Auth and identity · Protocol

OAuth 2.0 and social login

The standard that lets a person give an app limited access to another service without sharing their password, and the basis of 'Sign in with Google', 'Sign in with Apple' and similar buttons.

Ways to sign in · Free · updated

How it works

In the usual authorisation code flow, the app sends the user to the provider (Google, GitHub, Microsoft) with a list of scopes, the permissions it wants. The user signs in there and approves a consent screen, and the provider redirects back with a short-lived code. The app's server swaps that code for an access token, which it presents to the provider's APIs, and often a refresh token for getting new access tokens later. The app never sees the user's password.

OAuth was designed for delegated access (let this app read my calendar), not for proving identity, so social login normally adds OpenID Connect on top, which returns an ID token saying who the user is. GitHub is a notable exception that uses plain OAuth plus a profile API call. Mobile apps and single-page apps cannot keep a client secret, so they use PKCE. OAuth 2.1 gathers these lessons into one specification, requiring PKCE and dropping older flows such as the implicit flow.

For users, social login means no new password and a sign-up that takes seconds. For the app, it means following each provider's rules: a registered developer app, exact redirect URLs, reviews for sensitive scopes, and on iOS the App Store rule that apps offering third-party login must usually also offer Sign in with Apple or a similar privacy-focused option.

OAuth 2.0 and social login pros and cons

Pros

  • Sign-up in a couple of clicks, with no new password
  • The provider handles password resets, 2FA and suspicious sign-ins
  • Usually comes with an email address the provider has verified
  • Access tokens let an app use a person's Google, GitHub or Microsoft data with consent

Cons

  • Each provider needs its own developer app, keys and redirect URLs
  • People without those accounts, or wary of linking them, need another option
  • A provider outage, ban or policy change can block sign-ins
  • Easy to get subtly wrong by hand (state, PKCE, token checks)

When to use OAuth 2.0 and social login

Pick it when

  • Consumer apps where a quick sign-up matters
  • Users already live in Google Workspace, Microsoft 365 or GitHub
  • The app needs to act on the user's data in another service

Skip it when

  • Your audience rarely has, or wants to link, a big-tech account
  • You would write the protocol by hand instead of using a tested library or provider

OAuth 2.0 and social login pricing

Free

Free: Google, GitHub and Microsoft charge nothing for sign-in. Sign in with Apple needs a paid Apple Developer Program membership.

Approximate, checked September 2026.What the other tools cost

OAuth 2.0 and social login vs the alternatives

More in Auth and identity

Ways to sign in

All 17 Auth and identity terms

Crafted in the dark. Shipped to the world.

Tell us what you are building. You get a private project space with a proposal and a line-by-line quote within a day.