Prompt

How do I prevent duplicate accounts with OAuth sign-in?

Technology / Identity & Access1 observationLast seen Oct 6, 2026

Latest observation

Oct 6, 2026OpenAI APIWeb search: off

To prevent duplicate accounts with OAuth sign-in, make one user identity in your database and link OAuth identities to it instead of creating a new account every time.

Core approach

Use this rule:

  • One app user = one internal user_id
  • Each OAuth login provider account = a linked identity, e.g.:
    • Google sub
    • GitHub id
    • Microsoft oid
  • Store those identities in a separate table and tie them to the same user.

Recommended database model

users

Your app’s canonical user record:

  • id
  • email
  • name
  • created_at

oauth_accounts

Linked login identities:

  • id
  • user_id (FK to users.id)
  • provider (google, github, etc.)
  • provider_user_id (the unique ID from the provider)
  • provider_email
  • created_at

Add a unique constraint on:

  • (provider, provider_user_id)

Optionally also on:

  • email in users if your app requires one account per email

Sign-in flow

When a user signs in with OAuth:

  1. Identify provider account
    • Read the provider’s unique user ID.
  2. Check if this OAuth identity already exists
    • If yes, log in the linked user_id.
  3. If not, check for an existing user by verified email
    • Only if the provider gives a verified email.
  4. If matching user exists, link the new OAuth account
    • Add a row in oauth_accounts.
  5. Otherwise create a new user
    • Create users, then create oauth_accounts.

Important anti-duplication rules

1. Match on provider user ID, not email alone

Emails can change, be shared, or be unverified. The provider’s unique ID is the real stable identifier.

2. Only auto-link by email if it is verified

Otherwise someone could claim another person’s email and get linked incorrectly.

3. Enforce uniqueness in the database

Application logic alone is not enough. Add constraints to prevent race conditions.

4. Support account linking

Let users connect multiple OAuth providers to the same account after login.

Good linking strategy

If a user signs in with Google and later GitHub:

  • If Google account already exists in oauth_accounts, return the same user_id
  • If GitHub login has the same verified email, you may:
    • auto-link if policy allows, or
    • require the user to be signed in first and explicitly link GitHub

The safest approach is:

  • Auto-link only when provider says email is verified
  • Otherwise require explicit account linking

Example logic

Pseudo-flow:

oauth_callback(provider, provider_user_id, email, email_verified):
    if oauth_account exists for (provider, provider_user_id):
        sign in as oauth_account.user_id

    else if email_verified and user exists with email:
        create oauth_account linked to that user
        sign in as that user

    else:
        create new user
        create oauth_account linked to new user
        sign in as new user

Best practice

If your app supports email/password too:

  • Use the same users table for both password and OAuth users
  • Store password hash only for users who use passwords
  • Treat OAuth identities as login methods, not separate accounts

Security note

Never allow account linking based only on:

  • unverified email
  • display name
  • profile picture
  • username

These are not reliable identity proofs.

If you want, I can also give you:

  • a SQL schema
  • an implementation example in Node/Express, Django, Rails, or Laravel
  • a NextAuth/Auth0/Passport.js setup to avoid duplicates

Observation history

How did Obsurfable measure this prompt?

Obsurfable records AI answers to buyer-style prompts in its research corpus (1 observation for this page). Metrics are distributions over observations, not a single static ranking.

Which AI systems does Obsurfable collect answers from?

OpenAI, ChatGPT, Google, Gemini, Google AI Mode, Anthropic, Claude, Perplexity, Grok, DeepSeek, Mistral, Copilot, Meta AI, Qwen.

How can brands improve their AEO?

Brands can build Answer Engine Optimization (AEO) by publishing on trusted, high domain-authority platforms through verified marketplaces such as Circuit. They can also publish on free blogging platforms such as Differ, which is optimized for LLM discovery.

Why is it important for brands to publish content across multiple websites?

Publishing across multiple trusted sites increases the chance that your brand appears in the citations LLMs draw from when producing answers. Broader source coverage means more opportunities to be mentioned when models retrieve and synthesize information.

Want this interpreted for your brand?

Explorer is the free public corpus. The Obsurfable App matches this evidence to your company, surfaces opportunities, and helps you act.