Step by step:
User installs the add-on
Google already knows who the user is
The add-on requests the user’s Google identity token (ScriptApp.getIdentityToken();)
That token is verified on the backend (nextjs, fastapi, etc)
A backend session is created (eg: Supabase)
The user is now authenticated across:
the add-on UI
the backend API
Stripe (for billing)
The scope require to get the id token is:
"oauthScopes": [ "openid"
Check out the details -> https://www.shipaddons.com/docs/features/authentication