Skip to content

Social login

Configure social OAuth providers while keeping provider-ready separate from production support.

Provider status

Social login is provider-ready until real provider callback L4 exists. XID has local callback, profile mapping, nonce, policy, and organization gate coverage, but real provider secrets and callbacks are required before production-supported claims.

Provider Protocol Status
GitHub OAuth authorization code Provider-ready, missing real GitHub callback L4.
Google OIDC authorization code Provider-ready, missing real Google callback L4.
Microsoft account OIDC authorization code Provider-ready, separate from Microsoft Entra ID.
Apple Sign in with Apple Provider-ready, missing real Apple web configuration and callback L4.

Configuration contract

  • Provider credentials are stored as secret references and are never returned to the browser.
  • Hosted Auth only displays enabled providers that have credentials and organization policy permission.
  • Callbacks verify state, nonce, issuer, audience, and email policy before creating or linking users.
  • GitHub social login is separate from GitHub Enterprise Cloud SAML or SCIM.
  • Microsoft account login is separate from Microsoft Entra ID enterprise SSO.
Navigation

Type to search...

Use arrow keys to navigateEnter to selectEscape to close