Prompt
How do I let users sign in with Apple on iPhone and the web?
Latest observation
Oct 6, 2026
OpenAI APIWeb search: off
To support Sign in with Apple on both iPhone (iOS app) and the web, you’ll usually implement two separate client flows that both verify the same Apple-issued identity token on your backend.
1) Set up Apple Developer configuration
In the Apple Developer portal:
- Enable “Sign in with Apple” for your App ID.
- Create or verify:
- iOS App ID / Bundle ID
- Web Service ID (for web login)
- Return URL(s) for the web flow
- Create a Sign in with Apple key (
.p8)- Note the Key ID
- Note your Team ID
- Your backend will use those to exchange authorization codes / verify tokens.
2) iPhone / iOS app flow
On iPhone, use Apple’s native authentication framework:
- Framework: AuthenticationServices
- Class: ASAuthorizationAppleIDProvider
- Request: ASAuthorizationAppleIDRequest
Basic iOS steps
- Create an Apple ID request.
- Set requested scopes:
.fullName.email
- Present the Apple sign-in UI.
- Receive:
identityTokenauthorizationCode- user name/email only on first authorization
- Send the
identityTokenand/orauthorizationCodeto your backend. - Backend verifies the token and creates your app session.
iOS example (Swift)
import AuthenticationServices
let provider = ASAuthorizationAppleIDProvider()
let request = provider.createRequest()
request.requestedScopes = [.fullName, .email]
let controller = ASAuthorizationController(authorizationRequests: [request])
controller.delegate = self
controller.presentationContextProvider = self
controller.performRequests()
On success:
func authorizationController(controller: ASAuthorizationController, didCompleteWithAuthorization authorization: ASAuthorization) {
if let credential = authorization.credential as? ASAuthorizationAppleIDCredential {
let identityTokenData = credential.identityToken
let authorizationCodeData = credential.authorizationCode
let user = credential.user
// Send token/code to backend
}
}
3) Web flow
For the web, use Apple’s OAuth-style redirect flow.
Web steps
- Redirect user to Apple’s authorization endpoint.
- User authenticates and Apple redirects back to your
redirect_uri. - You receive:
codeid_tokenstate
- Verify
statefor CSRF protection. - Send the code/token to your backend.
- Backend verifies the identity token and establishes a session.
Typical authorization URL
https://appleid.apple.com/auth/authorize
Common parameters:
client_id= your Service IDredirect_uri= allowed return URLresponse_type=code id_tokenscope=name emailstate= random CSRF tokenresponse_mode= oftenform_post
Example redirect URL
https://appleid.apple.com/auth/authorize?
client_id=com.example.web&
redirect_uri=https://example.com/auth/apple/callback&
response_type=code%20id_token&
scope=name%20email&
state=RANDOM_CSRF_TOKEN&
response_mode=form_post
4) Backend verification
For both iOS and web, your backend should validate Apple’s JWT identity token.
Validate:
- Signature using Apple’s public keys
iss=https://appleid.apple.comaud= your app’s client ID:- iOS: your Bundle ID (or sometimes app-specific client depending on flow)
- Web: your Service ID
expnot expirednonceif you used one
Then:
- Find or create the user in your database
- Link Apple account by the token’s
subclaim (stable unique Apple user ID per client)
5) Important Apple Sign in details
- Apple returns email/name only the first time the user authorizes your app.
- The user may choose Hide My Email, so store Apple’s unique user identifier (
sub) instead of relying on email. - If you need to support both app and web for the same user, plan for account linking:
- same Apple identity may produce different
subvalues depending on client/app configuration - use your own internal user record and link identities carefully
- same Apple identity may produce different
6) Recommended architecture
- iOS app
- Native Apple sign-in UI
- Sends
identityToken/authorizationCodeto backend
- Web
- Redirect-based Apple OAuth flow
- Sends callback data to backend
- Backend
- Verifies Apple JWTs
- Creates your app session / JWT / cookie
- Stores the Apple user identifier and account links
7) If you want to support both with one backend
A common pattern:
- iOS/web client signs in with Apple.
- Client sends Apple response to backend.
- Backend verifies token.
- Backend issues your own session token/cookie.
- App and website both use your own auth session after Apple login.
That gives you one consistent account system across iPhone and web.
If you want, I can also give you:
- a step-by-step Apple Developer setup checklist
- Swift iOS sample code
- JavaScript/web implementation
- backend token verification example in Node, Python, or Go