Create an OAuth application in Google Cloud Console
Go to APIs & Services → Credentials, create (or select) a project
Configure the OAuth consent screen (User Type: External; set App name, User support email, and Developer contact email; add test users if still in test mode)
Create an OAuth client ID with Application type Web application
Add the authorized redirect URI below and save, then copy the Client ID and Client Secret