Designs user-authenticated OAuth 2.0/OIDC consent flows for ADK agents accessing Google Workspace APIs, using least-privilege scopes, authorization-code + PKCE redirects, and ADK credential-request callbacks without exposing user tokens to the model. TRIGGER when users ask to 'configure OAuth for ADK agent', 'request user consent in ADK', 'connect my agent to Google Drive/Workspace', 'handle user OAuth tokens', or use `OAuth2Auth`, `OidcAuth`, or `tool_context.request_credential`. DO NOT TRIGGER for service-account-only server-to-server access, creating Google Cloud API keys, or general Google Workspace administration.