HACKER Q&A
📣 brittpart_

Sign Up with Facebook/Apple/Google – API or OAuth?


What is this technology called? An API, OAuth? I'm trying to do some research on how this works but I'm not sure what I should be researching.


  👤 noodlesUK Accepted Answer ✓
Social login and SSO is generally implemented these days as OIDC (which is based on oauth2). You can read the RFCs for it, and they pretty much explain the whole thing.

Oauth2: https://tools.ietf.org/html/rfc6749

PKCE (replaces the implicit flow): https://tools.ietf.org/html/rfc7636

OIDC: https://openid.net/specs/openid-connect-core-1_0.html


👤 cuu508
They don't always make it obvious, but it is usually OAuth2, sometimes with tweaks