Google & Microsoft: sign-in and calendars
Get the keys for Sign in with Google and Microsoft, Google Calendar, Sheets and Outlook — for the website and the app.
This guide is for whoever runs a Deewan server. Two OAuth apps — one at Google, one at Microsoft — switch on everything below, on deewan.io and in the iOS and Android apps at once. The apps use the same keys: sign-in happens on your server, then the phone's secure browser sheet hands the session back to the app through the deewan:// link. Nothing extra is needed for mobile — with one exception: Expo Go (used while developing) can't receive that link, so the buttons explain themselves there instead of starting. Test sign-in in a development build or the store app.
| Feature | Needs | Scopes asked |
|---|---|---|
| Sign in with Google | Google OAuth client | openid email profile |
| Google Calendar sync | Google Calendar API enabled | calendar.events (asked when connecting) |
| Attendance to Google Sheets | Sheets + Drive APIs enabled | drive.file (asked when exporting) |
| Sign in with Microsoft | Microsoft Entra app registration | openid email profile offline_access User.Read |
| Outlook Calendar sync | Same Microsoft app | Calendars.ReadWrite (asked when connecting) |
Deewan asks for the least it can: sign-in requests identity only; calendar and Sheets access are asked for separately, when someone connects them. Refresh tokens are stored encrypted (AES-256-GCM).
Connecting always shows Google's consent screen. Sign-in uses the account picker only, but connecting Calendar or Sheets asks Google for consent every time: Google hands out a refresh token only on that screen, and without one a connection works for an hour and then stops. People may see the screen again when they reconnect — that's expected.
When something fails, people are told why. If Google or Microsoft sends someone back with an error — they cancelled, the account is already linked to another Deewan account, the sign-in expired, a work email isn't verified — Deewan shows that reason in their language instead of silently returning to the page. Unknown errors show a short code to quote to support.
- Open console.cloud.google.com, create a project (for example “Deewan”) and select it.
- APIs & Services → Library: enable Google Calendar API, Google Sheets API and Google Drive API.
- Google Auth Platform → Branding (the OAuth consent screen): app name Deewan, support email, logo, home page
https://deewan.io, privacy policyhttps://deewan.io/en/privacy, termshttps://deewan.io/en/terms, authorised domaindeewan.io, developer contact email. - Audience: user type External. While testing, add your own Google accounts as test users.
- Data access: add the scopes
openid,.../auth/userinfo.email,.../auth/userinfo.profile,.../auth/calendar.eventsand.../auth/drive.file. - Clients → Create client → Web application. Authorised JavaScript origin:
https://deewan.io. Authorised redirect URI:https://deewan.io/api/auth/callback/google. - Copy the Client ID and Client secret into the server's environment (below).
Removing “Google hasn't verified this app”
calendar.events is a sensitive scope, so until Google reviews the app, people see a warning and only test users can connect a calendar (sign-in itself works for everyone once the app is published). To remove it:
- Verify you own
deewan.ioin Google Search Console (a DNS TXT record), with the same Google account that owns the project. - Make sure the home page, privacy policy and terms load publicly and name Deewan; the privacy policy must say how Google data is used (Deewan uses it only to sync the person's own meetings and to create the spreadsheets they ask for).
- Audience → Publish app (from “Testing” to “In production”).
- Verification centre → Prepare for verification: justify each sensitive scope, and record a short video showing the sign-in, the consent screen with the scopes, and where the calendar data appears in Deewan.
- Submit. Review usually takes a few days to a few weeks; Google may email follow-up questions.
Microsoft (sign-in and Outlook)
- Open entra.microsoft.com → Applications → App registrations → New registration.
- Name Deewan. Supported account types: Accounts in any organizational directory and personal Microsoft accounts.
- Redirect URI: platform Web,
https://deewan.io/api/auth/callback/microsoft. Register. - Certificates & secrets → New client secret (24 months). Copy the secret's Value at once — it's shown only this time. Put a reminder in your calendar to replace it before it expires.
- API permissions → Add → Microsoft Graph → Delegated:
openid,profile,email,offline_access,User.Read,Calendars.ReadWrite. - Token configuration → Add optional claim → ID:
email,xms_edov,verified_primary_email,verified_secondary_email(tick “Turn on the Microsoft Graph email permission” if asked). Deewan uses these to know whether Microsoft vouches for a work address. - Branding & properties: logo, home page
https://deewan.io, terms and privacy links. Publisher verification (with a Microsoft AI Cloud Partner Program ID) removes the “unverified” label on the consent screen. - Copy the Application (client) ID from Overview, and the secret value, into the server's environment.
Work and school accounts: the organisation's own admin sets the email address, so Microsoft doesn't always vouch for it. Deewan accepts a Microsoft sign-in as proof of an address only when Microsoft does (personal accounts, or the optional claims above); otherwise it won't join an existing Deewan account or create a new one with that address. Such people sign up with email, then connect Microsoft from Settings.
Putting the keys on the server
GOOGLE_CLIENT_ID=1234567890-abc.apps.googleusercontent.com
GOOGLE_CLIENT_SECRET=GOCSPX-…
MICROSOFT_CLIENT_ID=00000000-0000-0000-0000-000000000000
MICROSOFT_CLIENT_SECRET=…Restart (or redeploy) the server. Each button appears on the website and in the app only once its keys are present — the app asks the server which ones are set up. Check with curl https://deewan.io/api/mobile/providers.
Troubleshooting
| You see | Fix |
|---|---|
redirect_uri_mismatch (Google) · AADSTS50011 (Microsoft) | The redirect URI must be exactly https://deewan.io/api/auth/callback/google or …/microsoft — no trailing slash, https. |
| “Google hasn't verified this app” | Expected until verification (above). Test users can continue through “Advanced”. |
access_denied / “Admin approval required” | The person's organisation blocks new apps. Their IT admin grants consent for Deewan once, for everyone. |
| Microsoft sign-in says the email isn't confirmed | Add the optional claims above; otherwise that account signs up with email and connects Microsoft afterwards. |
| Calendar stops syncing after months (Microsoft) | The client secret expired. Make a new one and update MICROSOFT_CLIENT_SECRET. |
| “This Google account is already connected to a different Deewan account” | That Google account belongs to another Deewan login. Sign in there, disconnect it in Settings → Integrations, then connect it here — or choose another Google account. |
| Export to Sheets asks to connect Google again and again | The Google connection had no refresh token (made before consent was forced). Connect once more; if it repeats, remove Deewan at myaccount.google.com/permissions and connect again. Also check the Google Sheets API is enabled. |
| “Sheets API has not been used / is disabled” | Enable Google Sheets API in the same Google Cloud project, wait a few minutes, try again. |
| Google / Microsoft buttons explain themselves in the app instead of starting | You're in Expo Go. Use a development build or the store app. |