DeewanDocs
API keys

Google & Microsoft: sign-in and calendars

Get the keys for Sign in with Google and Microsoft, Google Calendar, Sheets and Outlook — for the website and the app.

This guide is for whoever runs a Deewan server. Two OAuth apps — one at Google, one at Microsoft — switch on everything below, on deewan.io and in the iOS and Android apps at once. The apps use the same keys: sign-in happens on your server, then the phone's secure browser sheet hands the session back to the app through the deewan:// link. Nothing extra is needed for mobile — with one exception: Expo Go (used while developing) can't receive that link, so the buttons explain themselves there instead of starting. Test sign-in in a development build or the store app.

FeatureNeedsScopes asked
Sign in with GoogleGoogle OAuth clientopenid email profile
Google Calendar syncGoogle Calendar API enabledcalendar.events (asked when connecting)
Attendance to Google SheetsSheets + Drive APIs enableddrive.file (asked when exporting)
Sign in with MicrosoftMicrosoft Entra app registrationopenid email profile offline_access User.Read
Outlook Calendar syncSame Microsoft appCalendars.ReadWrite (asked when connecting)

Deewan asks for the least it can: sign-in requests identity only; calendar and Sheets access are asked for separately, when someone connects them. Refresh tokens are stored encrypted (AES-256-GCM).

Connecting always shows Google's consent screen. Sign-in uses the account picker only, but connecting Calendar or Sheets asks Google for consent every time: Google hands out a refresh token only on that screen, and without one a connection works for an hour and then stops. People may see the screen again when they reconnect — that's expected.

When something fails, people are told why. If Google or Microsoft sends someone back with an error — they cancelled, the account is already linked to another Deewan account, the sign-in expired, a work email isn't verified — Deewan shows that reason in their language instead of silently returning to the page. Unknown errors show a short code to quote to support.

Google

  • Open console.cloud.google.com, create a project (for example “Deewan”) and select it.
  • APIs & Services → Library: enable Google Calendar API, Google Sheets API and Google Drive API.
  • Google Auth Platform → Branding (the OAuth consent screen): app name Deewan, support email, logo, home page https://deewan.io, privacy policy https://deewan.io/en/privacy, terms https://deewan.io/en/terms, authorised domain deewan.io, developer contact email.
  • Audience: user type External. While testing, add your own Google accounts as test users.
  • Data access: add the scopes openid, .../auth/userinfo.email, .../auth/userinfo.profile, .../auth/calendar.events and .../auth/drive.file.
  • Clients → Create client → Web application. Authorised JavaScript origin: https://deewan.io. Authorised redirect URI: https://deewan.io/api/auth/callback/google.
  • Copy the Client ID and Client secret into the server's environment (below).

Removing “Google hasn't verified this app”

calendar.events is a sensitive scope, so until Google reviews the app, people see a warning and only test users can connect a calendar (sign-in itself works for everyone once the app is published). To remove it:

  • Verify you own deewan.io in Google Search Console (a DNS TXT record), with the same Google account that owns the project.
  • Make sure the home page, privacy policy and terms load publicly and name Deewan; the privacy policy must say how Google data is used (Deewan uses it only to sync the person's own meetings and to create the spreadsheets they ask for).
  • Audience → Publish app (from “Testing” to “In production”).
  • Verification centre → Prepare for verification: justify each sensitive scope, and record a short video showing the sign-in, the consent screen with the scopes, and where the calendar data appears in Deewan.
  • Submit. Review usually takes a few days to a few weeks; Google may email follow-up questions.

Microsoft (sign-in and Outlook)

  • Open entra.microsoft.com → Applications → App registrations → New registration.
  • Name Deewan. Supported account types: Accounts in any organizational directory and personal Microsoft accounts.
  • Redirect URI: platform Web, https://deewan.io/api/auth/callback/microsoft. Register.
  • Certificates & secrets → New client secret (24 months). Copy the secret's Value at once — it's shown only this time. Put a reminder in your calendar to replace it before it expires.
  • API permissions → Add → Microsoft Graph → Delegated: openid, profile, email, offline_access, User.Read, Calendars.ReadWrite.
  • Token configuration → Add optional claim → ID: email, xms_edov, verified_primary_email, verified_secondary_email (tick “Turn on the Microsoft Graph email permission” if asked). Deewan uses these to know whether Microsoft vouches for a work address.
  • Branding & properties: logo, home page https://deewan.io, terms and privacy links. Publisher verification (with a Microsoft AI Cloud Partner Program ID) removes the “unverified” label on the consent screen.
  • Copy the Application (client) ID from Overview, and the secret value, into the server's environment.

Work and school accounts: the organisation's own admin sets the email address, so Microsoft doesn't always vouch for it. Deewan accepts a Microsoft sign-in as proof of an address only when Microsoft does (personal accounts, or the optional claims above); otherwise it won't join an existing Deewan account or create a new one with that address. Such people sign up with email, then connect Microsoft from Settings.

Putting the keys on the server

Environment (never commit these)
GOOGLE_CLIENT_ID=1234567890-abc.apps.googleusercontent.com
GOOGLE_CLIENT_SECRET=GOCSPX-…
MICROSOFT_CLIENT_ID=00000000-0000-0000-0000-000000000000
MICROSOFT_CLIENT_SECRET=…

Restart (or redeploy) the server. Each button appears on the website and in the app only once its keys are present — the app asks the server which ones are set up. Check with curl https://deewan.io/api/mobile/providers.

Troubleshooting

You seeFix
redirect_uri_mismatch (Google) · AADSTS50011 (Microsoft)The redirect URI must be exactly https://deewan.io/api/auth/callback/google or …/microsoft — no trailing slash, https.
“Google hasn't verified this app”Expected until verification (above). Test users can continue through “Advanced”.
access_denied / “Admin approval required”The person's organisation blocks new apps. Their IT admin grants consent for Deewan once, for everyone.
Microsoft sign-in says the email isn't confirmedAdd the optional claims above; otherwise that account signs up with email and connects Microsoft afterwards.
Calendar stops syncing after months (Microsoft)The client secret expired. Make a new one and update MICROSOFT_CLIENT_SECRET.
“This Google account is already connected to a different Deewan account”That Google account belongs to another Deewan login. Sign in there, disconnect it in Settings → Integrations, then connect it here — or choose another Google account.
Export to Sheets asks to connect Google again and againThe Google connection had no refresh token (made before consent was forced). Connect once more; if it repeats, remove Deewan at myaccount.google.com/permissions and connect again. Also check the Google Sheets API is enabled.
“Sheets API has not been used / is disabled”Enable Google Sheets API in the same Google Cloud project, wait a few minutes, try again.
Google / Microsoft buttons explain themselves in the app instead of startingYou're in Expo Go. Use a development build or the store app.