Account and projects
Register your application, obtain credentials and configure its providers and callbacks.
Your AnyOAuth account
Sign in to the dashboard using Google or GitHub. Returning sign-ins resume the same provider-scoped owner account. Accounts are not linked by email.
Create an application
Choose New project, give the application a name, select Google and/or GitHub, and add the exact callback URLs your backend handles. Use HTTPS in production. HTTP loopback is available for local development.
Keep the credentials on your backend
The project ID is the public client ID. The client secret is displayed once on creation or rotation; store it in your server’s secret manager. Do not put it in browser JavaScript, an Expo/native app, a URL, or a public repository.
Update callbacks and providers
Each project owns its own callback allowlist and provider selection. The API checks those settings when starting authorization and again before completing the transaction. Deployment-wide provider availability is separate from project selections.
Rotate or retire a project
Secret rotation invalidates the old secret, outstanding authorization transactions, handoff codes and profile tokens. Deleting the project removes its associated identities and grants. Your application’s own sessions remain your responsibility.