03·Hands-on·12 min
Social login with OAuth
OAuth lets your app ask Google (or Kakao, GitHub, Apple) "who is this?" without ever seeing the user's password.
- Your app sends the user to the provider with your client id.
- The user signs in there and approves.
- The provider redirects back with a one-time code.
- Your server trades that code, plus your client secret, for the user's identity.
The client secret is the part that must never reach a browser. That exchange in step 4 is why social login needs a server, and why DontCode stores the secret write-only: you can replace it, never read it back.
Go deeper
Your task
Insight ProjectBackend ProjectIn your project, open Users, then Social Login, and configure one provider with its client id and secret.