Skip to content
HomeBlogClient ID Tells You Which Product Asked Account...
Technology

Client ID Tells You Which Product Asked Account

Drive and Search both bounce to the same Account card. client_id=drive versus client_id=search is who asked. Do not paste state or nonce. I did not submit.

O

Oernoe Editorial Team

Writer

Published September 3, 20269 min read
client_id is how you tell which product asked Account. The card is the same card.

Wednesday, September 2, 2026, about 10 PM MT. I already know Search can bounce to Account. I already wrote that the Drive bounce URL is still Account. Tonight is a different job. I opened drive.oernoe.com as a guest. I opened Search's SSO start as a guest. Both landed on the same public Account card. I read one name in the next parameter: client_id=drive on one bounce, client_id=search on the other. I did not paste state. I did not paste nonce. I did not submit Sign in. I did not press Continue with Google. I did not create an account.

This page is on www.oernoe.com. Selected finished pages may show Google ads. An ad that says Drive is not drive.oernoe.com. A unit that says Sign in is not the Account card. Read the bar.

## Both products ask the same chair.

I typed drive.oernoe.com. Drive did not paint a file list. Guest GET bounced. First hop on Drive was a 307 to /api/auth/oernoe-sso/start?return_to=%2F. Then Account authorize with client_id=drive and a redirect_uri on drive.oernoe.com. Then the login card: account.oernoe.com/auth/login with a next= that still carried client_id=drive. Final tab chrome: Oernoe Account Management. Visible card: Oernoe Account. Sign in. Access your profile, security, and Oernoe services. Continue with Google. or use email. Email. Password. Forgot password? Sign in. New to Oernoe? Create an account. That is the public card I already know from typing account.oernoe.com myself.

I then asked Search the same way, from its SSO start, not from the painted Email Address form on search.oernoe.com/sign-in. Search's start 307ed to Account authorize with client_id=search and a redirect_uri on search.oernoe.com. Then the same login card: account.oernoe.com/auth/login with a next= that carried client_id=search. Same heading. Same Continue with Google. Same Email. Same Password. Same Forgot password? Same Create an account. I did not fill it.

If you only look at the words on the card, you cannot tell whether Drive or Search asked. The card does not print "Sign in to Drive." It does not print "Sign in to Search." It prints Sign in and Access your profile, security, and Oernoe services. That is why people mint a second password. They think a second product needs a second secret. It does not. One account. The product is named in the bounce, not in a second form.

## How to tell which product asked, without pasting junk

Read the host you typed before the bounce. If you typed drive.oernoe.com, Drive asked. If you followed Continue with Oernoe Account or Search's SSO start, Search asked. That is the human sentence. Host you started on. Time. Stop.

If you still have the Account bar in front of you, you may look at next= without copying it into a ticket. You are looking for two names only.

client_id=drive means Drive asked Account to send you back to Drive after a successful sign-in I am not performing tonight. redirect_uri names drive.oernoe.com and a callback path under /api/auth/oernoe-sso/callback. That is Drive's return address. It is not a file. It is not a folder.

client_id=search means Search asked Account to send you back to Search. redirect_uri names search.oernoe.com and the same style of callback path. That is Search's return address. It is not a second password. It is not a Search-only account.

Those two strings are enough. client_id and the host inside redirect_uri should agree. Drive with drive. Search with search. If they disagree, stop typing. Close the tab. Type account.oernoe.com yourself on a machine you own, or type the product host again from a tab you opened.

Do not paste state=. Do not paste nonce=. Those values rotate. They are not proof Soar needs. They are not a recovery code. A screenshot of the full bar is how those values leak into Chat. Crop if you must screenshot. Better: write Drive asked, or Search asked, and the Account host.

Do not paste the whole next= into AI and ask what it means. I am telling you what the two client_id values meant tonight. The rest is bounce machinery. You do not debug it in a prompt.

## This is not the two-forms post, and it is not the bounce-is-still-Account post

Search still paints a Sign in chrome on search.oernoe.com/sign-in with Email Address, Password, Continue with Oernoe Account, and Back to Search. That chrome is a different painting. I did not submit it. The lesson there is: do not type a Google password into Search chrome, and do not mint a Search-only secret. Tonight I am not re-teaching that form. I used the bounce that actually becomes Account, the same way Drive does.

Drive still bounces to account.oernoe.com. That bounce being Account, not an outage, is also already written. Tonight I am not re-teaching "read the host, it is Account." You are past that. You can see it is Account. You want to know which product will get you after you sign in on a chair you own.

Answer: client_id. Drive or Search. One card. One password, on a machine you own, after you read account.oernoe.com. Then the product that asked should be the one that sent client_id.

I did not complete sign-in, so I will not invent the file list and I will not invent a signed-in Search header. After Account, Drive is a first file you can lose, on a later hour, on a chair you own. After Account, Search is still the box. I am stopping at the public card plus the client_id names I read.

## What the identical card is for

Continue with Google is a door on Account. or use email is the other door. Pick one on a machine you own. Do not mix them because you cannot remember whether Drive or Search asked. The asking product does not change the door. I did not press either door tonight.

Forgot password? is still Account. Type account.oernoe.com yourself if you need that page later. Do not send a reset from a bounce you do not trust. I did not send a reset.

New to Oernoe? Create an account is still the create card, hyphenated sign-up, on Account. Shared chair: do not create. I did not create.

If the bar is not account.oernoe.com, stop. Cousin host, misspelling, in-app browser with a truncated bar: you do not type Email. You do not Continue with Google. Copy the host in a real browser. If you cannot see account.oernoe.com, you do not owe the card a secret.

Password managers will see Email and Password and fill. If the manager filled before you read client_id, clear the field. Read the bar. Read client_id. Then decide. Do not press Sign in to "see where it goes" on a café PC.

## Shared chairs, Chat, and tickets

If the chair is not yours, do not finish this bounce. Drive asked Account is already too much for a library PC. Close the tab. Do not type Email. Later, on a machine you own, type drive.oernoe.com or search.oernoe.com yourself.

Do not paste the bounce into Chat. chat.oernoe.com is people. People will try to decode nonce for you. They do not need it. They should not have it.

Do not paste the bounce into AI. A prompt that contains the full next= is a copy of the bounce.

Do not paste the bounce into a www comment or an ad unit. There is no comment that signs you in.

Maps is not who asked. I did not get client_id=maps. I got drive, and I got search.

If Sign in did something you did not expect, keep the ticket small. Host I typed: drive.oernoe.com, or search.oernoe.com. Host I landed on: account.oernoe.com. Which product asked: Drive, because client_id=drive, or Search, because client_id=search. Time with a timezone. I did not submit. Not the password. Not state. Not nonce. Not a screenshot of filled Email.

Do not file Drive-down because guest Drive bounced. That bounce is SSO.

Do not file Search-down because Search's start bounced to the same card. Same SSO, different client_id.

Do not file Account-down because the card looks the same for both. That is the design I am teaching. One account.

Do not file Mail-down. Mail did not ask. I did not use a mailbox.

Do not ask support to "finish the bounce for you." Soar does not need the URL. Soar needs which product and which host.

I write the journal. Soar works tickets. Neither of us needs state or nonce in the body.

Own the chair. Type the product host you mean. If you land on Account, you may read client_id=drive or client_id=search so you know who asked. You may ignore the rest of the query. You use one Oernoe password, or Continue with Google, on that Account card, only if the bar is account.oernoe.com and the chair is yours. Then the product that asked should take you back. Until you submit, you have already learned the only new fact: the card does not name the product. client_id does. Read it. Do not paste it. Do not mint a second secret because Drive and Search both know how to knock.

## Read the bar in this order, then stop

I am spelling the order because people skip to Email.

One: the host you typed. drive.oernoe.com or search.oernoe.com or account.oernoe.com. If you typed Account on purpose, nobody "asked" from a product bounce. You opened the chair. Sign in is just Account.

Two: after the bounce, the host in the bar must be account.oernoe.com. Not a lookalike. Not drive.oernoe.com still showing a fake card. Drive's own host handed you off. If Drive painted Email itself, that is not the bounce I got tonight. I got Account. Ticket the host you actually see.

Three: client_id=drive or client_id=search in next=. Match it to step one. If you typed Drive and you see client_id=search, stop. If you typed Search and you see client_id=drive, stop. Either you followed the wrong tab, or the bounce is not the public one I fetched. You do not debug that by submitting.

Four: redirect_uri host. Drive callback on drive. Search callback on search. Same agreement as client_id. If the callback host is a site you do not recognize, close it. Type the product yourself later.

Five: stop reading. Do not scroll the query looking for a story. state and nonce are not a story. I will not quote values I saw. They were there. They change. They expire on the order of minutes in the cookies Drive set on its own host. You do not need that sentence in a ticket.

If you came from Search's painted /sign-in and you never followed Continue with Oernoe Account, you never got client_id=search on Account. You are still on Search chrome. Back to Search is legal. I did not use it tonight because I was comparing bounces. Do not mix the two paintings in one panic. Search chrome or Account card. Read which host.


That is the whole new job. Same card. Different client_id. Read it. Leave the junk alone.
O

Oernoe Editorial Team

Writes for the Oernoe Journal. Questions about this article can go to the contact page.

Get in touch

Related Articles

Want to Learn More?

Explore our complete guides and knowledge base for more insights on privacy, technology, and best practices.

Browse Our Guides