Prompt
How do I connect multiple identity providers to one user account?
Latest observation
To connect multiple identity providers (Google, GitHub, Microsoft, etc.) to a single user account, you typically implement account linking in your auth system.
Core idea
Instead of treating “user identity” as tied to one provider, create:
- One internal user record in your database
- Many external identities linked to that user
Example data model
usersidemailname- etc.
user_identitiesiduser_id→users.idprovider→google,github,azureadprovider_user_id→ the subject/unique ID from that provideremail_at_login(optional)created_at
This lets one account have multiple linked logins.
Typical flow
1) User signs in with a provider
- They authenticate with Google, GitHub, etc.
- Your app receives a provider-specific user ID and profile info
2) Find or create the internal user
- Check whether that
(provider, provider_user_id)already exists inuser_identities - If yes, log the user into the linked
user_id - If no, decide whether to:
- create a new user, or
- attach this identity to an existing user
3) Link additional providers
When the user is already logged in and clicks “Connect Google” or “Link GitHub”:
- Authenticate with the new provider
- Verify it’s the same person
- Insert a new row into
user_identitiestied to the sameuser_id
Important security rule
Do not automatically merge accounts just because emails match unless you trust email verification and your policy allows it.
Safer options:
- Link only when the user is already signed in
- Or require an explicit account-merge confirmation
This avoids accidental takeover if two providers expose the same email or if email ownership differs.
Recommended linking logic
Safe approach
- User is logged into their existing account
- They choose “Link another provider”
- You run OAuth/OpenID Connect flow for the new provider
- On callback, verify:
- the provider identity is valid
- the provider identity isn’t already linked to a different account
- Add it to the current user account
If user is not logged in
- Try to find an existing linked identity
- If not found, create a new account
- Optionally ask the user to sign in first to link accounts
Edge cases to handle
- Same provider identity already linked to another user
- Provider email changes
- Provider does not guarantee email uniqueness
- Unverified emails
- Users want to unlink a provider
- Users lose access to one provider and need recovery options
Provider-specific note
If you use OpenID Connect, the key identifier is usually:
issuer+subject(iss+sub)
That pair should be treated as the unique external identity, not just email.
Practical UX
Add an “Account settings” page with:
- Linked accounts
- “Connect Google/GitHub/etc.”
- “Disconnect” buttons
- Recovery options if one login method is removed
Short answer
Use a single internal user account with a many-to-one table of linked identities. Link new providers only after verifying ownership, preferably while the user is already authenticated.
If you want, I can show:
- a sample database schema,
- a Node/Python/Go implementation, or
- the exact flow for OAuth/OIDC account linking.