NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
pub.dev · #284 most downloaded on pub.dev
Obtain Access credentials for Google services using OAuth 2.0
Last release 20 days ago
17 Sep 2026
Ships unpredictably
gaps range from 8 days to 12 months
Nearly every release is documented
notes for 45 of 46 stable releases
Nothing withdrawn
no release was ever pulled
12 years old
50 releases · first in 2014
Added a fallback x-goog-api-client tracking header to AuthenticatedClient , ApiKeyClient , signBlob , and OAuth/STS token requests when not already se
x-goog-api-client tracking header to AuthenticatedClient,ApiKeyClient, signBlob, and OAuth/STS token requests when not already setGOOGLE_CLOUD_QUOTA_PROJECT now takes precedence over a credential's quota_project_id when set.
GOOGLE_CLOUD_QUOTA_PROJECT now takes precedence over a credential'squota_project_id when set.One column per quarter.
Fix web compatibility by removing transitive dart:io and package:google_cloud imports from the core googleapis_auth.dart library.
dart:io andpackage:google_cloud imports from the core googleapis_auth.dart library.Require google_cloud: '>=0.3.0 <0.6.0'
google_cloud: '>=0.3.0 <0.6.0'Added clientViaRefreshToken() function for creating an AutoRefreshingAuthClient directly from a refresh token, ClientId , and scopes.
clientViaRefreshToken() function for creating an AutoRefreshingAuthClient directly from a refresh token, ClientId, and scopes.Require google_cloud: '>=0.3.0 <0.5.0'
google_cloud: '>=0.3.0 <0.5.0'Added quotaProject support to existing credentials classes ( ServiceAccountCredentials , ClientViaServiceAccount , ClientFromFlow ).
quotaProject support to existing credentials classesServiceAccountCredentials, ClientViaServiceAccount, ClientFromFlow).clientViaApplicationDefaultCredentials now extracts quotaProject correctlyclientViaServiceAccountImpersonation and ImpersonatedAuthClient now acceptbaseClient.impersonated_service_accountexternal_account source filesGoogle Security Token Service.quota_project_id forCredentialsFileException and AuthorizationCallbackException classes.Exception, ArgumentError,UnsupportedError) with more specific exception types throughout the package toAuthClientSigningExtension.sign() now accepts an optional serviceAccountEmailsignBlob.AuthClientSigningExtension : Added sign() which accepts an optional serviceAccountCredentials argument, and getServiceAccountEmail() .
AuthClientSigningExtension: Added sign() which accepts an optionalserviceAccountCredentials argument, and getServiceAccountEmail().ServiceAccountCredentials
projectId and universeDomain properties.sign() method for RSA-SHA256 signing.signBlob() function for signing via IAM Credentials API.MetadataServerAuthorizationFlow
getMetadataValue (caching) and fetchMetadataValuepackage:google_cloud.refresh support to run().clientViaServiceAccountImpersonation() function andImpersonatedAuthClient class for service account impersonation via IAMRSAPrivateKey which is exposed by ServiceAccountCredentials.google_cloud: ^0.3.0.meta: ^1.15.0.sdk: ^3.9.0.args dependency.Add serviceAccountCredentials getter to AuthClient
serviceAccountCredentials getter to AuthClientsign() method to ServiceAccountCredentials for RSA-SHA256 signingIAMSigner class for signing via IAM Credentials APIclientViaServiceAccountImpersonation() function and ImpersonatedAuthClient class for service account impersonation via IAM Credentials APIAuthClientSigningExtension extension on AuthClient providing a universal sign() method that works across all auth contexts (service accounts, ADC, impersonated credentials)meta: ^1.0.2sdk: ^3.9.0args dependency.RSAPrivateKey which is exposed by ServiceAccountCredentials.Removed deprecated RefreshFailedException.
RefreshFailedException.auth.dart library.sdk: ^3.6.0auth_browser.dartCodeResponse.
Exports the same class from package:google_identity_serivces_web.Added support for custom post-auth html page
auth_browser.dart: handle pop-up closed errors correctly.
auth_browser.dart: handle pop-up closed errors correctly.Add support for non-Google OAuth 2.0 providers.
google_identity_services_web: ^0.3.0
google_identity_services_web: ^0.3.0http: ^1.0.0- Require Dart 2.19 or later. - Allow latest package:http.
package:http.Deprecated createImplicitBrowserFlow function.
README to include a warning about Flutter application usage.googlapis_auth.dartauthenticatedClient function: added optional bool closeUnderlyingClient
parameter.auth_browser.dart libraryAuthenticationException and use it instead of Exception or
StateError in many cases where authentication can fail.requestAccessCredentials, requestAuthorizationCode, revokeConsent,
and CodeResponse to support the new
Google Identity Services.createImplicitBrowserFlow function.auth_io.dart librarylistenPort parameter to clientViaUserConsent
and obtainAccessCredentialsViaUserConsent.Include plugin_name during browser authorization.
plugin_name during browser authorization.The secret param in ClientId constructor is now optional.
secret param in ClientId constructor is now optional.auth_browser library:
auth2 Javascript API.hostedDomain to all applicable functions.createImplicitBrowserFlow: added (unsupported) enableDebugLogs param.
(Maybe helpful for debugging, but should not be used in production.)auth_io library:
obtainAccessCredentialsViaCodeExchange
scopes are now acquired from the initial API call and not via a separate
API call to the tokeninfo endpoint.codeVerifier parameter.Nothing published for this version
Nothing published for this version
Deprecated RefreshFailedException - ServerRequestFailedException is used instead.
hostedDomain parameter to many functions in
auth_io.dart. If provided, restricts sign-in to Google Apps hosted accounts
at that domain.clientViaApiKey is now exported from googleapis_auth.dart.String? details to UserConsentException.http://metadata/ to http://metadata.google.internal.RefreshFailedException - ServerRequestFailedException is used
instead.It is convention to have the default library within a package align with the package name. auth.dart is now deprecated and will be removed in v2.
googleapis_auth.dart library. It is convention to have the default
library within a package align with the package name. auth.dart is now
deprecated and will be removed in v2.fromJson factory and toJson method to AccessToken,
AccessCredentials, and ClientId.- Add support for null-safety. - Require Dart 2.12 or later.
Nothing published for this version
Add clientViaApplicationDefaultCredentials for obtaining credentials using ADC.
clientViaApplicationDefaultCredentials for obtaining credentials using
ADC.Removed a dart:async import that isn't required for \>=Dart 2.1.
dart:async import that isn't required for >=Dart 2.1.Add the force parameter to the obtainAccessCredentialsViaUserConsent API.
force parameter to the obtainAccessCredentialsViaUserConsent API.Fix 'multiple completer completion' bug in ImplicitFlow.
ImplicitFlow.Look for GCE metadata host in environment under $GCE_METADATA_HOST.
$GCE_METADATA_HOST.Prepare for Uint8List SDK breaking change.
Initialize implicit browser flows statically, allowing multiple ImplicitFlow objects to initialize without trying to load the gapi JavaScript library
Support for specifying desired ResponseType, allowing applications to obtain an id_token using ImplicitBrowserFlow.
ResponseType, allowing applications to obtain
an id_token using ImplicitBrowserFlow.Ignore script loading error after timeout for in-browser implicit login-flow.
Switch all uppercase constants from dart:convert to lowercase.
dart:convert to lowercase.- Support Dart 2.
Support package:http >=0.11.3+17 <0.13.0.
package:http >=0.11.3+17 <0.13.0.Add an optional loginHint parameter to browser oauth2 flow APIs which can be used to specify a hint as to which user is being logged in.
loginHint parameter to browser oauth2 flow APIs which can be
used to specify a hint as to which user is being logged in.Added id_token to AccessCredentials
Added id_token to AccessCredentials
Migrated to Dart 2 BigInt.
Allow ServiceAccountCredentials constructors to take an optional user argument to specify a user to impersonate.
ServiceAccountCredentials constructors to take an optional user
argument to specify a user to impersonate.Nothing published for this version
Use preferred "Metadata-Flavor" HTTP header in MetadataServerAuthorizationFlow instead of the deprecated "X-Google-Metadata-Request" header.
MetadataServerAuthorizationFlow instead of the deprecated
"X-Google-Metadata-Request" header.Support package:crypto >= 0.9.2
Make package strong-mode compliant.
Support the latest version of crypto package.
crypto package.Fix async issue in oauth2 flow implementation
Allow ServiceAccountCredentials.fromJson to accept a Map.
ServiceAccountCredentials.fromJson to accept a Map.README.mdAdded optional force and immediate arguments to runHybridFlow.
force and immediate arguments to runHybridFlow.Renamed forceUserConsent parameter to immediate.
forceUserConsent parameter to immediate.runHybridFlow function to auth_browser, with corresponding
HybridFlowResult class.Add clientViaApiKey functions to auth_io ad auth_browser.
clientViaApiKey functions to auth_io ad auth_browser.- First release.
Your coding agent can read these notes before it upgrades. Set up the MCP server →