Authentication
Social sign-in
Google, GitHub, GitLab, LinkedIn and Apple on the hosted pages.
Supported providers#
| Provider | Status |
|---|---|
| Supported | |
| GitHub | Supported |
| GitLab (including self-managed) | Supported |
| Supported | |
| Apple | Supported |
| Microsoft, Facebook, Instagram | Not supported: they do not provide a verified email address, which account matching requires |
Setting up a provider#
- Create an OAuth app with the provider.
- In the environment's Authentication → Providers, enter the credentials the provider issued (for Apple, including the private key).
- Register the callback URL shown there with the provider. It is the API's
/authkit/oauth/callback, the same for every provider.
Client secrets and Apple's private key are encrypted at rest and never shown again in full.
Rules that apply#
- The provider must assert a verified email address; accounts are matched on it within the environment.
- After the provider returns, sign-in finishes on the hosted page, so MFA, blocked accounts and the one-time code handoff all apply.
- Social sign-in is per environment and can be turned off there (the API then answers
403).