Google OAuth API provides an easy and powerful way to integrate the login system on the website. Google Login API allows the user to sign in to the website using their Google account without signing up on that website. The Google login system definitely helps to increase the number of subscribers on your website. Nowadays, almost all users have a Google account, and they can log in with their Google account without registering on your website.
Google login is one of the easiest ways to let users sign in to a PHP website without creating and remembering another username and password. With Google Identity Services (GIS), your website can display Google’s official Sign in with Google button, receive a Google ID token, verify that token on the server, and create a local login session.
Web developers can easily implement the login and registration system in a web application using Google OAuth 2.0 and PHP. In this tutorial, we will build a complete Login with Google using PHP and MySQL system using the current Google Identity Services JavaScript library.
The implementation uses:
Google recommends using the ID token’s sub claim as the stable unique identifier for a Google account rather than using the email address as the account identifier.
Before we start, let’s take a look at the file structure of the project:
login_with_google_account_using_php/ ├── config.php ├── index.php ├── login.php ├── logout.php ├── vendor/ │ └── ... └── style.css
The responsibilities of each file are as follows:
config.php: Contains the Google Client ID and database configuration.index.php: Displays the Google Sign-In button and handles the user interface for login and logout.login.php: Handles the server-side verification of the Google ID token and manages the user session using PHP.logout.php: Handles the user logout process and destroys the session.vendor/: Contains the Composer dependencies, including the Google API PHP Client library.style.css: Contains the CSS styles for the login page.The authentication flow in this example is:
The important part is that the browser does not decide whether the Google credential is valid. The credential is sent to login.php, where it is verified on the server using Google’s PHP client.
Google Identity Services returns a JWT ID token after the user signs in, and Google’s documentation recommends verifying that ID token on the server before using the account information for authentication.
Google Identity Services requires an OAuth 2.0 client ID. Google also uses the client ID when verifying the ID token on your backend.
To create a Google Cloud project and obtain a Web Client ID. Follow these steps:
https://www.example.com.123456789012-abcdefghijklmnopqrstuvwxyz.apps.googleusercontent.com
config.php.To install the Google API PHP Client, you can use Composer. Run the following command in your project’s root directory:
composer require google/apiclient
Composer installs the Google API PHP Client and creates the vendor/ directory containing the Composer autoloader.
Note that if you don’t have Composer, you can download our source code and use it directly without installing the Google API PHP Client library. All the dependencies are already included in the vendor directory.
You need a MySQL database to store user information. Create a database and a users table that will hold the user information retrieved from Google account. You can use the following SQL commands to create the users table:
CREATE TABLE users (
id BIGINT UNSIGNED NOT NULL AUTO_INCREMENT,
google_sub VARCHAR(255) NOT NULL,
email VARCHAR(320) NOT NULL,
email_verified TINYINT(1) NOT NULL DEFAULT 0,
name VARCHAR(255) NULL,
given_name VARCHAR(255) NULL,
family_name VARCHAR(255) NULL,
picture_url TEXT NULL,
gender VARCHAR(50) NULL,
locale VARCHAR(20) NULL,
hosted_domain VARCHAR(255) NULL,
created_at TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP,
updated_at TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP ON UPDATE CURRENT_TIMESTAMP,
PRIMARY KEY (id),
UNIQUE KEY uq_users_google_sub (google_sub),
KEY idx_users_email (email)
) ENGINE=InnoDB DEFAULT CHARSET=utf8mb4;
The config.php file contains the Google Client ID and database configuration.
GOOGLE_CLIENT_ID) to the value you obtained from the Google Cloud Console.DB_HOST, DB_NAME, DB_USER, DB_PASSWORD) according to your MySQL setup.There are also a helper function database() that establishes a connection to the MySQL database using the MySQLi extension. The function returns a mysqli object that can be used for executing queries.
<?php
// Enable strict mode for type checking
declare(strict_types=1);
// Google Client ID for OAuth 2.0 authentication
const GOOGLE_CLIENT_ID = 'YOUR_GOOGLE_CLIENT_ID.apps.googleusercontent.com';
// Database configuration
const DB_HOST = 'localhost';
const DB_NAME = 'google_login_db';
const DB_USER = 'root';
const DB_PASSWORD = '';
// Start the session to manage user authentication state
if (session_status() === PHP_SESSION_NONE) {
session_start();
}
// Helper function for database connection
function database(): mysqli
{
mysqli_report(MYSQLI_REPORT_ERROR | MYSQLI_REPORT_STRICT);
$database = new mysqli(DB_HOST, DB_USER, DB_PASSWORD, DB_NAME);
$database->set_charset('utf8mb4');
return $database;
}
// Helper function to convert special characters to HTML entities for safe output
function e(mixed $value): string
{
return htmlspecialchars((string) ($value ?? ''), ENT_QUOTES, 'UTF-8');
}
?>
Create an index.php file that will handle the user-facing part of the authentication process. This page displays the Sign in with Google button and handles the Google Sign-In process. The page also checks if the user is already logged in by checking the session variable $_SESSION['google_user']. If the user is logged in, it displays their profile information; otherwise, it shows the Google Sign-In button.
Authenticated Google user’s information: Check if the user is logged in by verifying if the session variable $_SESSION['google_user'] is set to determine if the user is already logged in.
<?php
// Enable strict mode for type checking
declare(strict_types=1);
// Include the configuration file
require __DIR__ . '/config.php';
// Retrieve the user information from the session
$user = $_SESSION['google_user'] ?? null;
?>
Display Google Login Button: If the $user variable is null, it means the user is not logged in. In this case, the page displays the Google Sign-In button using the Google Identity Services JavaScript library. Otherwise, it shows the user’s profile information (Profile picture, Name, Email, Email verification status, Given name, Family name, Gender, Locale, Hosted domain, Google subject ID, etc.) and a logout button.
<?php if ($user === null): ?>
<!-- Display the Google Sign-In button if the user is not logged in -->
<section class="panel login-panel" aria-labelledby="login-title">
<div class="panel-mark">G</div>
<h2 id="login-title">Sign in to continue</h2>
<p class="muted">Your verified Google profile will be saved to the local database.</p>
<div id="google-button" class="google-button"></div>
<p id="status" class="status" role="status"></p>
</section>
<?php else: ?>
<!-- Display the user's profile information if logged in -->
<section class="panel profile-panel" aria-labelledby="profile-title">
<div class="profile-header">
<?php if (!empty($user['picture'])): ?>
<img class="avatar" src="<?= e($user['picture']) ?>" alt="Profile picture">
<?php else: ?>
<div class="avatar avatar-fallback"><?= e(strtoupper(substr($user['name'] ?: $user['email'], 0, 1))) ?></div>
<?php endif; ?>
<div>
<p class="eyebrow">Signed in successfully</p>
<h2 id="profile-title"><?= e($user['name'] ?: $user['email']) ?></h2>
</div>
</div>
<dl class="profile-grid">
<div><dt>Email</dt><dd><?= e($user['email']) ?></dd></div>
<div><dt>Email verified</dt><dd><?= $user['email_verified'] ? 'Yes' : 'No' ?></dd></div>
<div><dt>Given name</dt><dd><?= e($user['given_name'] ?: 'Not provided') ?></dd></div>
<div><dt>Family name</dt><dd><?= e($user['family_name'] ?: 'Not provided') ?></dd></div>
<div><dt>Gender</dt><dd><?= e($user['gender'] ?: 'Not provided by Google') ?></dd></div>
<div><dt>Locale</dt><dd><?= e($user['locale'] ?: 'Not provided') ?></dd></div>
<div><dt>Hosted domain</dt><dd><?= e($user['hd'] ?: 'Personal account') ?></dd></div>
<div><dt>Google subject ID</dt><dd class="breakable"><?= e($user['sub']) ?></dd></div>
</dl>
<a class="sign-out" href="logout.php">Sign out</a>
</section>
<?php endif; ?>
JavaScript for Google Sign-In: The JavaScript code initializes the Google Identity Services library, renders the Google Sign-In button, and handles the credential response. When the user successfully signs in with Google, the ID token is sent to the login.php backend for verification and session creation.
<?php if ($user === null): ?>
<!-- Load the Google Identity Services library -->
<script src="https://accounts.google.com/gsi/client" async defer></script>
<!-- JavaScript to handle the Google Sign-In button and credential response -->
<script>
function handleCredentialResponse(response) {
const status = document.getElementById('status');
status.textContent = 'Checking your Google account...';
const formData = new FormData();
formData.append('credential', response.credential);
fetch('login.php', { method: 'POST', body: formData, credentials: 'same-origin' })
.then((result) => result.json())
.then((result) => {
if (!result.success) {
throw new Error(result.message || 'Sign-in failed.');
}
window.location.reload();
})
.catch((error) => {
status.textContent = error.message;
});
}
window.addEventListener('load', () => {
google.accounts.id.initialize({
client_id: <?= json_encode(GOOGLE_CLIENT_ID, JSON_HEX_TAG | JSON_HEX_AMP | JSON_HEX_APOS | JSON_HEX_QUOT) ?>,
callback: handleCredentialResponse,
use_fedcm_for_button: true
});
google.accounts.id.renderButton(document.getElementById('google-button'), {
theme: 'outline',
size: 'large',
text: 'continue_with',
shape: 'rectangular',
width: 320
});
});
</script>
<?php endif; ?>
Create a login.php file that will handle the server-side verification of the Google ID token and manages the user session using PHP. It performs the following tasks:
<?php
// Enable strict mode for type checking
declare(strict_types=1);
// Loads Composer and application configuration
require __DIR__ . '/vendor/autoload.php';
require __DIR__ . '/config.php';
// Set the response content type to JSON
header('Content-Type: application/json; charset=utf-8');
// Check if the request method is POST
if ($_SERVER['REQUEST_METHOD'] !== 'POST') {
http_response_code(405);
echo json_encode(['success' => false, 'message' => 'POST requests only.']);
exit;
}
// Retrieve the Google credential from the POST data
$credential = $_POST['credential'] ?? '';
if (!is_string($credential) || $credential === '') {
http_response_code(400);
echo json_encode(['success' => false, 'message' => 'Google credential is missing.']);
exit;
}
try {
// Verify the Google ID token using the Google Client library
$googleClient = new Google\Client(['client_id' => GOOGLE_CLIENT_ID]);
$payload = $googleClient->verifyIdToken($credential);
if ($payload === false || empty($payload['sub']) || empty($payload['email'])) {
throw new RuntimeException('The Google ID token could not be verified.');
}
// Store or update the user information in the database
$database = database();
$statement = $database->prepare(
'INSERT INTO users
(google_sub, email, email_verified, name, given_name, family_name, picture_url, gender, locale, hosted_domain)
VALUES (?, ?, ?, ?, ?, ?, ?, ?, ?, ?)
ON DUPLICATE KEY UPDATE
email = VALUES(email),
email_verified = VALUES(email_verified),
name = VALUES(name),
given_name = VALUES(given_name),
family_name = VALUES(family_name),
picture_url = VALUES(picture_url),
gender = VALUES(gender),
locale = VALUES(locale),
hosted_domain = VALUES(hosted_domain)'
);
$googleSub = (string) $payload['sub'];
$email = (string) $payload['email'];
$emailVerified = !empty($payload['email_verified']) ? 1 : 0;
$name = $payload['name'] ?? null;
$givenName = $payload['given_name'] ?? null;
$familyName = $payload['family_name'] ?? null;
$pictureUrl = $payload['picture'] ?? null;
$gender = $payload['gender'] ?? null;
$locale = $payload['locale'] ?? null;
$hostedDomain = $payload['hd'] ?? null;
$statement->bind_param(
'ssisssssss',
$googleSub,
$email,
$emailVerified,
$name,
$givenName,
$familyName,
$pictureUrl,
$gender,
$locale,
$hostedDomain
);
$statement->execute();
// Store the user information in the session for later use
$_SESSION['google_user'] = [
'sub' => $googleSub,
'email' => $email,
'email_verified' => $emailVerified,
'name' => $name,
'given_name' => $givenName,
'family_name' => $familyName,
'picture' => $pictureUrl,
'gender' => $gender,
'locale' => $locale,
'hd' => $hostedDomain,
];
echo json_encode(['success' => true]);
} catch (Throwable $exception) {
error_log($exception->getMessage());
http_response_code(500);
echo json_encode(['success' => false, 'message' => 'Sign-in could not be completed.']);
}
?>
Create a logout.php file that will handle the user logout process. It destroys the session and redirects the user back to the login page (index.php). The logout process is straightforward and ensures that the user’s session is properly terminated, preventing unauthorized access to protected resources using PHP SESSION.
<?php
// Enable strict mode for type checking
declare(strict_types=1);
// Start the session and clear all session data to log the user out
session_start();
$_SESSION = [];
// If the session uses cookies, delete the session cookie by setting its expiration time in the past
if (ini_get('session.use_cookies')) {
$parameters = session_get_cookie_params();
setcookie(session_name(), '', time() - 42000, $parameters['path'], $parameters['domain'], $parameters['secure'], $parameters['httponly']);
}
// Destroy the session to log the user out
session_destroy();
header('Location: index.php');
exit;
?>
In this tutorial, we created a complete Login with Google using PHP and MySQL implementation using Google Identity Services. The system allows users to log in to your website using their Google account without the need for creating a new username and password. We have covered the entire process, including setting up the Google Cloud project, creating the MySQL database, implementing the frontend and backend logic, and managing user sessions.
The most important part of the implementation is the server-side verification of the Google ID token. Once the token is verified, the application can safely use the returned Google account information to create or update the local user account.
If you want to implement a more traditional registration and login system with PHP and MySQL, you can refer to the following tutorial for a secure implementation:
Looking for expert assistance to implement or extend this script’s functionality? Submit a Service Request
💰 Budget-friendly • 🌍 Global clients • 🚀 Production-ready solutions
Hi i would like to check the session whether user is logged in or not. How could i identify ??? So that i can use this login in my website for user login.
Thanks in Advance
Is there an easy way to “remember me on this computer” so the login with stay logged in after the browser is closed and re-opened?
?where to get google-api-php-client
Download the source code, all the required files including Google API PHP client library are included in it.
Hi , I just used your code and its working as expected. Thanks for the nice work!
My question is instead of redirecting to another tab for google account verification is there any way to do it in a popup somehow ?
Thanks in advance.
Yes possible, use Google JavaScript API instead of PHP OAuth Library. See this tutorial to integrate Google login without page redirect – https://www.codexworld.com/login-with-google-account-using-javascript/
I had to replace this code because Google + API is turning off.
This tutorial is the updated version of Google OAuth with PHP and the script does not use the Google+ API. See this tutorial and download the source code to integrate Google Sign-in authentication on your website without any dependencies on Google+ API. Since, the Google+ Sign-in feature has been fully deprecated, migrate it to the Google Sign-in authentication system right now.
Hello, can I get some help to work on iOS for the browser embedded webview? we use it on a wifi login platform (Hotspot) and we need it.
Hello we have a Wi-Fi platform, we use to login with Google, however, in access with iOS in embedded browsers does not work, this is our main use, we received a message from Google User Agent not allowed, there is something in What can we do to make this work? I believe I’m something on user_agent, thank you
Google no longer allow OAuth requests to Google in embedded browsers known as “web-views”.
where l can download de folder scr
You don’t need to download it separately, all the required files are included in the source code.
That code works perfectly. Thank you so much!
how we can retrieve mobile number ??
Its awesome tutorial with video and app demo, easily to understand and now try to implement
Hello your all code always works super
Great article, thanks. Is there a way to limit to a certain domain? I want to use google auth login for users using google apps with custom domain. Is there a way to capture the email address on my php form first and if domain matches then pass it to google to process the authentication and send it back to my application?
Great tutorial, thanks for sharing.
Great tutorial. Works perfectly. Much clearer than the explanationn from the guys @ Google.
Many thanks
hello Codexworld ..
I want to use above your googleplus login code in my web …so how i can implement it on sign up/sign form. so please ha
Thanks in advanc
Where can i find the source code package for get all libraries ?
You can get the source code by the download link at end of the tutorial.
Codexworld you are awesome dude this is very useful form me i was searching for this from last 30 days finally i got it thanks men
Sir i want to redirect to my website when user get login please help me how to do this thanks in advance
Great tutorials thanks.
How can i set this for multiple users of google.
Current this is use for only single user.
really its being helpful
how to get these from google libraries
src/
Google API, Google Client, Google Oauth and other libraries
—–
and
—-
can I insert id from another table?
You will find all Google API libraries in the source code package.
thank you nice post.with your code it’s working i am signing to google+. how i can sign with google to my application sir..
How to synchronize both facebook login and google login from same website?
Hi sir , I am implementing this in Zend framework and it is not working in zend. There is 404 page not found error when request redirect to my project. So can you please help me or provide it for zend framework also ….
where i can download the libraries? Google API, Google Client, Google Oauth and other libraries?
All required libraries can be found in our source code.
Great tutorial thanks
Great One thank you so much
Great tutorial, thx!
Is there any easy way to get data from youtube account when logging?
Very nice tutorial,
Thanks for providing this.
i want to combine facebook , linkedin and google auth login code using php …. Plz help me
WELL DONE ! This is the only script work very well
Although initially had received Error: redirect_uri_mismatch result does not include the slash at the end of Google Credential’s Authorized redirect URIs
http://localhost/login-with-google-api-using-php/
So I add a slash and all went smoothly
Thanx you CodexWorld it’s help me alot…
Good job! But how to customize the button? I’d like to implement this in Angular Material, on a button of the Framework.
Good Job. I like this…
that really great post (y)
Hi, great handy script. Any ideas on how I can limit access based on a domain?
nice tutorial!
I want to get mobile number from google and facebook profile using your code
Nice
Good Tutorial.
But need some more introduction for implementation for new developers.
Hello there,
Great tutorial thanks, but is there a way to accept only accept login from users from a specific hosted domain?
Thanks!
Tom
Is it necessary to have live domain/ website to do this ??
I am developing a website that would require to use login with gmail account but it’s not on live server . Is there any way i can do this from my local host ??
@Pritesh You can test Google Account login script on localhost. Use localhost as a domain name in Authorized redirect URIs fields (http://localhost/login-with-google-api-using-php) at Google Developers Console.