# Google provider inventory Verified read-only on 2026-08-28 against the authenticated Google Cloud and Firebase consoles, the local Dev `.env`, the installed Test and Prod `.env` files over SSH, and the repository environment validators. No secret values were read into this document. This is an inventory, not a source of secrets. ## Environment contract Who Need Help has exactly three deployment environments: | Environment | Public origin | Android build/package | Google project | | --- | --- | --- | --- | | Dev | `https://whoneedhelp.imalto.site` | `development` / `org.whoneedhelp.mobile.development` | `Who Need Help Development` / `who-need-help-development` / `299749044449` | | Test | `https://test.whoneedhelp.com` | `staging` / `org.whoneedhelp.mobile.staging` | `Who Need Help Staging` / `who-need-help-staging` / `340523338913` | | Prod | `https://whoneedhelp.com` | `release` / `org.whoneedhelp.mobile` | `Who Need Help Production` / `who-need-help-production` / `184178014037` | `staging` is only the existing Google display name and Android build/package label for **Test**. It is not a fourth environment. Reuse the three project IDs above; do not create another Google Cloud or Firebase project for these environments. The repository enforces this mapping in [`scripts/validate-android-environment.sh`](../scripts/validate-android-environment.sh). The installed runtime identifiers match the table: Dev points to `who-need-help-development`, Prod points to `who-need-help-production`, and Test has its own Web OAuth client while all Firebase/FCM values remain empty. ## Current registrations ### Dev - [Google OAuth clients](https://console.cloud.google.com/auth/clients?project=who-need-help-development) - Web: `Who Need Help Development Web` (`299749044449-j364ndp46h83r6mmtrj2qrlleas05an0.apps.googleusercontent.com`) - origin: `https://whoneedhelp.imalto.site` - callback: `https://whoneedhelp.imalto.site/auth/google/callback` - Android: `Who Need Help Development Android` (`299749044449-e39l1h560kot97bj2mjjat70or2sn00n.apps.googleusercontent.com`) - [Firebase project](https://console.firebase.google.com/project/who-need-help-development/settings/general): Spark, shown as `No-cost ($0/month)` at verification time. - Firebase Android app: `Who Need Help Development`, package `org.whoneedhelp.mobile.development`, app ID `1:299749044449:android:284bfd48e072ca29e307a0`. - [IAM service accounts](https://console.cloud.google.com/iam-admin/serviceaccounts?project=who-need-help-development): - `wnh-dev-fcm-sender@who-need-help-development.iam.gserviceaccount.com` is enabled for FCM HTTP v1; - the Firebase Admin SDK service account exists and has no user-managed key. ### Test - [Google OAuth clients](https://console.cloud.google.com/auth/clients?project=who-need-help-staging) - Web: `Who Need Help Staging Web` (`340523338913-8qjj8vtnamq44mtl7eg5fv60o8cfnts5.apps.googleusercontent.com`) - origin: `https://test.whoneedhelp.com` - callback: `https://test.whoneedhelp.com/auth/google/callback` - Android: `Who Need Help Staging Android` (`340523338913-4634ev1onnv8a5q092pncpocj9smfvvg.apps.googleusercontent.com`), package `org.whoneedhelp.mobile.staging`. - Firebase is not connected to `who-need-help-staging`; the current Firebase project list contains only Dev and Prod. - [IAM service accounts](https://console.cloud.google.com/iam-admin/serviceaccounts?project=who-need-help-staging): no service accounts were present, so Test has no FCM sender registration. - The Google Cloud project has a billing account linked. The console showed `$0.00` estimated charges for 2026-08-01 through 2026-08-28; this observation is not a pricing guarantee. - The Web OAuth client also contains the old callback `https://staging.whoneedhelp.com/auth/google/callback`. It is not part of the three-environment contract. Do not rely on or remove it until the owner explicitly chooses the cleanup. ### Prod - [Google OAuth clients](https://console.cloud.google.com/auth/clients?project=who-need-help-production) - Web: `Who Need Help Production Web` (`184178014037-elt40fdgum1umln6440fgmb6h7o7dskr.apps.googleusercontent.com`) - origin: `https://whoneedhelp.com` - callback: `https://whoneedhelp.com/auth/google/callback` - Android clients: `Who Need Help Android Upload`, `Who Need Help Android Play RSA 1`, `Who Need Help Android Play RSA 2`, and `Who Need Help Android Play ML-DSA`. - [Firebase project](https://console.firebase.google.com/project/who-need-help-production/settings/general): Spark, shown as `No-cost ($0/month)` at verification time. - Firebase Android app: `Who Need Help Production`, package `org.whoneedhelp.mobile`, app ID `1:184178014037:android:18b3996444c3bebce361dc`. - [IAM service accounts](https://console.cloud.google.com/iam-admin/serviceaccounts?project=who-need-help-production): - `who-need-help-fcm@who-need-help-production.iam.gserviceaccount.com` is enabled for FCM HTTP v1; - the Firebase Admin SDK service account exists and has no user-managed key. - [Google Play app](https://play.google.com/console/u/0/developers/5283023225403815420/app/4972430103169452589/app-dashboard) is the production Android application. - Four Android OAuth clients currently exist while the local Play identity inventory records three Play signing identities. The purpose of the fourth client has not been verified; do not delete or merge any of them based only on their similar names. ## Configuration ownership Each checkout keeps one ignored `.env`. Provider secrets must remain there or in the ignored provider files consumed by the import scripts; never copy them into this document or commit them. | Capability | Runtime configuration | | --- | --- | | Web Google sign-in | `GOOGLE_OAUTH_CLIENT_ID`, `GOOGLE_OAUTH_CLIENT_SECRET` | | Android Google sign-in | `GOOGLE_OAUTH_AUTHORIZED_PARTY_IDS` | | Public Firebase Android config | four `WNH_FIREBASE_*` values | | Server-side FCM | `FCM_PROJECT_ID` and exactly one service-account source | | Android App Links | `ANDROID_APP_LINKS_PACKAGE_NAME`, `ANDROID_APP_LINKS_SHA256_CERT_FINGERPRINTS` | Relevant validated importers: - [`scripts/import-firebase-android-config.sh`](../scripts/import-firebase-android-config.sh) - [`scripts/import-fcm-service-account.sh`](../scripts/import-fcm-service-account.sh) - [`scripts/import-play-android-config.sh`](../scripts/import-play-android-config.sh) The Dev and Prod FCM sender accounts being present proves registration only; delivery still requires the matching environment configuration and an actual device smoke test. Test currently has OAuth but no Firebase/FCM registration. The ignored `tmp/environment-access/*.env` files are historical snapshots, not live configuration. In particular, its old Dev snapshot still references the historical `who-need-help-dev-firebase` setup and must not be used to recreate or overwrite the current Dev configuration. ## Do not recreate - Do not create a fourth environment called Staging. - Do not create another Firebase project for Dev or Prod. - Do not place OAuth client secrets, Firebase API keys, service-account JSON, private keys, or key IDs in documentation. - Do not delete an OAuth client, callback, Firebase app, fingerprint, or service account until its active environment and signing identity have been verified.