Prompt
Apple login mobile app OAuth
Latest observation
Oct 6, 2026
OpenAI APIWeb search: off
If you want “Sign in with Apple” in a mobile app using OAuth / OpenID Connect, here’s the practical setup.
1) What Apple uses
Apple login is OAuth 2.0 + OpenID Connect.
You typically use:
- Authorization endpoint:
https://appleid.apple.com/auth/authorize - Token endpoint:
https://appleid.apple.com/auth/token - Issuer:
https://appleid.apple.com
2) Recommended mobile flow
For iOS/Android mobile apps, use the Authorization Code Flow with PKCE.
Why:
- Safer than implicit flow
- Works well with mobile apps
- Avoids embedding a client secret in the app
3) Apple Developer setup
You need to create/configure:
- App ID / Bundle ID
- Sign In with Apple enabled
- Service ID if you’re doing web-based auth or backend exchange
- Key for generating the Apple client secret on your backend
- Redirect URI registered in Apple Developer portal
4) Typical flow
- App opens Apple sign-in UI.
- User authenticates with Apple.
- Apple returns an authorization code.
- App sends code to your backend.
- Backend exchanges code for tokens using:
client_idclient_secret(JWT signed with your Apple private key)coderedirect_uri
- Backend verifies the
id_token. - Backend creates your app session / user account.
5) Important Apple-specific notes
- Apple only returns the user’s name/email the first time the user authorizes.
- Use the
subclaim in theid_tokenas the stable Apple user identifier. - The client secret is a JWT signed with your Apple private key (
ES256), not your app secret. - Refresh tokens may be available depending on flow and scopes.
6) Example token exchange
Backend POST to:
https://appleid.apple.com/auth/token
Form fields:
client_idclient_secretcodegrant_type=authorization_coderedirect_uri
7) JWT client secret claims
When creating the Apple client secret JWT:
iss: Your Apple Team IDiat: Issued at timeexp: Expiration time (Apple allows up to 6 months)aud:https://appleid.apple.comsub: Your Service ID / client_id
8) Best practice
For mobile apps:
- Use the native Apple Sign In SDK if available
- Or use OAuth2 + PKCE
- Verify the
id_tokenon your backend - Never trust only the app-side response
If you want, I can give you:
- a full Apple OAuth flow diagram,
- iOS Swift example,
- Android/Kotlin example, or
- backend token exchange code in Node/Python/Java.
Brands