Prompt
I need account linking for email/password plus social login
Latest observation
Oct 6, 2026
OpenAI APIWeb search: off
You want one user account to support both:
- email + password login
- social login (Google, Apple, Facebook, etc.)
This is a common setup, and the key is to model users in a way that supports multiple auth identities per person.
Recommended approach
1) Keep a single users record
Store the actual person/account separately from login methods.
Example:
usersidemailnamecreated_at...
2) Add an auth_identities / linked_accounts table
Each login method gets its own row.
Example:
auth_identitiesiduser_idprovider(password,google,apple,facebook)provider_user_id(sub / subject / id from provider)email(optional)password_hash(only for password auth, or store elsewhere)created_at
A single user can have:
- one email/password identity
- one Google identity
- one Apple identity
- etc.
Linking flow
A) User signs up with email/password
- Create
usersrow - Create password auth identity linked to that user
B) User later signs in with Google
- Verify Google token
- Check whether
provider_user_idalready exists - If not, see whether the Google email matches an existing user
- If the user is already authenticated and explicitly wants to link, attach the Google identity to that user
- Prevent accidental merges without verification
Important security rule
Do not automatically link accounts only because emails match unless the email is:
- verified by the provider, and
- your app’s policy allows it
Better:
- if the user is logged in, they can click “Link Google account”
- if not logged in, ask them to authenticate first or confirm ownership
Typical user experience
Account settings page
Show:
- Email/password: linked
- Google: not linked → “Connect”
- Apple: linked → “Disconnect”
Linking steps
- User logs into their existing account
- Clicks “Connect Google”
- Redirects to Google OAuth
- On callback, you associate that Google identity with the current user
Data model example
users
- id
- email
- name
- email_verified
- created_at
auth_identities
- id
- user_id
- provider
- provider_user_id
- email
- password_hash
- created_at
Constraints:
provider + provider_user_idmust be unique- optional: one password identity per user
- optional: one identity per provider per user
Edge cases to plan for
- User signs up with email/password using
a@x.com, then later logs in with Google using the same email - User has multiple social providers connected
- Provider changes email later
- User wants to unlink a provider
- User deletes their account
If you want, I can help with one of these next:
- DB schema
- API endpoints
- OAuth linking flow
- Firebase / Supabase / Auth0 implementation
- Frontend UX for linking/unlinking
If you tell me your stack, I can give you an exact implementation.