Secure GenAI Applications in Python - Full Example Project

NeuralNineAbout 6 min readJul 22, 2025Watch original
THE SUMMARYAI-generated

Key Concepts

  • Generative AI Application Security: Building secure applications using GenAI, focusing on authentication and authorization.
  • Social Login: Implementing login functionality using existing social media accounts (specifically Google).
  • FastAPI: A modern, high-performance web framework for building APIs with Python.
  • OpenAI API: Utilizing OpenAI's API for tasks like structured output extraction from text.
  • Google Cloud Platform (GCP): Accessing Google services like Sheets API and Drive API.
  • Auth0: A platform for authentication and authorization, used here for social login with Google.
  • OAuth 2.0: An authorization framework that enables applications to obtain limited access to user accounts on an HTTP service.
  • Structured Output: Extracting data from unstructured text into a defined format (e.g., JSON) using OpenAI.
  • Pydantic: A data validation and settings management library using Python type annotations.
  • Google Sheets API: An API that allows programmatic access to Google Sheets.
  • Google Drive API: An API that allows programmatic access to Google Drive.

Secure Generative AI Application with Social Login: A Step-by-Step Guide

1. Overview and Motivation

The video demonstrates building a secure generative AI application in Python that allows users to log in with their Google account, extract data from PDF invoices stored in Google Drive, and populate a Google Sheets document with the extracted information. This is presented as a proof of concept that can be customized and extended for various use cases.

  • Example Application: A PDF invoice processor that extracts data (invoice number, date, total, recipient, sender) and writes it to a Google Sheet.
  • Customization: The application can be adapted to use different APIs, social accounts, and features.

2. Application Architecture and Components

The application consists of a FastAPI backend serving a basic HTML frontend and connecting to three main services:

  • FastAPI Backend: Handles user authentication, API requests, and data processing.
  • OpenAI API: Used for extracting structured information from PDF documents.
  • Google Cloud Platform (GCP): Provides access to Google Sheets API and Drive API for interacting with Google services.
  • Auth0: Manages user authentication with Google accounts and authorization for accessing Google APIs.

3. Setting Up Auth0 for Authentication

Auth0 is used to handle user authentication with Google accounts. The video outlines the following steps:

  • Account Creation: Create a free Auth0 account.
  • Application Creation: Create a new "Regular Web Application" in Auth0 and name it (e.g., "PDF Extractor App").
  • Callback URLs: Configure the application settings with the following callback URLs:
    • http://localhost:8000/auth/callback (for local development)
    • https://<your-tenant>.auth0.com/auth/callback (replace <your-tenant> with your Auth0 tenant ID)
  • Logout URL: Set the logout URL to http://localhost:8000.
  • Environment Variables: Set the following environment variables:
    • AUTH0_SECRET: Generate a secret key using openssl rand -hex 32.
    • APP_BASE_URL: Set to http://localhost:8000.
    • AUTH0_DOMAIN: Your Auth0 tenant domain (e.g., <your-tenant>.auth0.com).
    • AUTH0_CLIENT_ID: The client ID of your Auth0 application (found in the application settings).
    • AUTH0_CLIENT_SECRET: The client secret of your Auth0 application (found in the application credentials).
    • OPENAI_API_KEY: Your OpenAI API key.
  • Social Connection: Configure a social connection for Google/Gmail in Auth0, providing the client ID and client secret from your Google Cloud project.
  • Permissions: Enable the necessary permissions (scopes) for the Google connection, including offline_access, drive permissions, and spreadsheets permissions.
  • Token Vault: Enable the "Token Vault" feature in the social connection settings to securely store and retrieve access tokens for the Google API.
  • Grant Types: In advanced settings, allow "Token Exchange" for federated connections.

4. Setting Up Google Cloud Platform (GCP)

The video details the steps to configure a Google Cloud project for accessing Google Sheets and Drive APIs:

  • Project Creation: Create a new project in the Google Cloud Console (console.cloud.google.com).
  • API Enablement: Enable the Google Sheets API and the Google Drive API for the project.
  • OAuth Consent Screen: Configure the OAuth consent screen:
    • Set the application name (e.g., "PDF Extraction App").
    • Provide a support email address.
    • Choose "External" as the user type.
    • Add [email protected] as contact information.
  • OAuth Client Creation: Create an OAuth client:
    • Choose "Web application" as the application type.
    • Set the name (e.g., "PDF Extractor Client").
    • Add authorized JavaScript origins: https://<your-tenant>.auth0.com
    • Add authorized redirect URIs: https://<your-tenant>.auth0.com/login/callback
  • Client ID and Secret: Obtain the client ID and client secret from the created OAuth client.
  • Data Access (Scopes): Configure the scopes (permissions) for the application. For simplicity, the video grants all permissions for Sheets API and Drive API, but it's recommended to be more granular in a production environment.
    • Sheets API: Select all scopes.
    • Drive API: Select all scopes.
  • Test Users: Add your email address as a test user to the OAuth consent screen to bypass the verification process during development.

5. Project Setup and Dependencies

The video uses UV for package management, but pip can also be used.

  • Project Initialization: Initialize a Python project (using uv init or creating a main.py file).
  • Environment File: Create a .env file to store environment variables (API keys, client IDs, secrets).
  • Dependency Installation: Install the required Python packages:
    • pip install pypdf2 openai python-dotenv pydantic fastapi google-api-python-client auth0-server-python
    • Or using UV: uv add pypdf2 openai python-dotenv pydantic fastapi google-api-python-client auth0-server-python

6. Code Implementation (FastAPI Backend)

The video provides code snippets for the FastAPI backend, which are available on GitHub. The key components include:

  • Import Statements: Import necessary libraries (os, io, json, pypdf2, openai, dotenv, pydantic, fastapi, googleapiclient, auth0).
  • Environment Variable Loading: Load environment variables from the .env file using load_dotenv().
  • Auth0 Server Client Initialization: Initialize the Auth0 server client with the environment variables.
  • Pydantic Model: Define a Pydantic model for the invoice data (invoice number, date, total, recipient, sender).
  • OpenAI Client Initialization: Initialize the OpenAI client with the API key.
  • FastAPI Instance Creation: Create a FastAPI application instance.
  • User Settings Dictionary: Create an empty dictionary to store user-specific settings (folder ID, sheet ID).
  • HTML Rendering Function: Define a helper function to render HTML templates with data.
  • PDF Text Extraction Function: Define a function to extract text from PDF files using pypdf2.
  • Invoice Data Extraction Function: Define a function to extract invoice data using the OpenAI API and the Pydantic model for structured output.
  • API Endpoints:
    • / (Root): Handles user login and displays the home page with settings form.
    • /settings (POST): Saves the folder ID and sheet ID provided by the user.
    • /auth/callback: Handles the callback from Auth0 after successful or unsuccessful login.
    • /process (POST): Processes the PDF invoices, extracts data, and writes it to the Google Sheet.
    • /logout: Logs the user out.
  • Uvicorn Configuration: Configure Uvicorn to run the FastAPI application.

7. HTML Templates

The video mentions the following HTML templates:

  • base.html: Base HTML structure with placeholders for title and content.
  • home.html: Home page with settings form and process button.
  • login.html: Login page with a button that redirects to the Auth0 login URL.
  • result.html: Displays the result of the PDF processing (success or error).

8. Running the Application

  • Run the FastAPI application using Uvicorn: uvicorn main:app --reload

9. Key Takeaways and Conclusion

The video demonstrates how to build a secure generative AI application using Python, FastAPI, OpenAI, Google Cloud Platform, and Auth0. It highlights the importance of secure authentication and authorization, and how Auth0 can simplify the process of implementing social login and managing access tokens for Google APIs. The application can be customized and extended for various use cases involving data extraction and processing. The key is leveraging Auth0 to handle authentication and authorization, allowing the developer to focus on the core logic of the application.

AI summaries can miss context or contain errors. Check important details against the original video.

Go a little deeper.

Have a question about this video? Load its transcript to open the video chat.