Prompt
What should I use for account linking across multiple providers?
Latest observation
Oct 6, 2026
OpenAI APIWeb search: off
For account linking across multiple providers, the safest default is:
Use a stable internal user ID as the primary account, and link each provider’s identity to that user record.
Recommended approach
- One internal user record in your database
- Many linked identities per user, one per provider
- e.g. Google, GitHub, Apple, Microsoft
- Store for each identity:
providernameprovider_user_id(the subject/user ID from that provider)- optional email(s), profile data, tokens if needed
- Authenticate by provider, then look up the linked identity and resolve to your internal user
Why this is better
- Provider emails can change
- Users can have multiple emails
- Two providers may return the same email for different people, or different emails for the same person
- The provider’s unique user ID is usually the only stable identifier within that provider
Common linking strategy
- User signs in with provider A
- If there’s an existing linked identity for
(provider A, provider_user_id), log them in - Otherwise:
- if your app has a verified email match policy, optionally prompt to merge
- or create a new user
- Let users link additional providers from their account settings after re-authentication
Important security note
Don’t auto-link accounts just because the email matches unless:
- the email is verified
- you trust the provider’s verification process
- and you’re comfortable with the account-takeover risk
Good storage model
usersexternal_accountsiduser_idproviderprovider_subjectemailemail_verifiedcreated_atlast_login_at
If you want the simplest rule
Treat (provider, provider_subject) as the canonical external identity and map it to one internal user.
If you want, I can also suggest:
- a database schema
- an account-linking flow
- or provider-specific caveats for Google/Apple/GitHub/Auth0/Cognito.