Skip to content

Social providers

Supported providers: Google, GitHub, Apple, Microsoft, Facebook, Discord, GitLab, X (Twitter), LinkedIn, Slack and Zoom.

  1. In the dashboard open Authentication → Providers and choose a provider. The page shows where to create the OAuth app and the exact callback URL to register (the same URL for every social provider of the project).
  2. Create the OAuth app at the provider and register that callback URL.
  3. Enter the client ID and client secret in PotaLab Base and enable the provider. Client secrets are write-only: they are stored encrypted and never returned.

Microsoft supports a tenant setting (default common) and self-managed GitLab an issuer URL.

// login page
await base.auth.signInWithOAuth({
provider: "google",
redirectTo: "https://app.example.com/auth/callback",
scopes: ["email"], // optional
})
// on /auth/callback
const code = new URL(location.href).searchParams.get("code")!
await base.auth.exchangeCodeForSession(code)

With skipBrowserRedirect: true the call returns data.url instead of navigating, which is what mobile apps need (see React Native).

On every OAuth sign-in Base resolves the account in this order:

  1. An existing identity signs in as its user.
  2. Otherwise, a user with the same verified provider email gets the identity linked.
  3. Otherwise, a new user is created.

An unverified provider email that matches an existing account is refused with email_exists, so an account cannot be taken over. Automatic linking can be switched off per project; users then link explicitly with auth.linkIdentity({ provider, redirectTo }) while signed in. Facebook rarely reports a verified email, so Facebook identities usually do not link implicitly.