Prompt
What should I use for authentication on mobile and web?
Latest observation
Oct 6, 2026
OpenAI APIWeb search: off
For both mobile and web, the most common and generally best choice is:
Use OAuth 2.0 / OpenID Connect (OIDC) with PKCE
Why this is usually the best option
- Works well for web and mobile
- Industry standard
- Supports social login, enterprise SSO, and your own accounts
- Safer than rolling your own auth
- PKCE protects public clients like mobile apps and SPA web apps
Recommended setup by app type
1) Web app
- Server-rendered web app: use OIDC Authorization Code Flow
- SPA (React/Vue/etc.): use OIDC Authorization Code Flow with PKCE
- Store session in secure, HttpOnly cookies if you have a backend
2) Mobile app
- Use OIDC Authorization Code Flow with PKCE
- Open the login page in the system browser / ASWebAuthenticationSession / Chrome Custom Tabs
- Do not use embedded webviews for login if you can avoid it
Token handling
- Prefer short-lived access tokens
- Use refresh tokens only when appropriate, and store them securely:
- iOS: Keychain
- Android: Keystore / EncryptedSharedPreferences
- On web, prefer HttpOnly secure cookies for session management when possible
Good identity providers
If you don’t want to build auth yourself, consider:
- Auth0
- AWS Cognito
- Firebase Auth
- Azure AD B2C / Entra ID
- Okta
- Clerk (popular for modern apps)
If you want a simple rule
- Modern app with mobile + web: use OpenID Connect + PKCE
- Want less work: use a managed provider like Auth0, Firebase, or Cognito
If you tell me your stack (e.g. React + React Native, Next.js + iOS/Android, etc.), I can recommend the exact flow and storage strategy.