Prompt
What should I use for auth if I need redirect-based login on web and mobile?
Latest observation
Oct 6, 2026
OpenAI APIWeb search: off
If you need redirect-based login that works on both web and mobile, the usual best choice is:
Use OpenID Connect (OIDC) on top of OAuth 2.0, with the Authorization Code flow + PKCE
Why this is the right fit
- Redirect-based login is exactly what OIDC is designed for.
- It works well for:
- Web apps: redirect to the identity provider, then back to your app
- Mobile apps: open a browser/tab, then deep-link back into the app
- Authorization Code + PKCE is the modern recommended flow for:
- public clients like mobile apps
- browser-based apps
- apps that should not embed passwords or store client secrets
What to avoid
- Implicit flow: legacy, not recommended
- Password-based login in the app: generally a bad idea unless you fully own the auth system and have a strong reason
Typical setup
Web
- User clicks “Sign in”
- Redirect to the identity provider
- User authenticates
- Provider redirects back to your web app with an authorization code
- Your app exchanges the code for tokens
Mobile
- User taps “Sign in”
- App opens the system browser
- User authenticates
- Provider redirects to a custom URI scheme or universal/app link
- App receives the code and exchanges it for tokens using PKCE
Best practice architecture
Use an external identity provider such as:
- Auth0
- Okta
- Azure AD / Entra ID
- AWS Cognito
- Firebase Auth
- Keycloak
- FusionAuth
These providers handle:
- login pages
- session management
- MFA
- social login
- password reset
- enterprise SSO
In short
Use OIDC Authorization Code Flow with PKCE.
That’s the standard answer for redirect-based login across both web and mobile.
If you want, I can also recommend:
- the best setup for SPA + mobile,
- the best auth provider for your stack, or
- a diagram of the full redirect flow.