SocialIdentity

data class SocialIdentity(val provider: AuthProvider, val idToken: String, val rawNonce: String, val authorizationCode: String? = null, val userId: String? = null, val email: String? = null, val displayName: String? = null, val rawUserJson: String? = null)(source)

What a provider hands back. Everything here is untrusted client input until a server verifies it — a debugger can hand your app any idToken it likes.

The server must, at minimum: verify the JWT signature against the provider's JWKS, check iss and aud, check exp, and check that the nonce claim equals SHA-256(rawNonce) — which is why rawNonce travels back with the identity instead of being discarded. Skipping the nonce check leaves the replay window that the nonce exists to close.

Constructors

Link copied to clipboard
constructor(provider: AuthProvider, idToken: String, rawNonce: String, authorizationCode: String? = null, userId: String? = null, email: String? = null, displayName: String? = null, rawUserJson: String? = null)

Properties

Link copied to clipboard

Apple only: one-time code your server exchanges for an access/refresh token pair.

Link copied to clipboard
Link copied to clipboard
Link copied to clipboard

The OIDC ID token (a JWT). Send to your server; never trust its claims on the client.

Link copied to clipboard
Link copied to clipboard

The unhashed nonce. The server compares SHA-256 of this to the token's nonce claim.

Link copied to clipboard

Apple's user field, verbatim JSON, present only on the very first authorization. Apple never sends the name again — not on re-sign-in, not on token refresh. Persist it server-side on first sight or it is gone for that Apple ID forever (short of the user revoking the grant in Settings and starting over).

Link copied to clipboard

Apple's stable sub for this app. Google's is inside idToken and is read server-side.