;&#10;&lt;li&gt;Under &lt;strong&gt;Data Access&lt;/strong&gt;, add only the scope or scopes for the access tiers you will use. The &lt;a href="https://marketing-toolbox.org/auth/#credential-precedence"&gt;authentication guide&lt;/a&gt; lists the exact tiers and scopes.&lt;/li&gt;&#10;&lt;/ol&gt;&#10;&lt;p&gt;External Testing refresh tokens can expire after seven days. Personal testing does not require verification or publishing the app to Production.&lt;/p&gt;</description></item></channel></rss>