chore: remove redundant example section

This commit is contained in:
Andrey A. committed 2026-02-27 19:22:36 +01:00
1 parent 32a955a054
commit b81ef0adf0
1 file changed
+27 -114
@@ -6,8 +6,6 @@ subtitle: 'Set up social login (OAuth/OIDC) providers for self-hosted Supabase w
This guide covers the **server-side configuration** required to enable social login providers on a self-hosted Supabase instance running with Docker Compose. This applies to all OAuth and OIDC-based providers, including third-party identity providers like Keycloak.
For client-side implementation details, see [Social Login](/docs/guides/auth/social-login).
## Before you begin
You need:
@@ -296,38 +294,38 @@ GOTRUE_EXTERNAL_KEYCLOAK_URL: ${KEYCLOAK_URL}
</Tabs>
### Other supported providers
## Other supported providers
The Auth service supports 20+ OAuth providers. Each follows the same `GOTRUE_EXTERNAL_{PROVIDER}_*` pattern. Below is a reference for all providers:
The Auth service supports many OAuth providers. Below is a reference for all providers:
| Provider | Env prefix | Extra variables | Docs |
|----------|-----------|-----------------|------|
| Apple | `APPLE_` | — | [Login with Apple](/docs/guides/auth/social-login/auth-apple) |
| Apple | `APPLE_` | - | [Login with Apple](/docs/guides/auth/social-login/auth-apple) |
| Azure (Microsoft) | `AZURE_` | `URL` (tenant URL) | [Login with Azure](/docs/guides/auth/social-login/auth-azure) |
| Bitbucket | `BITBUCKET_` | — | [Login with Bitbucket](/docs/guides/auth/social-login/auth-bitbucket) |
| Discord | `DISCORD_` | — | [Login with Discord](/docs/guides/auth/social-login/auth-discord) |
| Facebook | `FACEBOOK_` | — | [Login with Facebook](/docs/guides/auth/social-login/auth-facebook) |
| Figma | `FIGMA_` | — | [Login with Figma](/docs/guides/auth/social-login/auth-figma) |
| Bitbucket | `BITBUCKET_` | - | [Login with Bitbucket](/docs/guides/auth/social-login/auth-bitbucket) |
| Discord | `DISCORD_` | - | [Login with Discord](/docs/guides/auth/social-login/auth-discord) |
| Facebook | `FACEBOOK_` | - | [Login with Facebook](/docs/guides/auth/social-login/auth-facebook) |
| Figma | `FIGMA_` | - | [Login with Figma](/docs/guides/auth/social-login/auth-figma) |
| GitHub | `GITHUB_` | `URL` (for GitHub Enterprise) | [Login with GitHub](/docs/guides/auth/social-login/auth-github) |
| GitLab | `GITLAB_` | `URL` (for self-hosted GitLab) | [Login with GitLab](/docs/guides/auth/social-login/auth-gitlab) |
| Google | `GOOGLE_` | — | [Login with Google](/docs/guides/auth/social-login/auth-google) |
| Kakao | `KAKAO_` | — | [Login with Kakao](/docs/guides/auth/social-login/auth-kakao) |
| Google | `GOOGLE_` | - | [Login with Google](/docs/guides/auth/social-login/auth-google) |
| Kakao | `KAKAO_` | - | [Login with Kakao](/docs/guides/auth/social-login/auth-kakao) |
| Keycloak (OIDC) | `KEYCLOAK_` | `URL` (realm URL, **required**) | [Login with Keycloak](/docs/guides/auth/social-login/auth-keycloak) |
| LinkedIn (OIDC) | `LINKEDIN_OIDC_` | — | [Login with LinkedIn](/docs/guides/auth/social-login/auth-linkedin) |
| Notion | `NOTION_` | — | [Login with Notion](/docs/guides/auth/social-login/auth-notion) |
| Slack (OIDC) | `SLACK_OIDC_` | — | [Login with Slack](/docs/guides/auth/social-login/auth-slack) |
| Snapchat | `SNAPCHAT_` | — | — |
| Spotify | `SPOTIFY_` | — | [Login with Spotify](/docs/guides/auth/social-login/auth-spotify) |
| Twitch | `TWITCH_` | — | [Login with Twitch](/docs/guides/auth/social-login/auth-twitch) |
| Twitter | `TWITTER_` | — | [Login with Twitter](/docs/guides/auth/social-login/auth-twitter) |
| WorkOS | `WORKOS_` | — | [Login with WorkOS](/docs/guides/auth/social-login/auth-workos) |
| Zoom | `ZOOM_` | — | [Login with Zoom](/docs/guides/auth/social-login/auth-zoom) |
| LinkedIn (OIDC) | `LINKEDIN_OIDC_` | - | [Login with LinkedIn](/docs/guides/auth/social-login/auth-linkedin) |
| Notion | `NOTION_` | - | [Login with Notion](/docs/guides/auth/social-login/auth-notion) |
| Slack (OIDC) | `SLACK_OIDC_` | - | [Login with Slack](/docs/guides/auth/social-login/auth-slack) |
| Snapchat | `SNAPCHAT_` | - | - |
| Spotify | `SPOTIFY_` | - | [Login with Spotify](/docs/guides/auth/social-login/auth-spotify) |
| Twitch | `TWITCH_` | - | [Login with Twitch](/docs/guides/auth/social-login/auth-twitch) |
| Twitter | `TWITTER_` | - | [Login with Twitter](/docs/guides/auth/social-login/auth-twitter) |
| WorkOS | `WORKOS_` | - | [Login with WorkOS](/docs/guides/auth/social-login/auth-workos) |
| Zoom | `ZOOM_` | - | [Login with Zoom](/docs/guides/auth/social-login/auth-zoom) |
For each provider, you need at minimum `ENABLED`, `CLIENT_ID`, `SECRET`, and `REDIRECT_URI` in `docker-compose.yml`. The `.env` variable names do not include the `GOTRUE_EXTERNAL_` prefix — that is added in the Docker Compose passthrough.
For each provider, you need at minimum `ENABLED`, `CLIENT_ID`, `SECRET`, and `REDIRECT_URI` in `docker-compose.yml`. The `.env` variable names do not include the `GOTRUE_EXTERNAL_` prefix - that is added in the Docker Compose passthrough.
<Admonition type="note">
**LinkedIn (OIDC)** and **Slack (OIDC)** use multi-word env prefixes. The full Docker Compose variables are `GOTRUE_EXTERNAL_LINKEDIN_OIDC_CLIENT_ID` and `GOTRUE_EXTERNAL_SLACK_OIDC_CLIENT_ID` respectively — not `LINKEDIN_CLIENT_ID` or `SLACK_CLIENT_ID`.
**LinkedIn (OIDC)** and **Slack (OIDC)** use multi-word env prefixes. The full Docker Compose variables are `GOTRUE_EXTERNAL_LINKEDIN_OIDC_CLIENT_ID` and `GOTRUE_EXTERNAL_SLACK_OIDC_CLIENT_ID` respectively - not `LINKEDIN_CLIENT_ID` or `SLACK_CLIENT_ID`.
</Admonition>
@@ -337,91 +335,11 @@ For each provider, you need at minimum `ENABLED`, `CLIENT_ID`, `SECRET`, and `RE
</Admonition>
## Complete example: Google OAuth
## Test the login flow
This walkthrough starts from a fresh self-hosted Supabase setup and adds Google OAuth.
You can test OAuth with the following minimal HTML page:
### 1. Create Google OAuth credentials
1. Open [Google Cloud Console](https://console.cloud.google.com/apis/credentials)
2. Create a new project or select an existing one
3. If prompted, configure the **OAuth consent screen** (External, fill in app name and email)
4. Go to **Credentials** > **Create Credentials** > **OAuth client ID**
5. Application type: **Web application**
6. Authorized redirect URIs: add `https://supabase.example.com/auth/v1/callback` (replace with your `API_EXTERNAL_URL`)
7. Click **Create** and note the **Client ID** and **Client Secret**
### 2. Edit `.env`
Add the following after the phone auth section:
```
## OAuth - Google
GOOGLE_ENABLED=true
GOOGLE_CLIENT_ID=123456789-abcdef.apps.googleusercontent.com
GOOGLE_SECRET=GOCSPX-your-secret-here
```
### 3. Edit `docker-compose.yml`
In the `auth` service `environment:` block, add after the phone/SMS variables:
```
services:
auth:
environment:
# ... existing variables ...
GOTRUE_EXTERNAL_GOOGLE_ENABLED: ${GOOGLE_ENABLED}
GOTRUE_EXTERNAL_GOOGLE_CLIENT_ID: ${GOOGLE_CLIENT_ID}
GOTRUE_EXTERNAL_GOOGLE_SECRET: ${GOOGLE_SECRET}
GOTRUE_EXTERNAL_GOOGLE_REDIRECT_URI: ${API_EXTERNAL_URL}/auth/v1/callback
```
### 4. Restart the auth service
```sh
docker compose up -d auth
```
### 5. Verify
```sh
curl https://<your-domain>/auth/v1/settings
```
Confirm `"google": true` appears in the response under `external`.
### 6. Test the login flow
You can test without a full app by saving this as an HTML file and opening it in your browser:
```js name=test-oauth.js
// Save as a .js file served by any static file server, or paste into your browser console.
// Replace these with your actual values:
const SUPABASE_URL = 'https://supabase.example.com'
const SUPABASE_ANON_KEY = 'your-anon-key'
// Using supabase-js loaded via CDN or npm
const supabase = window.supabase.createClient(SUPABASE_URL, SUPABASE_ANON_KEY)
// Trigger the OAuth flow
const { data, error } = await supabase.auth.signInWithOAuth({
provider: 'google',
})
// After the redirect back, check for a session
const { data: session } = await supabase.auth.getSession()
if (session.session) {
console.log('Logged in as:', session.session.user.email)
}
```
Or use a minimal HTML page. Create a file called `test-oauth.html`:
{/* supa-mdx-lint-disable Rule003Spelling */}
```text name=test-oauth.html
```html
<!DOCTYPE html>
<html>
<body>
@@ -528,13 +446,8 @@ All OAuth-related environment variables for the `auth` service in `docker-compos
| Variable | Description | Required |
|----------|------------|----------|
| `GOTRUE_EXTERNAL_{PROVIDER}_ENABLED` | Enable the provider (`true`/`false`) | Yes |
| `GOTRUE_EXTERNAL_{PROVIDER}_CLIENT_ID` | OAuth client ID from the provider | Yes |
| `GOTRUE_EXTERNAL_{PROVIDER}_SECRET` | OAuth client secret from the provider | Yes |
| `GOTRUE_EXTERNAL_{PROVIDER}_REDIRECT_URI` | Callback URL: `{API_EXTERNAL_URL}/auth/v1/callback` | Yes |
| `GOTRUE_EXTERNAL_{PROVIDER}_URL` | Base URL for self-hosted or tenant-specific providers (Keycloak, Azure, GitLab, GitHub Enterprise) | Provider-dependent |
| `GOTRUE_EXTERNAL_{PROVIDER}_API_URL` | API endpoint URL override | No |
| `GOTRUE_EXTERNAL_{PROVIDER}_EMAIL_OPTIONAL` | Allow sign-up without email from this provider | No |
| `GOTRUE_EXTERNAL_{PROVIDER}_SKIP_NONCE_CHECK` | Skip nonce verification for ID token flows | No |
| `GOTRUE_EXTERNAL_*_ENABLED` | Enable the provider (`true`/`false`) | Yes |
| `GOTRUE_EXTERNAL_*_CLIENT_ID` | OAuth client ID from the provider | Yes |
| `GOTRUE_EXTERNAL_*_SECRET` | OAuth client secret from the provider | Yes |
| `GOTRUE_EXTERNAL_*_REDIRECT_URI` | Callback URL: `${API_EXTERNAL_URL}/auth/v1/callback` | Yes |
| `GOTRUE_SITE_URL` | Default redirect URL after authentication (set via `SITE_URL` in `.env`) | Yes |
| `GOTRUE_URI_ALLOW_LIST` | Additional allowed redirect URLs (set via `ADDITIONAL_REDIRECT_URLS` in `.env`) | No |