Hey! You need to grant permission first.
You are right that user doesn’t have to know about any permissions but you have to grant it to your client which is node server in this example.
Make sure that your clients in the browser do not receive any JS code that explicitly calls OAuth google API.