Package-level declarations

Types

Link copied to clipboard
class AndroidAppleSignIn(context: Context, config: AppleSignInConfig, nonceSource: () -> String = { newRawNonce() }, stateSource: () -> String = { newRawNonce() })

Sign in with Apple on Android. There is no native SDK — this is Apple's OAuth web flow, and it needs a server. AppleSiwaServer documents exactly which server, and why no client-only path exists once you ask for name and email.

Link copied to clipboard
class AndroidGoogleSignIn(activityContext: Context, config: GoogleSignInConfig = GoogleSignInConfig(), credentialManager: CredentialManager = CredentialManager.create(activityContext), nonceSource: () -> String = { newRawNonce() }) : SocialSignIn

Google sign-in through Credential Manager — the only supported path since the legacy GoogleSignInClient was deprecated.

Link copied to clipboard
enum class AppleScope : Enum<AppleScope>
Link copied to clipboard
data class AppleSignInConfig(val appCallbackUri: String, val servicesId: String = APPLE_SERVICES_ID, val redirectUri: String = APPLE_SIWA_REDIRECT_URI, val scopes: Set<AppleScope> = setOf(AppleScope.NAME, AppleScope.EMAIL))

Client-side configuration for Sign in with Apple through the web flow (Android).

Link copied to clipboard

The server half of Sign in with Apple on Android, written down because there is no client-only path and pretending otherwise is how this ships broken.

Link copied to clipboard

The parts of Sign in with Apple on Android that are pure string work: building the authorize URL, and reading the callback your server bounced back. Platform-free on purpose — this is where the tests are, and it is identical whether the browser is a Custom Tab, an external browser, or a WebView you should not be using for OAuth.

Link copied to clipboard
data class AppleWebPending(val authorizeUrl: String, val state: String, val rawNonce: String)

A started Apple web sign-in. Hold it until the deep link comes back.

Link copied to clipboard
sealed interface AppleWebStart

Result of AndroidAppleSignIn.begin — either the browser is up, or the reason it is not.

Link copied to clipboard
Link copied to clipboard
data class GoogleSignInConfig(val serverClientId: String = GOOGLE_WEB_CLIENT_ID, val filterByAuthorizedAccounts: Boolean = true, val signUpFallback: Boolean = true, val autoSelectEnabled: Boolean = true)

Configuration for GetGoogleIdOption.

Link copied to clipboard
class IosAppleSignIn(anchor: () -> UIWindow, nonceSource: () -> String = { newRawNonce() }) : SocialSignIn

Sign in with Apple on iOS, natively — no Services ID, no redirect URI, no server bounce. The App ID's Sign In with Apple capability and the matching entitlement are the whole configuration, which is why none of the __PROVISION_APPLE_*__ values appear on this side. (Your server still needs them to exchange or revoke the code; see AppleSiwaServer.)

Link copied to clipboard

Reason-carrying capability flag. Four states, not a Boolean, because the three failures want three different UIs: hide the button, offer "add an account", say "not on this device".

Link copied to clipboard
sealed interface SignInOutcome
Link copied to clipboard
data class SocialIdentity(val provider: AuthProvider, val idToken: String, val rawNonce: String, val authorizationCode: String? = null, val userId: String? = null, val email: String? = null, val displayName: String? = null, val rawUserJson: String? = null)

What a provider hands back. Everything here is untrusted client input until a server verifies it — a debugger can hand your app any idToken it likes.

Link copied to clipboard
interface SocialSignIn

Third-party sign-in for the toolkit: the shared vocabulary, and the store rules attached to it.

Link copied to clipboard
class TokenStore(settings: Settings, persistedKey: String)

Where an app keeps its auth secrets, and nothing else.

Properties

Link copied to clipboard

Apple's Services ID — the OAuth client_id for Sign in with Apple on the web and on Android. Not the App ID: iOS uses the App ID capability and needs none of these three values.

Link copied to clipboard

Key ID of the Sign in with Apple .p8. Server-side only: it is the kid of the client secret JWT.

Link copied to clipboard

The redirect_uri registered against the Services ID. Must be an https URL you control that runs code — see AppleSiwaServer for why it cannot be an app link when scopes are requested.

Link copied to clipboard

Apple Developer Team ID. Server-side only: it is the iss of the client secret JWT.

Link copied to clipboard

The WEB OAuth client ID from the Google Cloud console, not the Android one.

Functions

Link copied to clipboard
fun newRawNonce(bytes: Int = NONCE_BYTES): String

A fresh, cryptographically random nonce/state value as lowercase hex.

fun newRawNonce(bytes: Int = NONCE_BYTES): String

A fresh, cryptographically random nonce/state value as lowercase hex.