All the major OAuth providers. One profile API.Explore the quickstart
All field notes
Gabe

Gabe

Founder, AnyOAuth

Builds AnyOAuth and MailKite. Writes about social sign-in, identity boundaries, and building applications with AI coding tools.

Posts by Gabe

Building with AnyOAuth4 min read

One secret for all your app's sign-in providers

Google and GitHub sign-in can use the same project credentials. Multiple independent apps should still have separate projects. The useful simplification is fewer provider integrations, not a secret shared everywhere.

Read article
Building with AnyOAuth4 min read

One profile format doesn't mean one identity

Google and GitHub return different profile data. A normalized response makes that data easier to use, but your account model still needs a stable subject, nullable fields, and deliberate account linking.

Read article
Building with AnyOAuth4 min read

Social sign-in without password handling

Social sign-in removes a password database from this login flow, not the responsibility to protect people’s data. Here’s an ownership inventory you can use before connecting a familiar account to your app.

Read article
Building with AnyOAuth5 min read

Familiar accounts, one sign-in integration

Google and GitHub can share your application’s callback and profile contract without becoming interchangeable identities. This note separates the provider choice users see from the integration and account decisions your backend owns.

Read article
Building with AnyOAuth5 min read

Secure OAuth handoffs need separate checks

State, PKCE, callback matching, and a backend secret protect different parts of a login. Use this failure-oriented review to check the handoff without mistaking any one safeguard for a complete session system.

Read article
OAuth fundamentals5 min read

What is OAuth? Follow the permission, not the login button

OAuth 2.0 is an authorization framework that lets an application obtain limited access to an API without taking the user’s password. To understand a social login built around it, separate the API permission, the evidence of identity, and the session your app creates afterward.

Read article
OAuth fundamentals5 min read

OAuth vs SAML: choose by the boundary you need to cross

OAuth delegates access to APIs; SAML exchanges assertions about identity and is used for federated sign-in. For a login-protocol decision, compare SAML with OpenID Connect, then handle any delegated API access as a separate OAuth requirement.

Read article
OAuth fundamentals5 min read

PKCE: what the verifier proves, and what it does not

PKCE, or Proof Key for Code Exchange, binds authorization-code redemption to a secret verifier created for that transaction. With S256, the authorization request sends a SHA-256-derived challenge, and the token request must supply the original verifier; an intercepted code alone is insufficient.

Read article