Google + GitHub sign-in. One profile API.Explore the quickstart

A profile-only security boundary.

AnyOAuth is designed for social sign-in. It does not expose provider tokens or offer access to provider APIs. This page describes the implementation model, not a security certification.

Provider credentials stay server-side

Google identity tokens are validated for signature, issuer, audience, lifetime, and transaction nonce. GitHub profiles are retrieved server-side using the freshly exchanged token. Provider access and refresh tokens are not persisted or returned to customers.

A protected identity handoff

Both legs use authorization codes and PKCE S256. Provider callbacks are bound to a browser cookie and transaction-specific state. Customer callbacks must exactly match a registered URL. Customer backends authenticate with their client secret when exchanging a single-use code.

Short-lived AnyOAuth tokens

Our opaque profile tokens only retrieve one identity within one project. Tokens and client secrets are stored as SHA-256 hashes. Profile tokens expire after 15 minutes and can be revoked. They cannot be used at Google, GitHub, or any other provider.

Identity isolation

Accounts are identified by provider and provider subject within each customer project. Matching emails do not merge identities. Dashboard access checks project ownership, and state-changing dashboard requests validate the origin.

What your application handles

Your application must verify callback state against its initiating browser session, keep its client secret and PKCE verifier on the backend, and create its own user session. Revoking an AnyOAuth token does not log someone out of a session your application has already created.

Stored data

D1 stores project settings, normalized identity profiles, dashboard accounts, hashed credentials, and short-lived sign-in transactions. Expired transaction and token records are removed by scheduled cleanup. Profiles remain until deleted through the dashboard.