> For the complete documentation index, see [llms.txt](/docs/llms.txt)

# Google Reconcile Lambda | FusionAuth Docs

An overview of the Google Reconcile lambda.

# Google Reconcile Lambda

When a Google identity provider is used to complete a federated login request, FusionAuth will use the [configured linking strategy](/docs/lifecycle/authenticate-users/identity-providers/#linking-strategies) to reconcile the user. FusionAuth will attempt to match the user information returned from the Google identity provider to an existing user account or create a new one.

You may optionally utilize a lambda to customize the user and user registration during the authentication event.

When you create a new lambda using the FusionAuth administrative user interface, you will be provided an empty function to implement.

Starting in version 1.65.0, you can use [attribute mappings](/docs/lifecycle/authenticate-users/identity-providers/#attribute-mappings) to map IdP claims directly to FusionAuth user and registration fields without writing a lambda. Reconcile lambdas and attribute mappings are mutually exclusive. Attempting to configure both on a given IdP results in a validation error.

## Lambda Structure[#](#lambda-structure)

If you are using the API to create the lambda you will need to ensure your function has the following signature:

```
function reconcile(user, registration, idToken, context) {
  // Lambda code goes here
}
```

This lambda must contain a function named `reconcile` that accepts the following parameters:

*   `user` - the FusionAuth User object. You can modify this object. However, the **email** and **username** attributes may not be modified after the user has been linked.
*   `registration` - the FusionAuth UserRegistration object. You can modify this object.

*   `idToken` - the JSON payload returned by the Google Token Info API. This object is read-only.
*   `context` - Available since 1.64.0 - an object containing the context of the request, including access to [secrets](/docs/extend/code/lambdas#secrets). This object is read-only.

The two FusionAuth objects are well documented in the [User API](/docs/apis/users) and [Registration API](/docs/apis/registrations) documentation. The `idToken` may contain various user claims to utilize during the reconcile process.

## Assigning The Lambda[#](#assigning-the-lambda)

Once a lambda is created, you may assign it to the Google identity provider in the IdP configuration.

Navigate to Settings -> Identity Providers and select your existing Google configuration or click Add provider and select Google if it has not yet been configured.

## Default Lambda[#](#default-lambda)

A default Google reconcile lambda is available in FusionAuth that may be used or modified. The default Google lambda function is documented below.

```
// This is the default Google reconcile, modify this to your liking.
function reconcile(user, registration, idToken) {
  // Un-comment this line to see the idToken object printed to the event log
  // console.info(JSON.stringify(idToken, null, 2));

  // The idToken is the response from the tokeninfo endpoint
  // https://developers.google.com/identity/sign-in/web/backend-auth#calling-the-tokeninfo-endpoint
  user.firstName = idToken.given_name;
  user.lastName = idToken.family_name;
  user.fullName = idToken.name;
  user.imageUrl = idToken.picture;
}
```