Google + GitHub sign-in. One profile API.Explore the quickstart

One profile.
All your OAuth logins.

Let users sign in with Google or GitHub. Get a consistent identity through one API, without handling provider tokens.

Your users’ familiar accounts. Your application’s own sessions.

Example application
Your backendNormalized identity
GET/v1/profile200 OK
{
  "subject": "usr_demo_google",
  "provider": "google",
  "name": "Jane Smith",
  "username": null,
  "email": "jane@example.com",
  "emailVerified": true,
  "avatarUrl": "https://…"
}

An AnyOAuth token. Profile access only.

Interactive preview. No sign-in request is sent.

Two providers. One integration.

GoogleGitHub

The identity layer
your application needs.

Keep the familiar sign-in experience. Leave provider-specific callbacks and profile formats to AnyOAuth.

One profile,
every provider.

A consistent response for the fields you need. Stable subjects keep identities separate within each project.

Googlegoogle subject
GitHubgithub subject
Your applicationprofile.subject

A token that
knows its limits.

Our token retrieves one profile. It expires in 15 minutes, can be revoked, and cannot access provider APIs.

AnyOAuth profile token
aop_••••••••••••••
Profile only15 minutesRevocable

Sessions that
stay yours.

You own the user record, session, and permissions. Get the identity, then continue with your application’s logic.

Verified identity
Your session

Familiar accounts.
A consistent way in.

Google and GitHub adapters use the same code exchange and profile endpoint. Enable the providers your application needs.

Google

OpenID Connect

Sign users in with their Google account. Receive validated identity claims and preserve their email verification status.

openidprofileemail

GitHub

OAuth identity flow

Sign users in with their GitHub account. Get their profile and primary email without requesting repository access.

read:useruser:email

Availability depends on the service’s configured provider applications. Profile fields vary by provider.

Three steps.
One signed-in user.

A small API that fits into your backend. No provider-specific token handling in your application.

  1. 1

    Redirect to sign in

    Send the user to AnyOAuth with state, a PKCE challenge, and your registered callback.

  2. 2

    Exchange the code

    Validate the returned state. Your backend exchanges the code for an AnyOAuth token.

  3. 3

    Get the profile

    Fetch the identity, find or create your user, and issue your application’s session.

Read the quickstart
Your backendHTTP API
// Exchange the single-use callback code
POST /v1/token
{
  "grant_type": "authorization_code",
  "client_id": "YOUR_CLIENT_ID",
  "client_secret": "YOUR_SERVER_SECRET",
  "code": "CALLBACK_CODE",
  "redirect_uri": "YOUR_CALLBACK",
  "code_verifier": "ORIGINAL_VERIFIER"
}

// Use the returned AnyOAuth token
GET /v1/profile
Authorization: Bearer aop_…

Just identity.
A clear boundary.

Your application gets the profile it needs. Provider credentials stay inside the server-side sign-in flow.

Explore the security model
  • Protected handoff

    Browser-bound state, PKCE, exact callbacks, and single-use codes.

  • Short-lived credentials

    Profile tokens expire after 15 minutes and are stored only as hashes.

  • Project-scoped identities

    Separate subjects per project. Matching emails never automatically merge accounts.

A few things
worth knowing.

Clear answers before you add another piece to your authentication stack.

Do I get a Google or GitHub token?

No. Your backend gets an AnyOAuth token that can only fetch the signed-in user’s profile. Provider tokens are not returned or stored.

Does AnyOAuth manage my application sessions?

Your app owns its sessions and permissions. Fetch the profile, find or create your user by the stable subject, and issue your own session cookie.

What profile information is available?

Subject, provider, provider subject, name, username, email, email verification status, and avatar. Fields that a provider does not supply are returned as null.

How long does the token last?

AnyOAuth profile tokens expire after 15 minutes. There is no refresh token. You can revoke a token early, or delete the associated user in your dashboard.

Can I request inbox or repository access?

No. AnyOAuth is sign-in only. It requests identity scopes and does not provide access to repositories, messages, calendars, or other provider APIs.

Your next sign-in,
without the extra plumbing.

Create a project. Register your callback. Get the profile.