Switching from Gemini API to Vertex AI Integration
I have a Node.js application that formerly used the pure Gemini API. I switched to using the Vertex AI integration.
In order to achieve this, you need to set up your environment to use Application Default Credentials (ADC) and specify your Google Cloud project ID.
#!/bin/bash
export GOOGLE_CLOUD_PROJECT=<my-project-id>
bash <(curl -sSL \
https://storage.googleapis.com/cloud-samples-data/adc/setup_adc.sh)
Then it stores the service credentials in a file:
${HOME}/.config/gcloud/application_default_credentials.json
Which contains:
{
"account": "",
"client_id": "....apps.googleusercontent.com",
"client_secret": "...",
"quota_project_id": "gen-lang-client-0123456",
"refresh_token": "1//OlP1frQqGdZVykkPbFRWzVUBo1s",
"type": "authorized_user",
"universe_domain": "googleapis.com"
}
Then you can use the following code to generate content using the Vertex AI integration:
const {GoogleGenAI} = require('@google/genai');
const GOOGLE_CLOUD_PROJECT = process.env.GOOGLE_CLOUD_PROJECT;
const GOOGLE_CLOUD_LOCATION = process.env.GOOGLE_CLOUD_LOCATION || 'global';
async function generateContent(
projectId = GOOGLE_CLOUD_PROJECT,
location = GOOGLE_CLOUD_LOCATION
) {
const client = new GoogleGenAI({
vertexai: true, // This enables Vertex AI integration
project: projectId,
location: location,
});
const response = await client.models.generateContent({
model: 'gemini-3-flash-preview',
contents: 'How does AI work?',
});
console.log(response.text);
return response.text;
}
How Token Renewal is Managed?
The renewal process is handled automatically by Google's underlying authentication libraries (google-auth-library) without requiring any additional code or manual intervention
Automatic Token Refresh on Request:
- OAuth access tokens used by Google APIs are short-lived (usually expiring after 1 hour).
- Every time you run your TypeScript code and call client.models.generateContent(...), the SDK loads the credentials from the ADC JSON file.
- The library automatically exchanges the long-lived refresh_token for a fresh access_token by calling Google's OAuth 2.0 token endpoint.
- Even if you do not run your script for weeks, the SDK will transparently request a new access token the moment you invoke the function.
When might the refresh_token itself expire?
While access tokens refresh automatically, the underlying refresh_token can become invalid if:
- You changed your Google Account password.
- You manually revoked access for the Google Cloud SDK / Google Auth in your Google Account security settings.
- Your organization's Google Workspace session policies enforce maximum token lifetimes or session re-authentication.
- The refresh token remains unused for an extended period (typically 6 months).
What to do if the credentials ever expire?
If the refresh token itself is invalidated, the SDK will throw an invalid_grant or authentication error.
To re-authorize, simply run:
gcloud auth application-default login
Or re-run your setup script: This will open a browser window to authenticate and update your application_default_credentials.json with a new refresh token.