Google Chat (Chat API)
Delivery: Official add-on. Google Chat in Fased is an HTTP-only integration. The gateway verifies Google-signed webhook requests, routes DMs and spaces into the normal session model, and sends replies through the Chat API using your service account. Status: supported for DMs and spaces through Google Chat webhooks. Google Chat is an official optional add-on. Install it from Agent > Channels, onboarding, or the CLI before entering credentials:Quick setup (beginner)
Only the Google Chat webhook path should be public. Keep the dashboard and the rest of the gateway private behind Tailscale, your reverse proxy, or another access boundary.- Create a Google Cloud project and enable the Google Chat API.
- Go to: Google Chat API Credentials
- Enable the API if it is not already enabled.
- Create a Service Account:
- Press Create Credentials > Service Account.
- Name it whatever you want (e.g.,
fased-chat). - Leave permissions blank (press Continue).
- Leave principals with access blank (press Done).
- Create and download the JSON Key:
- In the list of service accounts, click on the one you just created.
- Go to the Keys tab.
- Click Add Key > Create new key.
- Select JSON and press Create.
- Store the downloaded JSON file on your gateway host (e.g.,
~/.fased/googlechat-service-account.json). - Create a Google Chat app in the
Google Cloud Console Chat Configuration:
- Fill in the Application info:
- App name: (e.g.
Fased) - Avatar URL: (e.g.
https://example.com/logo.png) - Description: (e.g.
Personal AI Assistant)
- App name: (e.g.
- Enable Interactive features.
- Under Functionality, check Join spaces and group conversations.
- Under Connection settings, select HTTP endpoint URL.
- Under Triggers, select Use a common HTTP endpoint URL for all
triggers and set it to your gateway’s public URL followed by
/googlechat.- Tip: Run
fased statusto find your gateway’s public URL.
- Tip: Run
- Under Visibility, check Make this Chat app available to specific people and groups in <Your Domain>.
- Enter your email address (e.g.
[email protected]) in the text box. - Click Save at the bottom.
- Fill in the Application info:
- Enable the app status:
- After saving, refresh the page.
- Look for the App status section (usually near the top or bottom after saving).
- Change the status to Live - available to users.
- Click Save again.
- Open Agents, select the Agent, then use Agent > Channels > Google
Chat to configure the service account path + webhook audience:
- Env:
GOOGLE_CHAT_SERVICE_ACCOUNT_FILE=/path/to/service-account.json - Or config:
channels.googlechat.serviceAccountFile: "/path/to/service-account.json".
- Env:
- Set the webhook audience type + value (matches your Chat app config).
- Start or restart the gateway if the UI asks for it. Google Chat will POST to your webhook path.
Add to Google Chat
Once the gateway is running and your email is added to the visibility list:- Go to Google Chat.
- Click the + (plus) icon next to Direct Messages.
- In the search bar, type the App name you configured in Google Cloud.
- Private apps do not appear in the public Marketplace browse list. Search for the app by name.
- Select your bot from the results.
- Click Add or Chat to start a 1:1 conversation.
- Send “Hello” to trigger the assistant!
Public URL (Webhook-only)
Google Chat webhooks require a public HTTPS endpoint. Expose only the/googlechat path to the internet. Keep the Fased dashboard and other
sensitive endpoints on your private network.
Option A: Tailscale Funnel (Recommended)
Use Tailscale Serve for the private dashboard and Funnel for the public webhook path. This keeps/ private while exposing only /googlechat.
-
Check what address your gateway is bound to:
Note the IP address (e.g.,
127.0.0.1,0.0.0.0, or your Tailscale IP like100.x.x.x). -
Expose the dashboard to the tailnet only (port 8443):
-
Expose only the webhook path publicly:
- Authorize the node for Funnel access: If prompted, visit the authorization URL shown in the output to enable Funnel for this node in your tailnet policy.
-
Verify the configuration:
https://<node-name>.<tailnet>.ts.net/googlechat
Your private dashboard stays tailnet-only:
https://<node-name>.<tailnet>.ts.net:8443/
Use the public URL (without :8443) in the Google Chat app config.
Note: This configuration persists across reboots. To remove it later, runtailscale funnel resetandtailscale serve reset.
Option B: Reverse Proxy (Caddy)
If you use a reverse proxy like Caddy, only proxy the specific path:your-domain.com/googlechat is routed to Fased and the rest
of the domain stays outside the gateway route.
Option C: Cloudflare Tunnel
Configure your tunnel’s ingress rules to only route the webhook path:- Path:
/googlechat->http://localhost:18789/googlechat - Default Rule: HTTP 404 (Not Found)
How it works
- Google Chat sends webhook POSTs to the gateway. Each request includes an
Authorization: Bearer <token>header. - Fased verifies the token against the configured
audienceType+audience:audienceType: "app-url"→ audience is your HTTPS webhook URL.audienceType: "project-number"→ audience is the Cloud project number.
- Messages are routed by space:
- DMs use session key
agent:<agentId>:googlechat:dm:<spaceId>. - Spaces use session key
agent:<agentId>:googlechat:group:<spaceId>.
- DMs use session key
- DM access is pairing by default. Unknown senders receive a pairing code.
Approve with:
fased pairing approve googlechat <code>
- Group spaces require @-mention by default. Use
botUserif mention detection needs the app’s user name.
Targets
Use these identifiers for delivery and allowlists:- Direct messages:
users/<userId>(recommended). - Raw email
[email protected]is mutable. It is only used for direct allowlist matching whenchannels.googlechat.dangerouslyAllowNameMatching: true. - Deprecated:
users/<email>is treated as a user id, not an email allowlist. - Spaces:
spaces/<spaceId>.
Config highlights
- Service account credentials can also be passed inline with
serviceAccount(JSON string). serviceAccountRefis also supported as an env/file SecretRef, including per-account refs underchannels.googlechat.accounts.<id>.serviceAccountRef.- Default webhook path is
/googlechatifwebhookPathisn’t set. dangerouslyAllowNameMatchingre-enables mutable email principal matching for allowlists. Treat it as compatibility mode.- Reactions are available via the
reactionstool andchannels actionwhenactions.reactionsis enabled. typingIndicatorsupportsnone,message(default), andreaction. Reaction typing requires user OAuth.- Attachments are downloaded through the Chat API and stored in the media
pipeline, capped by
mediaMaxMb.
Troubleshooting
405 Method Not Allowed
If Google Cloud Logs Explorer shows errors like:-
Channel not configured: The
channels.googlechatsection is missing from your config. Verify with:If it returns “Config path not found”, add the configuration (see Config highlights). - Runtime not loaded: Google Chat is a bundled channel extension. If Agent > Channels shows restart required after saving credentials, restart the gateway so the runtime registers the webhook handler.
-
Gateway not restarted: after adding config, restart the gateway:
Other issues
- Check
fased channels status --probefor auth errors or missing audience config. - If no messages arrive, confirm the Chat app’s webhook URL and event subscriptions.
- If mention gating blocks replies, set
botUserto the app’s user resource name and verifyrequireMention. - Use
fased logs --followwhile sending a test message to see if requests reach the gateway.