SocialSignIn
Third-party sign-in for the toolkit: the shared vocabulary, and the store rules attached to it.
Compliance — App Store Guideline 4.8 and 5.1.1(v)
4.8 (Login Services). An app that offers any third-party or social login — Google, Facebook, a partner SSO — must also offer an equivalent login service that limits data collection to name and email, lets the user keep the email private, and does not track them for advertising without consent. Sign in with Apple satisfies 4.8. So shipping AuthProvider.GOOGLE without also shipping AuthProvider.APPLE is a rejection, not a roadmap item. That is why this module implements Apple on both platforms, including the ugly Android web flow — the Android side is not the one that gets reviewed, but the two platforms must offer the same accounts or the same user cannot sign in on their second device.
5.1.1(v) (Account Deletion). An app that supports account creation must let the user start account deletion from inside the app. A "contact support" link does not satisfy it. For an app using Sign in with Apple, deletion must also revoke the Apple grant server-side (POST https://appleid.apple.com/auth/revoke, authenticated with the same client secret JWT as the token exchange) — otherwise the account is gone but Apple still lists the app under the user's Apple ID, which is itself a 5.1.1(v) rejection. Revocation needs the refresh token, so the server has to have stored it at sign-in. Decide that before launch, not at the first rejection.
Neither rule can be satisfied by client code alone, which is the honest reason both appear here: the seam below is only the part of the problem that fits in a library.
Inheritors
Functions
Why the button may not be drawn. SignInAvailability.AVAILABLE is the only green light.
Presents the provider's UI and suspends until the user finishes, cancels, or it fails.