How to Authenticate the Gemini Interactions API with Application Default Credentials (ADC)
Use google.auth.default() to load OAuth 2.0 credentials from your environment, refresh the token for SDKs that require explicit authentication, and pass that token to the Gemini client—while the Vertex AI SDK handles this automatically when initialized with your project ID.
The google/skills repository provides production-ready reference implementations demonstrating how to authenticate Gemini Interactions API requests using Application Default Credentials (ADC). This pattern leverages the google-auth library to automatically discover valid credentials whether you are developing locally with user credentials or deploying on Google Cloud infrastructure with service accounts.
How ADC Authentication Works with the Gemini Interactions API
When you invoke google.auth.default(), the library returns a credentials object and your Google Cloud project ID according to the source code in google/skills. The Gemini Interactions API accepts a bearer token derived from these credentials. Depending on your SDK choice, you either pass this token explicitly to the client constructor or allow the SDK to manage the authentication layer transparently.
Method 1: Vertex AI SDK (Automatic ADC Handling)
The Vertex AI SDK streamlines authentication by automatically utilizing ADC when you initialize the client with your project ID. In skills/cloud/agent-platform-inference/scripts/gemini_vertexai_sdk.py, the implementation loads credentials via google.auth.default() and passes the project ID to vertexai.init():
import google.auth
import vertexai
from vertexai.generative_models import GenerativeModel
# Load ADC and project ID
_, project_id = google.auth.default()
# Initialize Vertex AI with the project
vertexai.init(project=project_id, location="us-central1")
# Create the Gemini model
model = GenerativeModel("gemini-2.5-pro")
# Generate a response
response = model.generate_content("Why is the sky blue?")
print(response.text)
This approach requires no manual token refresh because the Vertex AI SDK manages the OAuth 2.0 token lifecycle internally.
Method 2: OpenAI-Compatible SDK (Manual Token Refresh)
When using the OpenAI-compatible SDK to call the Gemini Interactions API, you must manually refresh the ADC token and supply it as the api_key. The reference implementation in skills/cloud/agent-platform-inference/scripts/gemini_openai_sdk.py demonstrates this explicit pattern:
import google.auth
import google.auth.transport.requests
import openai
# Load ADC
creds, _ = google.auth.default()
# Refresh to obtain an access token
creds.refresh(google.auth.transport.requests.Request())
access_token = creds.token
# Load the project ID for the endpoint URL
_, project_id = google.auth.default()
# Configure the OpenAI client to talk to Vertex AI
client = openai.OpenAI(
base_url=f"https://aiplatform.googleapis.com/v1/projects/{project_id}/locations/us-central1/endpoints/openapi",
api_key=access_token,
)
# Call Gemini via the OpenAI interface
response = client.chat.completions.create(
model="google/gemini-2.5-pro",
messages=[{"role": "user", "content": "Why is the sky blue?"}],
)
print(response.choices[0].message.content)
The critical step is calling creds.refresh(google.auth.transport.requests.Request()) to generate a valid OAuth 2.0 access token before initializing the client.
Method 3: GenAI SDK (Enterprise ADC Configuration)
The newer GenAI SDK also leverages ADC but requires explicit enterprise configuration. As shown in skills/cloud/agent-platform-inference/scripts/gemini_genai_sdk.py, you initialize the client with enterprise=True and pass the project ID obtained from google.auth.default():
from google import genai
import google.auth
# Load ADC and project ID
_, project_id = google.auth.default()
# Initialize the GenAI client (Vertex AI backend)
client = genai.Client(enterprise=True, project=project_id, location="us-central1")
# Generate content with Gemini
response = client.models.generate_content(
model="gemini-2.5-pro", contents="Why is the sky blue?"
)
print(response.text)
Summary
- Application Default Credentials automatically discover valid credentials for your environment via
google.auth.default(), whether running locally or on Google Cloud. - Vertex AI SDK handles ADC authentication automatically when you call
vertexai.init(project=project_id, location="us-central1")with the project ID fromgoogle.auth.default(). - OpenAI-compatible SDK requires manual token refresh using
creds.refresh(google.auth.transport.requests.Request())before passing the token to theapi_keyparameter. - GenAI SDK uses ADC with explicit enterprise configuration via
genai.Client(enterprise=True, project=project_id). - Reference implementations are available in the
google/skillsrepository underskills/cloud/agent-platform-inference/scripts/and additional configuration guidance is provided inskills/cloud/gemini-interactions-api/SKILL.md.
Frequently Asked Questions
What is the difference between using ADC with Vertex AI SDK versus the OpenAI-compatible SDK?
The Vertex AI SDK automatically manages the OAuth 2.0 token lifecycle when you call vertexai.init(), while the OpenAI-compatible SDK requires you to manually refresh the token using creds.refresh(google.auth.transport.requests.Request()) and pass it explicitly as the api_key parameter to the client constructor.
How do I refresh the ADC token when using the OpenAI-compatible client?
Call creds.refresh(google.auth.transport.requests.Request()) on the credentials object returned by google.auth.default(), then access the token string via creds.token and supply it to the OpenAI client constructor as shown in skills/cloud/agent-platform-inference/scripts/gemini_openai_sdk.py.
Can I use ADC authentication on local development machines?
Yes. ADC works on local workstations by reading credentials obtained via the gcloud auth application-default login command, local credential files, or environment variables, allowing the same authentication code to run both locally and in production without modification.
Which SDK requires manual token refresh when authenticating the Gemini Interactions API?
Only the OpenAI-compatible SDK requires manual token refresh. Both the Vertex AI SDK and the GenAI SDK handle credential refreshing automatically when initialized with the project ID from google.auth.default().
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →