All the major OAuth providers. One profile API.Explore the quickstart
Documentation navigation

Profiles, tokens and sessions

Use a project-scoped identity and let your application own its authenticated session.

On this page

Identity is scoped to a project

Use the normalized profile’s subject as your application identity key. Google and GitHub identities remain separate, even when their email addresses happen to match. Names, usernames, email and avatars are nullable; emailVerified is a separate signal.

The profile token is an AnyOAuth token

The exchange returns an opaque profile-only token. It is not a provider access token or an OpenID Connect ID token. AnyOAuth never returns upstream provider credentials to customer applications. The schema-generated exchange reference describes its exact shape and lifetime.

Your application owns its session

Fetch the profile on your backend, find or create the corresponding application user, then issue your own secure session cookie or appropriate app session. Revoking a profile token does not retire those application sessions.

Handle errors and retries

On denial, consume the saved transaction and show an explicit retry action. For an ambiguous code-exchange network failure, start a new sign-in rather than automatically reusing a single-use code. Infrastructure may return a non-JSON error; SDKs expose structured protocol/transport errors without raw request details.