Sign in with Apple is what iPhone users reach for first, and the App Store requires it the moment an iOS app offers any other social login. Unlike Google or Kakao, Apple does not hand you a client secret: DontCode signs one for every login from a private key you download once. So this guide collects four values, a Services ID, your Team ID, a Key ID and the key file, and it needs a paid Apple Developer Program membership (USD 99 a year).
Go to developer.apple.com/account and sign in. Sign in with Apple is only available to Apple Developer Program members, so enroll first if the account is a free one.
Open "Membership details" in the sidebar. The Team ID is the ten-character code shown there. Keep it for the last step.
Go to "Certificates, Identifiers & Profiles" → "Identifiers" → the plus button → "App IDs" → "App". Give it a description and an explicit Bundle ID such as com.yourcompany.yourapp. Under Capabilities, tick "Sign in with Apple". Click Continue, then Register. If you already have an App ID for an iOS app, open it and tick the capability there instead.
Back in "Identifiers", click the plus button → "Services IDs". The description is the name people see on Apple's sign-in sheet, so use your product name. The identifier is what DontCode calls the Services ID, for example com.yourcompany.yourapp.web. Register it, then open it and tick "Sign in with Apple" → "Configure". Pick the App ID from the previous step as the Primary App ID. Under "Domains and Subdomains" add your deployed domain without https://, and under "Return URLs" paste your DontCode redirect URL exactly. Click Next, Done, Continue, then Save.
Go to "Keys" → the plus button. Name the key, tick "Sign in with Apple", click Configure and choose the same Primary App ID, then Save, Continue and Register. Apple shows a Key ID and offers the key file once: click Download and keep the .p8 file somewhere safe. If you lose it you must revoke the key and make a new one.
In your DontCode project go to Users → Sign-in → Apple. Enter the Services ID, the Team ID, the Key ID, and open the .p8 file in any text editor and paste its whole contents, from BEGIN PRIVATE KEY to END PRIVATE KEY, into the private key box. Click Save. Your app redeploys and the Apple button appears on your sign-in form in a few seconds.
Also check the troubleshooting section on the main guide for issues that apply to all providers.
One of the four values does not match. The most common mix-up is entering the App ID or Bundle ID where the Services ID belongs. Also check that the key is still active under Keys, that it has Sign in with Apple enabled for this Primary App ID, and that the Team ID has no typo.
The Return URL on the Services ID must match your DontCode redirect URL character for character, including https:// and the /api/auth/oauth/callback path, and the domain must be listed under Domains and Subdomains. Register every domain your app answers on, the dontcode.cafe address and any custom domain.
They chose "Hide My Email". The relay address is real and receives mail, but only from senders Apple knows about. If you send email from your own domain, register it under "Services" → "Sign in with Apple for Email Communication" in your developer account, or those messages are dropped.
Apple shares the name only the first time someone authorizes your app. If that sign-in failed partway, the name is gone until they remove your app under Settings → Apple ID → Sign in with Apple on their device and sign in again.
Apple refuses localhost and only calls back to the Return URLs you registered. Test on your deployed domain.