> For the complete documentation index, see [llms.txt](https://doc.duaer.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://doc.duaer.com/troubleshooting/google-oauth-invalid-grant.md).

# Fix Google invalid_grant and 7-day token expiry in Duaer

When a Gmail, Google Sheets, or Google Drive credential in Duaer fails with invalid_grant after a few days, the Google app is usually still in Testing. Publish it and reconnect.
## Why Duaer shows invalid_grant

The error is usually invalid_grant or Token has been expired or revoked. Duaer tried to swap its refresh token for a new one and Google refused. Common causes:

- The OAuth app in Google Cloud has publishing status Testing, so refresh tokens for external users expire after 7 days. This is the most common cause.
- The Google account changed its password, or removed the app on its security page.
- The same account authorized the same client too many times, and the oldest token was revoked.

## Fix it in Duaer

1. Open Google Cloud console and select the project your Duaer credential uses.
2. Open Audience under Google Auth Platform (OAuth consent screen in the older console) and select Publish app so the status reads In production.
3. Back in Duaer, open the credential, select Sign in with Google, and save.
4. Run the affected digital organizations with Execute step, then publish them again.

After publishing, Google may show an unverified app notice. You can continue for yourself and your team; offering restricted scopes such as Gmail to many outside users needs Google app verification. Full setup: [Google OAuth credentials in Duaer](/integrations/builtin/credentials/google/oauth-single-service.md).
## Questions

### Why does my Duaer Google credential need a new sign-in every 7 days?

The OAuth app in Google Cloud is still in Testing, so external refresh tokens expire after 7 days. Publish it to In production and reconnect once in Duaer.

### After reconnecting a Duaer credential, do I edit every node?

No. Duaer nodes point to the same credential, so every node using it works after you sign in again and save.

## Related

- [Set up Google OAuth2 single service credentials in Duaer](https://doc.duaer.com/integrations/builtin/credentials/google/oauth-single-service.md)
- [Send mail with Gmail in Duaer](https://doc.duaer.com/build/gmail.md)
- [Read rows with Google Sheets in Duaer](https://doc.duaer.com/build/google-sheets.md)
- [Fix Google Sheets 429 quota exceeded in Duaer](https://doc.duaer.com/troubleshooting/google-sheets-429-quota-exceeded.md)

