How YouTube credentials are configured today

This guide documents the existing Google Cloud OAuth configuration for a YouTube Data API client in the codebase. It clarifies how credentials are named and why no user-facing feature is currently active despite the client's existence.

  1. 1 What exists today

    A complete YouTube Data API v3 client already exists in this codebase, covering channel info, listing channel videos, and updating video metadata, plus YouTube Analytics reporting. Nothing currently calls this client; there is no route, worker, or UI component that invokes it. Consequently, setting up these credentials does not yet turn on a visible feature for end users.

  2. 2 The shared Google Cloud OAuth client

    This deployment uses one Google Cloud OAuth 2.0 client for every Google surface rather than one client per feature. This design choice is made because an OAuth client is not scoped to a single API at token-request time; the specific capabilities depend on the scopes granted to the refresh token. The client identifiers are named for Ads because that was the original reason the client was created, but any Google surface can use them as the default.

  3. 3 An optional override just for YouTube

    If you want YouTube to use a different OAuth client than the shared default, you can set GOOGLE_YOUTUBE_CLIENT_ID and GOOGLE_YOUTUBE_CLIENT_SECRET. The code checks for these YouTube-specific environment variables first and only falls back to the shared Ads client if they are unset. This allows for independent management of YouTube credentials without affecting other Google integrations.

  4. 4 Set the API key and refresh token

    Public channel and video data reads use a plain API key, while channel-owner actions require a refresh token. The refresh token must be obtained through Google's OAuth consent flow for the YouTube upload scope and is tied to the Google Cloud OAuth client described in the previous step. These two values serve distinct purposes: the API key for public data access and the refresh token for authenticated channel management.

  5. 5 One refresh token means one channel for the whole deployment

    The refresh token acts as a single, deployment-wide identity. Whichever Google account produced the token determines the YouTube channel that all workspace calls act as. There is no per-workspace YouTube identity mechanism in this codebase today, meaning all users interact with the same underlying channel identity.

Next

Status: reviewed · reviewed by gemini-3.8-flash