Package-level declarations
Types
Sign in with Apple on Android. There is no native SDK — this is Apple's OAuth web flow, and it needs a server. AppleSiwaServer documents exactly which server, and why no client-only path exists once you ask for name and email.
Google sign-in through Credential Manager — the only supported path since the legacy GoogleSignInClient was deprecated.
Client-side configuration for Sign in with Apple through the web flow (Android).
The server half of Sign in with Apple on Android, written down because there is no client-only path and pretending otherwise is how this ships broken.
The parts of Sign in with Apple on Android that are pure string work: building the authorize URL, and reading the callback your server bounced back. Platform-free on purpose — this is where the tests are, and it is identical whether the browser is a Custom Tab, an external browser, or a WebView you should not be using for OAuth.
A started Apple web sign-in. Hold it until the deep link comes back.
Result of AndroidAppleSignIn.begin — either the browser is up, or the reason it is not.
Configuration for GetGoogleIdOption.
Sign in with Apple on iOS, natively — no Services ID, no redirect URI, no server bounce. The App ID's Sign In with Apple capability and the matching entitlement are the whole configuration, which is why none of the __PROVISION_APPLE_*__ values appear on this side. (Your server still needs them to exchange or revoke the code; see AppleSiwaServer.)
Reason-carrying capability flag. Four states, not a Boolean, because the three failures want three different UIs: hide the button, offer "add an account", say "not on this device".
What a provider hands back. Everything here is untrusted client input until a server verifies it — a debugger can hand your app any idToken it likes.
Third-party sign-in for the toolkit: the shared vocabulary, and the store rules attached to it.
Where an app keeps its auth secrets, and nothing else.
Properties
Apple's Services ID — the OAuth client_id for Sign in with Apple on the web and on Android. Not the App ID: iOS uses the App ID capability and needs none of these three values.
Key ID of the Sign in with Apple .p8. Server-side only: it is the kid of the client secret JWT.
The redirect_uri registered against the Services ID. Must be an https URL you control that runs code — see AppleSiwaServer for why it cannot be an app link when scopes are requested.
Apple Developer Team ID. Server-side only: it is the iss of the client secret JWT.
The WEB OAuth client ID from the Google Cloud console, not the Android one.