Prompt
I need to let users sign in with multiple providers
Latest observation
Oct 6, 2026
OpenAI APIWeb search: off
To let users sign in with multiple providers, the key idea is to separate authentication methods from user accounts.
Recommended approach
1. Create one internal user record
Each person should have a single app user account, even if they can log in with:
- Apple
- GitHub
- email/password
- etc.
2. Store linked identities separately
Have a table/collection for external identities, for example:
-
usersidnameemail- ...
-
auth_identitiesiduser_idprovider(google,github,apple)provider_user_idemail_at_logincreated_at
This lets one user link multiple providers to the same account.
3. Use a linking flow
When someone signs in with a provider:
- If provider identity already exists → log them in
- If provider identity is new:
- If you trust the email and it matches an existing user, optionally prompt to link
- Otherwise create a new user
4. Handle account linking carefully
Avoid automatically merging accounts just because emails match unless:
- the provider verifies the email
- and your security policy allows it
For higher security, do:
- “We found an existing account with this email. Please sign in and link this provider.”
5. Let users manage linked providers
In account settings, show:
- connected providers
- add/remove provider
- primary login method
- recovery options
Common edge cases
- Same email across providers
- Providers that don’t always return email
- Users signing up with one provider, then later using another
- Users removing their only login method
- Email changes at the provider side
Practical rule
Never use email alone as the unique identity key.
Use:
providerprovider_user_id
as the true external identity.
If you want, I can also give you:
- a database schema
- a login/linking flow diagram
- code examples for NextAuth, Auth0, Firebase, Supabase, or custom auth