03·Hands-on·12 min

Social login with OAuth

OAuth lets your app ask Google (or Kakao, GitHub, Apple) "who is this?" without ever seeing the user's password.

  1. Your app sends the user to the provider with your client id.
  2. The user signs in there and approves.
  3. The provider redirects back with a one-time code.
  4. Your server trades that code, plus your client secret, for the user's identity.

The client secret is the part that must never reach a browser. That exchange in step 4 is why social login needs a server, and why DontCode stores the secret write-only: you can replace it, never read it back.

Go deeper

Your task

Insight ProjectBackend Project

In your project, open Users, then Social Login, and configure one provider with its client id and secret.