All the major OAuth providers. One profile API.Explore the quickstart
Documentation navigation

Start with an agent

The easiest path for vibe coders and agents—install the AnyOAuth skill, connect the CLI or MCP, and approve sign-in in your browser.

On this page

Install the AnyOAuth skill

Give your coding agent the AnyOAuth skill. It walks through installation, browser sign-in, project setup, and adding Google/GitHub login to your app. This is the easiest starting point if you’re building with an agent.

From your project directory, install it with the Skills CLI:

Terminal
npx skills add AnyOAuth/anyoauth --skill anyoauth

Or, once the AnyOAuth CLI is installed:

Terminal
anyoauth skill install
# For Claude Code:
anyoauth skill install --dir .claude/skills/anyoauth

The default location is .agents/skills/anyoauth/SKILL.md. The installer preserves an existing skill rather than overwriting it. You can also copy the raw skill into your agent’s skill directory.

Then ask your agent:

Use the AnyOAuth skill to add Google and GitHub sign-in to this app. Create or reuse a project, register the correct callback, and keep the client secret on the backend.

Install the CLI

Use Node.js 22 or newer. The package includes both the CLI and local MCP server:

Terminal
npm install --global @anyoauth/cli
anyoauth --help

Initial source installation: until @anyoauth/cli is published to npm, install from the repository. Run the following npm commands inside the cloned checkout:

Terminal
git clone https://github.com/AnyOAuth/anyoauth.git
# Open the anyoauth checkout in your terminal, then:
npm ci
npm run tooling:check
npm install --global ./packages/cli

Sign in through the website

Terminal
anyoauth login
anyoauth me

The CLI opens AnyOAuth in your browser. Sign in with Google or GitHub, compare the displayed device code with your terminal, and approve the connection. Credentials are saved locally for both CLI and MCP; you don’t need to paste an API key.

For a remote terminal, use anyoauth login --no-browser and open the displayed URL on your own computer. Agents that need to return control to you can use anyoauth login --start, then anyoauth login --complete after you approve. Approval requests last 10 minutes; management sessions last 30 days.

Connect the MCP server

After installing the package, add this to a host that supports mcpServers (such as Claude Desktop):

JSON
{
"mcpServers": {
"anyoauth": {
"command": "anyoauth",
"args": ["mcp"]
}
}
}

Use an absolute executable path if your host cannot find globally installed binaries. Restart or reconnect the host. You can also use anyoauth-mcp as the command without arguments. For Codex, configure the equivalent stdio server:

TOML
[mcp_servers.anyoauth]
command = "anyoauth"
args = ["mcp"]

The agent calls anyoauth_login to open the website and show you a code, then anyoauth_completeLogin after approval. If you already ran anyoauth login, the MCP server uses that saved session automatically.

Create a project

Terminal
anyoauth list-projects
anyoauth create-project --json '{"name":"My app","redirectUris":["http://localhost:3000/auth/callback"],"providers":["google","github"]}'

In MCP, call anyoauth_listProjects and anyoauth_createProject with the same fields. The result includes project.id and a one-time clientSecret. Save the secret in your backend’s secret configuration before closing the result. AnyOAuth manages the provider applications; you don’t need your own Google/GitHub app.

Use your actual port and exact callback path. For production, register an HTTPS URL. See projects and callback protection.

Discover commands and tools

Terminal
anyoauth commands
anyoauth create-project --help
anyoauth providers
anyoauth list-project-users --id app_YOUR_PROJECT_ID

CLI commands and MCP input schemas are generated from the same sign-in JSON contract and management JSON contract. Fields and validation match on both surfaces. The CLI accepts generated field flags, inline --json, or --input file.json (--input - reads stdin). API results are JSON; errors go to stderr with a nonzero exit.

Management tokens control your projects and identities. They are different from the 15-minute profile tokens used by application login. The skill guides your agent through the SDK integration, including browser-bound state/PKCE, backend code exchange, identity lookup, and your application’s own session.

Local development and sign-out

For a local AnyOAuth checkout, set ANYOAUTH_API_ORIGIN=http://localhost:8787 when running the CLI or MCP. Credentials are scoped to that origin, so a development token isn’t used against production. The shared credential directory defaults to ~/.config/anyoauth; ANYOAUTH_CONFIG_DIR overrides it. Files use owner-only permissions on POSIX systems.

Terminal
anyoauth logout

This revokes the installation’s saved management token. Application user sessions are owned by your app; see sessions.