Prompt
How do I set up OAuth for a mobile app?
Latest observation
Oct 6, 2026
OpenAI APIWeb search: off
Setting up OAuth for a mobile app usually means using OAuth 2.0 with the Authorization Code flow + PKCE. That’s the recommended approach for native mobile apps.
High-level steps
-
Register your app with the OAuth provider
- Create an app/client in the provider’s developer console.
- Get a client ID.
- Set a redirect URI for your mobile app.
-
Use Authorization Code + PKCE
- Your app opens the provider’s login page in the system browser.
- The user signs in and approves access.
- The provider redirects back to your app with an authorization code.
- Your app exchanges that code for access token (and usually a refresh token).
- PKCE prevents interception attacks.
-
Handle redirect back into the app
- iOS: custom URL scheme or universal links
- Android: app links / intent filters
- Cross-platform: same concept, platform-specific setup
-
Store tokens securely
- Use Keychain on iOS, Keystore/EncryptedSharedPreferences on Android.
- Don’t store tokens in plain text or logs.
-
Call your API with the access token
- Send
Authorization: Bearer <token>in requests.
- Send
-
Refresh tokens when needed
- When access tokens expire, use the refresh token to get a new access token.
- If refresh fails, send the user through login again.
Recommended flow for mobile: Authorization Code + PKCE
1) Generate PKCE values
- code verifier: random secret string created by the app
- code challenge: derived from the verifier using SHA-256 and Base64URL
2) Start login in the browser
Redirect user to something like:
GET https://provider.com/oauth/authorize?
response_type=code&
client_id=YOUR_CLIENT_ID&
redirect_uri=YOUR_REDIRECT_URI&
scope=openid%20profile%20email&
code_challenge=YOUR_CODE_CHALLENGE&
code_challenge_method=S256
3) Receive the authorization code
The provider redirects to:
YOUR_REDIRECT_URI?code=AUTH_CODE&state=RANDOM_STATE
- Validate the
stateto prevent CSRF.
4) Exchange code for tokens
Your app sends a POST request to the token endpoint:
POST https://provider.com/oauth/token
Content-Type: application/x-www-form-urlencoded
grant_type=authorization_code&
client_id=YOUR_CLIENT_ID&
code=AUTH_CODE&
redirect_uri=YOUR_REDIRECT_URI&
code_verifier=YOUR_CODE_VERIFIER
The response usually includes:
access_tokenrefresh_token(sometimes)expires_inid_tokenif using OpenID Connect
Mobile-specific best practices
- Use the system browser, not an embedded webview, for login.
- Use PKCE always.
- Use universal links/app links if possible instead of custom schemes, because they’re harder to hijack.
- Validate state on return.
- Never ship a client secret in a mobile app.
- Keep scopes minimal.
- Log out properly by clearing local tokens and optionally revoking refresh tokens.
Platform notes
iOS
- Common options:
ASWebAuthenticationSession- Universal Links
- Custom URL schemes if needed
- Store tokens in Keychain
Android
- Common options:
- Chrome Custom Tabs
- App Links / intent filters
- Store tokens in EncryptedSharedPreferences or Android Keystore-backed storage
Libraries you can use
- AppAuth (excellent for OAuth/OIDC on iOS and Android)
- MSAL for Microsoft identity
- Provider SDKs if they support system-browser-based auth
If you’re using OpenID Connect
If you also need user identity, use OIDC on top of OAuth:
- add
scope=openid - you’ll get an
id_token - use the provider’s userinfo endpoint or decode the ID token for basic profile info
If you want, I can also give you:
- a step-by-step iOS example,
- an Android example, or
- a backend + mobile architecture diagram.