Homebridge Google Nest SDM Setup (2026 Edition)
Set up Homebridge-Nest with a Google account so Nest devices can appear in Apple HomeKit with a cleaner smart-home workflow.
Important Update (2026)
Google has changed parts of the Device Access setup process since this guide was originally published. If you’re configuring Homebridge today, there are several additional steps that are required to receive real-time updates from your Nest devices.
This article has been updated with the latest setup process, including Google Cloud Pub/Sub, OAuth scopes, and common troubleshooting steps.
Understanding the Three Google Projects
One of the biggest sources of confusion is that Google uses three different components.
| Component | Purpose |
|---|---|
| Device Access Project | Gives access to your Nest devices |
| Google Cloud Project | Hosts Pub/Sub topics and subscriptions |
| OAuth Client | Authenticates Homebridge |
These are related, but they are not the same thing.
Enable the Smart Device Management API
Enable the following API inside your Google Cloud project:
- Smart Device Management API
Also enable:
- Cloud Pub/Sub API
Both are required.
Configure Pub/Sub
Real-time thermostat updates rely on Google Cloud Pub/Sub.
Create a Topic
Create a topic named:
nest
The resulting topic should look like:
projects/YOUR_GCP_PROJECT/topics/nest
Grant Permissions
The Nest Device Access service needs permission to publish messages.
Grant the following principal access:
sdm-publisher@googlegroups.com
Role:
Pub/Sub Publisher
Enable the Topic
Open the Google Device Access Console.
Locate Pub/Sub Topic.
Enter:
projects/YOUR_GCP_PROJECT/topics/nest
After validation, the topic should show as Enabled.
Create a Pull Subscription
Next, create a subscription.
Recommended settings:
Subscription ID
nest-homebridge
Delivery Type
Pull
The full subscription path will be similar to:
projects/YOUR_GCP_PROJECT/subscriptions/nest-homebridge
OAuth Authentication
When generating the authorization code, request both OAuth scopes.
https://www.googleapis.com/auth/sdm.service
and
https://www.googleapis.com/auth/pubsub
Example authorization URL:
https://nestservices.google.com/partnerconnections/DEVICE_ACCESS_PROJECT_ID/auth?redirect_uri=https://www.google.com&access_type=offline&prompt=consent&client_id=YOUR_CLIENT_ID&response_type=code&scope=https://www.googleapis.com/auth/sdm.service+https://www.googleapis.com/auth/pubsub
After approving access, Google redirects to:
https://www.google.com/?code=...
Copy the authorization code.
Exchange it for a refresh token using Google’s OAuth token endpoint.
Homebridge Configuration
Your configuration should contain something similar to:
{
"platform": "homebridge-google-nest-sdm",
"projectId": "DEVICE_ACCESS_PROJECT_ID",
"gcpProjectId": "GOOGLE_CLOUD_PROJECT",
"subscriptionId": "projects/GOOGLE_CLOUD_PROJECT/subscriptions/nest-homebridge",
"clientId": "...",
"clientSecret": "...",
"refreshToken": "..."
}
Notice that:
projectIdis the Device Access Project.gcpProjectIdis the Google Cloud project.subscriptionIdis the Pub/Sub subscription.
Troubleshooting
Request had insufficient authentication scopes
Cause:
The refresh token was generated without the Pub/Sub scope.
Solution:
Generate a new authorization code requesting both:
https://www.googleapis.com/auth/sdm.service
and
https://www.googleapis.com/auth/pubsub
Then generate a new refresh token.
invalid_client
Cause:
The OAuth Client Secret does not match the Client ID.
Solution:
Verify that the Homebridge configuration contains the matching Client ID, Client Secret, and Refresh Token.
If you create a new OAuth client, you must generate a new refresh token using that client.
”Can’t link to Nest Thermostat API”
Possible causes include:
- Existing Partner Connection
- Incorrect Google account
- OAuth client mismatch
- OAuth consent screen configuration
Removing the existing Partner Connection and authorizing again typically resolves the issue.
crypto-key is missing
This message usually appears when Pub/Sub has not been fully configured.
Verify:
- Pub/Sub Topic
- Publisher permissions
- Pull Subscription
- OAuth scopes
Security Recommendations
Never publish or share:
- OAuth Client Secret
- Refresh Token
- Authorization Code
If any of these credentials are accidentally exposed:
- Rotate the OAuth Client Secret.
- Generate a new authorization code.
- Generate a new refresh token.
- Update Homebridge.
Architecture Overview
Nest Thermostat
│
▼
Smart Device Management API
│
▼
Google Pub/Sub Topic
│
▼
Pull Subscription
│
▼
homebridge-google-nest-sdm
│
▼
Apple Home
Understanding this flow makes troubleshooting much easier because each component has a specific responsibility.
Final Thoughts
Once configured correctly, the Google Smart Device Management API is a stable and reliable way to integrate Nest thermostats with Homebridge and Apple Home.
Although the initial setup is more involved than many Homebridge plugins, the result is an official Google-supported integration that provides secure authentication and real-time thermostat updates through Google Cloud Pub/Sub.