Authenticating and Calling Gemini Models via the Agent Platform GenAI SDK: 3 Methods Explained
The google/skills repository demonstrates how to authenticate with Google Cloud Application Default Credentials and invoke Gemini-2.5-pro through three distinct SDK interfaces: the native Vertex AI SDK, the high-level Gen AI SDK, and an OpenAI-compatible client.
The Agent Platform GenAI SDK provides flexible pathways for integrating Google's foundation models into your applications. This guide examines the reference implementations in the google/skills repository, detailing how to handle authentication via google.auth.default() and execute inference requests using the specific SDK that best fits your architecture.
Authentication Prerequisites
All example scripts follow an identical authentication pattern that leverages Application Default Credentials (ADC). This approach eliminates the need to hardcode secrets or manage token refresh logic manually.
The google.auth.default() function inspects the runtime environment for valid credentials, checking the GOOGLE_APPLICATION_CREDENTIALS environment variable, attached service accounts on Google Cloud compute resources, or user credentials from Cloud Shell and the gcloud CLI. The function returns a tuple containing the credentials object and the project ID, which is required for all subsequent Vertex AI operations.
import google.auth
credentials, project_id = google.auth.default()
Extracting the project_id is critical because Vertex AI resources are project-scoped. All three SDK methods require this identifier to construct the proper API endpoints and billing contexts.
Method 1: Native Vertex AI SDK
The file skills/cloud/agent-platform-inference/scripts/gemini_vertexai_sdk.py demonstrates direct usage of the vertexai package, providing the most native integration with Google Cloud's infrastructure.
First, initialize the Vertex AI service with your project and region. The vertexai.init() function configures the global context for subsequent model operations.
import vertexai
from vertexai.generative_models import GenerativeModel
vertexai.init(project=project_id, location="us-central1")
model = GenerativeModel("gemini-2.5-pro")
response = model.generate_content("Why is the sky blue?")
print(response.text)
This method gives you direct access to Vertex AI-specific features such as grounding, safety filters, and model tuning configurations. Use this approach when you need fine-grained control over the generation parameters or when integrating with other Vertex AI services like Vector Search or Model Registry.
Method 2: Gen AI SDK (High-Level Abstraction)
For developers seeking a simplified interface, skills/cloud/agent-platform-inference/scripts/gemini_genai_sdk.py implements the newer google.genai package. This SDK abstracts away low-level Vertex AI details while maintaining full access to Gemini capabilities.
Initialize the client with enterprise=True to ensure compatibility with the Agent Platform's enterprise features, passing the project ID and location obtained from the authentication step.
from google import genai
client = genai.Client(enterprise=True, project=project_id, location="us-central1")
response = client.models.generate_content(
model="gemini-2.5-pro",
contents="Why is the sky blue?"
)
print(response.text)
The genai.Client handles request serialization, retry logic, and response parsing automatically. This is the recommended approach for new applications that do not require legacy OpenAI compatibility or deep Vertex AI customization.
Method 3: OpenAI-Compatible SDK
When migrating existing applications or maintaining compatibility with OpenAI-centric codebases, skills/cloud/agent-platform-inference/scripts/gemini_openai_sdk.py shows how to wrap Vertex AI endpoints in the OpenAI client interface.
This approach requires manually refreshing the access token from your Google credentials, as the OpenAI client does not natively understand Google's authentication flows.
import google.auth.transport.requests
import openai
def get_gcp_access_token():
creds, _ = google.auth.default()
creds.refresh(google.auth.transport.requests.Request())
return creds.token
client = openai.OpenAI(
base_url=f"https://aiplatform.googleapis.com/v1/projects/{project_id}/locations/us-central1/endpoints/openapi",
api_key=get_gcp_access_token(),
)
response = client.chat.completions.create(
model="google/gemini-2.5-pro",
messages=[{"role": "user", "content": "Why is the sky blue?"}],
)
print(response.choices[0].message.content)
Use this method when you need to drop Gemini models into existing OpenAI integrations without refactoring your application's chat completion logic.
Comparing the Three Approaches
Each SDK targets different architectural requirements:
- Vertex AI SDK (
gemini_vertexai_sdk.py): Best for Google Cloud-native applications requiring advanced Vertex AI features like custom model tuning or integrated grounding services. - Gen AI SDK (
gemini_genai_sdk.py): Ideal for new development requiring clean, minimal code with enterprise-grade retry and authentication handling. - OpenAI-Compatible SDK (
gemini_openai_sdk.py): Essential for migration scenarios or multi-provider abstraction layers where maintaining the OpenAI function signature is mandatory.
All three methods support the same underlying Gemini-2.5-pro model and utilize identical authentication mechanisms via google.auth.default().
Summary
- Application Default Credentials eliminate secret management by automatically detecting service accounts or user credentials in the Google Cloud environment.
- The Vertex AI SDK provides native access to Google Cloud's full generative AI feature set through
vertexai.init()andGenerativeModel. - The Gen AI SDK offers the cleanest abstraction for new applications via
genai.Client(enterprise=True). - The OpenAI-compatible client enables drop-in replacement for existing OpenAI integrations by routing requests to Vertex AI endpoints with refreshed access tokens.
- All implementations require the project ID extracted from
google.auth.default()and target theus-central1region in the provided examples.
Frequently Asked Questions
How does Application Default Credentials handle token refresh?
The google.auth.default() function returns credentials that automatically refresh when used with Google client libraries. For the OpenAI-compatible approach, you must manually call creds.refresh(google.auth.transport.requests.Request()) before each request or implement a wrapper that checks token expiration, as shown in skills/cloud/agent-platform-inference/scripts/gemini_openai_sdk.py.
Which SDK provides the best performance for high-throughput applications?
The Gen AI SDK and Vertex AI SDK both offer equivalent underlying performance since they communicate with the same Vertex AI endpoints. The Gen AI SDK includes built-in retry logic and connection pooling optimizations that make it preferable for production workloads, while the OpenAI-compatible layer introduces minimal latency overhead for request translation.
Can I use these methods with models other than Gemini-2.5-pro?
Yes. While the examples specifically use gemini-2.5-pro, you can substitute other Gemini model versions such as gemini-1.5-pro or gemini-1.5-flash by changing the model string in the GenerativeModel constructor, the client.models.generate_content() call, or the OpenAI model parameter respectively.
What authentication options exist outside of Application Default Credentials?
While the google/skills examples exclusively use ADC, the underlying SDKs support explicit credential passing via the credentials parameter in vertexai.init() or by constructing a custom google.auth.credentials.Credentials object. However, ADC remains the recommended approach for security and portability across Google Cloud environments.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →