GOOGLE_WEB_CLIENT_ID

The WEB OAuth client ID from the Google Cloud console, not the Android one.

This is the single most-reported Credential Manager failure: an Android client ID is accepted by the builder, compiles, and then fails at runtime with a generic GetCredentialException. The Android client ID exists only to bind your package + signing SHA-1; the audience of the ID token — which is what setServerClientId sets — is the web client. A client ID is public by design, so the real value may live in the repo once provisioned.