Authentication

Social sign-in

Google, GitHub, GitLab, LinkedIn and Apple on the hosted pages.

Supported providers#

ProviderStatus
GoogleSupported
GitHubSupported
GitLab (including self-managed)Supported
LinkedInSupported
AppleSupported
Microsoft, Facebook, InstagramNot supported: they do not provide a verified email address, which account matching requires

Setting up a provider#

  1. Create an OAuth app with the provider.
  2. In the environment's Authentication → Providers, enter the credentials the provider issued (for Apple, including the private key).
  3. Register the callback URL shown there with the provider. It is the API's /authkit/oauth/callback, the same for every provider.

Client secrets and Apple's private key are encrypted at rest and never shown again in full.

Rules that apply#

  • The provider must assert a verified email address; accounts are matched on it within the environment.
  • After the provider returns, sign-in finishes on the hosted page, so MFA, blocked accounts and the one-time code handoff all apply.
  • Social sign-in is per environment and can be turned off there (the API then answers 403).