AppleSignInConfig
constructor(appCallbackUri: String, servicesId: String = APPLE_SERVICES_ID, redirectUri: String = APPLE_SIWA_REDIRECT_URI, scopes: Set<AppleScope> = setOf(AppleScope.NAME, AppleScope.EMAIL))(source)
Parameters
appCallbackUri
the URI your server 302s to, which your app declares as a deep link. An https:// App Link (with assetlinks.json and android:autoVerify="true") is the right choice; a custom scheme works but any app can register it, which is a real account-takeover vector.
scopes
empty means no server bounce is required — and no name or email, ever. See AppleSiwaServer.