Explore Technology Practical Guides Mac Smart Home Resume Projects Search the site
Smart Home

Homebridge Google Nest SDM Setup (2026 Edition)

April 27, 2023 Freddy Reyes

Set up Homebridge-Nest with a Google account so Nest devices can appear in Apple HomeKit with a cleaner smart-home workflow.

Homebridge Google Nest SDM Setup (2026 Edition)

Important Update (2026)

Google has changed parts of the Device Access setup process since this guide was originally published. If you’re configuring Homebridge today, there are several additional steps that are required to receive real-time updates from your Nest devices.

This article has been updated with the latest setup process, including Google Cloud Pub/Sub, OAuth scopes, and common troubleshooting steps.


Understanding the Three Google Projects

One of the biggest sources of confusion is that Google uses three different components.

ComponentPurpose
Device Access ProjectGives access to your Nest devices
Google Cloud ProjectHosts Pub/Sub topics and subscriptions
OAuth ClientAuthenticates Homebridge

These are related, but they are not the same thing.


Enable the Smart Device Management API

Enable the following API inside your Google Cloud project:

  • Smart Device Management API

Also enable:

  • Cloud Pub/Sub API

Both are required.


Configure Pub/Sub

Real-time thermostat updates rely on Google Cloud Pub/Sub.

Create a Topic

Create a topic named:

nest

The resulting topic should look like:

projects/YOUR_GCP_PROJECT/topics/nest

Grant Permissions

The Nest Device Access service needs permission to publish messages.

Grant the following principal access:

sdm-publisher@googlegroups.com

Role:

Pub/Sub Publisher

Enable the Topic

Open the Google Device Access Console.

Locate Pub/Sub Topic.

Enter:

projects/YOUR_GCP_PROJECT/topics/nest

After validation, the topic should show as Enabled.


Create a Pull Subscription

Next, create a subscription.

Recommended settings:

Subscription ID

nest-homebridge

Delivery Type

Pull

The full subscription path will be similar to:

projects/YOUR_GCP_PROJECT/subscriptions/nest-homebridge

OAuth Authentication

When generating the authorization code, request both OAuth scopes.

https://www.googleapis.com/auth/sdm.service

and

https://www.googleapis.com/auth/pubsub

Example authorization URL:

https://nestservices.google.com/partnerconnections/DEVICE_ACCESS_PROJECT_ID/auth?redirect_uri=https://www.google.com&access_type=offline&prompt=consent&client_id=YOUR_CLIENT_ID&response_type=code&scope=https://www.googleapis.com/auth/sdm.service+https://www.googleapis.com/auth/pubsub

After approving access, Google redirects to:

https://www.google.com/?code=...

Copy the authorization code.

Exchange it for a refresh token using Google’s OAuth token endpoint.


Homebridge Configuration

Your configuration should contain something similar to:

{
  "platform": "homebridge-google-nest-sdm",
  "projectId": "DEVICE_ACCESS_PROJECT_ID",
  "gcpProjectId": "GOOGLE_CLOUD_PROJECT",
  "subscriptionId": "projects/GOOGLE_CLOUD_PROJECT/subscriptions/nest-homebridge",
  "clientId": "...",
  "clientSecret": "...",
  "refreshToken": "..."
}

Notice that:

  • projectId is the Device Access Project.
  • gcpProjectId is the Google Cloud project.
  • subscriptionId is the Pub/Sub subscription.

Troubleshooting

Request had insufficient authentication scopes

Cause:

The refresh token was generated without the Pub/Sub scope.

Solution:

Generate a new authorization code requesting both:

https://www.googleapis.com/auth/sdm.service

and

https://www.googleapis.com/auth/pubsub

Then generate a new refresh token.


invalid_client

Cause:

The OAuth Client Secret does not match the Client ID.

Solution:

Verify that the Homebridge configuration contains the matching Client ID, Client Secret, and Refresh Token.

If you create a new OAuth client, you must generate a new refresh token using that client.


Possible causes include:

  • Existing Partner Connection
  • Incorrect Google account
  • OAuth client mismatch
  • OAuth consent screen configuration

Removing the existing Partner Connection and authorizing again typically resolves the issue.


crypto-key is missing

This message usually appears when Pub/Sub has not been fully configured.

Verify:

  • Pub/Sub Topic
  • Publisher permissions
  • Pull Subscription
  • OAuth scopes

Security Recommendations

Never publish or share:

  • OAuth Client Secret
  • Refresh Token
  • Authorization Code

If any of these credentials are accidentally exposed:

  1. Rotate the OAuth Client Secret.
  2. Generate a new authorization code.
  3. Generate a new refresh token.
  4. Update Homebridge.

Architecture Overview

Nest Thermostat
        │
        ▼
Smart Device Management API
        │
        ▼
Google Pub/Sub Topic
        │
        ▼
Pull Subscription
        │
        ▼
homebridge-google-nest-sdm
        │
        ▼
Apple Home

Understanding this flow makes troubleshooting much easier because each component has a specific responsibility.


Final Thoughts

Once configured correctly, the Google Smart Device Management API is a stable and reliable way to integrate Nest thermostats with Homebridge and Apple Home.

Although the initial setup is more involved than many Homebridge plugins, the result is an official Google-supported integration that provides secure authentication and real-time thermostat updates through Google Cloud Pub/Sub.