How to Authenticate the Gemini Interactions API with Application Default Credentials (ADC)

Use google.auth.default() to load OAuth 2.0 credentials from your environment, refresh the token for SDKs that require explicit authentication, and pass that token to the Gemini client—while the Vertex AI SDK handles this automatically when initialized with your project ID.

The google/skills repository provides production-ready reference implementations demonstrating how to authenticate Gemini Interactions API requests using Application Default Credentials (ADC). This pattern leverages the google-auth library to automatically discover valid credentials whether you are developing locally with user credentials or deploying on Google Cloud infrastructure with service accounts.

How ADC Authentication Works with the Gemini Interactions API

When you invoke google.auth.default(), the library returns a credentials object and your Google Cloud project ID according to the source code in google/skills. The Gemini Interactions API accepts a bearer token derived from these credentials. Depending on your SDK choice, you either pass this token explicitly to the client constructor or allow the SDK to manage the authentication layer transparently.

Method 1: Vertex AI SDK (Automatic ADC Handling)

The Vertex AI SDK streamlines authentication by automatically utilizing ADC when you initialize the client with your project ID. In skills/cloud/agent-platform-inference/scripts/gemini_vertexai_sdk.py, the implementation loads credentials via google.auth.default() and passes the project ID to vertexai.init():

import google.auth
import vertexai
from vertexai.generative_models import GenerativeModel

# Load ADC and project ID

_, project_id = google.auth.default()

# Initialize Vertex AI with the project

vertexai.init(project=project_id, location="us-central1")

# Create the Gemini model

model = GenerativeModel("gemini-2.5-pro")

# Generate a response

response = model.generate_content("Why is the sky blue?")
print(response.text)

This approach requires no manual token refresh because the Vertex AI SDK manages the OAuth 2.0 token lifecycle internally.

Method 2: OpenAI-Compatible SDK (Manual Token Refresh)

When using the OpenAI-compatible SDK to call the Gemini Interactions API, you must manually refresh the ADC token and supply it as the api_key. The reference implementation in skills/cloud/agent-platform-inference/scripts/gemini_openai_sdk.py demonstrates this explicit pattern:

import google.auth
import google.auth.transport.requests
import openai

# Load ADC

creds, _ = google.auth.default()

# Refresh to obtain an access token

creds.refresh(google.auth.transport.requests.Request())
access_token = creds.token

# Load the project ID for the endpoint URL

_, project_id = google.auth.default()

# Configure the OpenAI client to talk to Vertex AI

client = openai.OpenAI(
    base_url=f"https://aiplatform.googleapis.com/v1/projects/{project_id}/locations/us-central1/endpoints/openapi",
    api_key=access_token,
)

# Call Gemini via the OpenAI interface

response = client.chat.completions.create(
    model="google/gemini-2.5-pro",
    messages=[{"role": "user", "content": "Why is the sky blue?"}],
)
print(response.choices[0].message.content)

The critical step is calling creds.refresh(google.auth.transport.requests.Request()) to generate a valid OAuth 2.0 access token before initializing the client.

Method 3: GenAI SDK (Enterprise ADC Configuration)

The newer GenAI SDK also leverages ADC but requires explicit enterprise configuration. As shown in skills/cloud/agent-platform-inference/scripts/gemini_genai_sdk.py, you initialize the client with enterprise=True and pass the project ID obtained from google.auth.default():

from google import genai
import google.auth

# Load ADC and project ID

_, project_id = google.auth.default()

# Initialize the GenAI client (Vertex AI backend)

client = genai.Client(enterprise=True, project=project_id, location="us-central1")

# Generate content with Gemini

response = client.models.generate_content(
    model="gemini-2.5-pro", contents="Why is the sky blue?"
)
print(response.text)

Summary

  • Application Default Credentials automatically discover valid credentials for your environment via google.auth.default(), whether running locally or on Google Cloud.
  • Vertex AI SDK handles ADC authentication automatically when you call vertexai.init(project=project_id, location="us-central1") with the project ID from google.auth.default().
  • OpenAI-compatible SDK requires manual token refresh using creds.refresh(google.auth.transport.requests.Request()) before passing the token to the api_key parameter.
  • GenAI SDK uses ADC with explicit enterprise configuration via genai.Client(enterprise=True, project=project_id).
  • Reference implementations are available in the google/skills repository under skills/cloud/agent-platform-inference/scripts/ and additional configuration guidance is provided in skills/cloud/gemini-interactions-api/SKILL.md.

Frequently Asked Questions

What is the difference between using ADC with Vertex AI SDK versus the OpenAI-compatible SDK?

The Vertex AI SDK automatically manages the OAuth 2.0 token lifecycle when you call vertexai.init(), while the OpenAI-compatible SDK requires you to manually refresh the token using creds.refresh(google.auth.transport.requests.Request()) and pass it explicitly as the api_key parameter to the client constructor.

How do I refresh the ADC token when using the OpenAI-compatible client?

Call creds.refresh(google.auth.transport.requests.Request()) on the credentials object returned by google.auth.default(), then access the token string via creds.token and supply it to the OpenAI client constructor as shown in skills/cloud/agent-platform-inference/scripts/gemini_openai_sdk.py.

Can I use ADC authentication on local development machines?

Yes. ADC works on local workstations by reading credentials obtained via the gcloud auth application-default login command, local credential files, or environment variables, allowing the same authentication code to run both locally and in production without modification.

Which SDK requires manual token refresh when authenticating the Gemini Interactions API?

Only the OpenAI-compatible SDK requires manual token refresh. Both the Vertex AI SDK and the GenAI SDK handle credential refreshing automatically when initialized with the project ID from google.auth.default().

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →