How it works
In the usual authorisation code flow, the app sends the user to the provider (Google, GitHub, Microsoft) with a list of scopes, the permissions it wants. The user signs in there and approves a consent screen, and the provider redirects back with a short-lived code. The app's server swaps that code for an access token, which it presents to the provider's APIs, and often a refresh token for getting new access tokens later. The app never sees the user's password.
OAuth was designed for delegated access (let this app read my calendar), not for proving identity, so social login normally adds OpenID Connect on top, which returns an ID token saying who the user is. GitHub is a notable exception that uses plain OAuth plus a profile API call. Mobile apps and single-page apps cannot keep a client secret, so they use PKCE. OAuth 2.1 gathers these lessons into one specification, requiring PKCE and dropping older flows such as the implicit flow.
For users, social login means no new password and a sign-up that takes seconds. For the app, it means following each provider's rules: a registered developer app, exact redirect URLs, reviews for sensitive scopes, and on iOS the App Store rule that apps offering third-party login must usually also offer Sign in with Apple or a similar privacy-focused option.
OAuth 2.0 and social login pros and cons
Pros
- Sign-up in a couple of clicks, with no new password
- The provider handles password resets, 2FA and suspicious sign-ins
- Usually comes with an email address the provider has verified
- Access tokens let an app use a person's Google, GitHub or Microsoft data with consent
Cons
- Each provider needs its own developer app, keys and redirect URLs
- People without those accounts, or wary of linking them, need another option
- A provider outage, ban or policy change can block sign-ins
- Easy to get subtly wrong by hand (state, PKCE, token checks)
When to use OAuth 2.0 and social login
Pick it when
- Consumer apps where a quick sign-up matters
- Users already live in Google Workspace, Microsoft 365 or GitHub
- The app needs to act on the user's data in another service
Skip it when
- Your audience rarely has, or wants to link, a big-tech account
- You would write the protocol by hand instead of using a tested library or provider
OAuth 2.0 and social login pricing
Free
Free: Google, GitHub and Microsoft charge nothing for sign-in. Sign in with Apple needs a paid Apple Developer Program membership.
Approximate, checked September 2026.What the other tools cost
OAuth 2.0 and social login vs the alternatives
Related terms
More in Auth and identity
Ways to sign in