All the major OAuth providers. One profile API.Explore the quickstart

Auth you can inspect.

Field notes for developers and AI-assisted builders. Fewer credential puzzles, clearer identity boundaries, and a sign-in flow you can explain after the assistant writes it.

Follow via RSS
Start here

Stop juggling OAuth client IDs and secrets

Adding another sign-in button shouldn't mean maintaining another provider integration. Here's which credentials your app can hand off, and which one still belongs on your backend.

GabeRead the credential field note
  1. Google and GitHub provider applications
  2. AnyOAuth manages provider credentials
  3. Your backend uses project credentials
Provider credentials stay with the service. Your app still authenticates its backend with its own project client ID and secret.

15 articles

Building with AnyOAuth4 min read

Social sign-in without password handling

Social sign-in removes a password database from this login flow, not the responsibility to protect people’s data. Here’s an ownership inventory you can use before connecting a familiar account to your app.

GabeRead article
Building with AnyOAuth5 min read

Familiar accounts, one sign-in integration

Google and GitHub can share your application’s callback and profile contract without becoming interchangeable identities. This note separates the provider choice users see from the integration and account decisions your backend owns.

GabeRead article
Building with AnyOAuth5 min read

Secure OAuth handoffs need separate checks

State, PKCE, callback matching, and a backend secret protect different parts of a login. Use this failure-oriented review to check the handoff without mistaking any one safeguard for a complete session system.

GabeRead article
OAuth fundamentals5 min read

What is OAuth? Follow the permission, not the login button

OAuth 2.0 is an authorization framework that lets an application obtain limited access to an API without taking the user’s password. To understand a social login built around it, separate the API permission, the evidence of identity, and the session your app creates afterward.

GabeRead article
OAuth fundamentals5 min read

PKCE: what the verifier proves, and what it does not

PKCE, or Proof Key for Code Exchange, binds authorization-code redemption to a secret verifier created for that transaction. With S256, the authorization request sends a SHA-256-derived challenge, and the token request must supply the original verifier; an intercepted code alone is insufficient.

GabeRead article