Hi,
I work with Google Cloud often, and typically use Ruby to interface with the APIs. Ruby is an official SDK of Google Cloud. However, I prefer these days to things in Crystal if possible (it is all about speed!). However, crystal is not an official SDK of Google.
Well, I was able to write a generator that creates crystal shards from the Google Discovery docs (similar to openSDK specs). This is similar to how almost all the official languages are generated these days. The most recent language (Rust) acknowledges this in the README.
At the moment, there is only one library generated (Cloud Storage), but I am working on generating all the SDKs. Of course, when I say I wrote the code, I really meant that I worked with an AI tool to create it. Thus, it is not idiomatic - but it works… :-)
Please see: GitHub - nbrandaleone-gcp/google-apis-cr: A library (shard) that generates Crystal code for interacting with Google APIs. · GitHub
Nick Brandaleone
really neat idea, generating the shards from the discovery docs is basically how the official clients stay in sync, so that should age well. cloud storage is a solid first one too. auth is usually the fiddly part with these, are you planning to bake in oauth and service account support or leaving that to the user.
I started writing something to handle discovery with my google shard, but as you can see here, I never got anywhere with it.
I had immediate problems to solve and needed to get the Auth, Calendar, Drive, and People APIs working. Since then, I’ve added Gemini, Gmail, Maps, Places, Tasks, Storage, and BigQuery.
Rachel - you are correct that authorization is usually a problem with these types of libraries. For now, I am supporting “Application Default Credentials”, which basically grabs a token at a known location. I am working on service account credentials support, but it has not been fully implemented yet.
3. Authentication Implementation (src/google_apis/auth.cr)
- Resolution Precedence:
$GOOGLE_APPLICATION_CREDENTIALS environment variable.
- Well-known user ADC file:
~/.config/gcloud/application_default_credentials.json (or %APPDATA%/gcloud/... on Windows).
- AuthorizedUserCredentials:
- Exposes
authorization_header ("Bearer <token>").
- Proactive token caching and refresh: refreshes whenever expired or within 60 seconds of expiration.
- Thread- and fiber-safe access via
Mutex.
- Exposes
project_id and quota_project_id.
- Redacts sensitive secrets in
#inspect and #to_s to prevent leakage into logs.
- ServiceAccountCredentials:
- Parses service account JSON metadata.
- Raises
UnsupportedCredentialsTypeError explaining that RS256 JWT signing requires cryptography shards beyond Crystal’s standard library.
- Unit Specs: Mock HTTP server testing resolution, token refresh, caching, and error handling (
spec/google_apis/auth_spec.cr).
Your library was an inspiration to me! You have covered most of the popular services, and it is idiomatic to boot! This library will have fuller coverage of Cloud APIs, but will not be idiomatic due to the AI tool writing most of the code.
Nick
Feel free to borrow mine. I built it into my GCS implementation:
Haven’t gotten around to generalizing it yet because GCS is the only thing I’ve been using ServiceAccounts for.
Thank you. I will see if I can integrate the code next week.
I appreciate it.
Nick