mirror of
https://github.com/supabase/supabase.git
synced 2026-10-11 12:25:05 +03:00
chore: remove redundant example section
This commit is contained in:
1 parent
32a955a054
commit
b81ef0adf0
1 file changed
+27
-114
@@ -6,8 +6,6 @@ subtitle: 'Set up social login (OAuth/OIDC) providers for self-hosted Supabase w
|
||||
|
||||
This guide covers the **server-side configuration** required to enable social login providers on a self-hosted Supabase instance running with Docker Compose. This applies to all OAuth and OIDC-based providers, including third-party identity providers like Keycloak.
|
||||
|
||||
For client-side implementation details, see [Social Login](/docs/guides/auth/social-login).
|
||||
|
||||
## Before you begin
|
||||
|
||||
You need:
|
||||
@@ -296,38 +294,38 @@ GOTRUE_EXTERNAL_KEYCLOAK_URL: ${KEYCLOAK_URL}
|
||||
|
||||
</Tabs>
|
||||
|
||||
### Other supported providers
|
||||
## Other supported providers
|
||||
|
||||
The Auth service supports 20+ OAuth providers. Each follows the same `GOTRUE_EXTERNAL_{PROVIDER}_*` pattern. Below is a reference for all providers:
|
||||
The Auth service supports many OAuth providers. Below is a reference for all providers:
|
||||
|
||||
| Provider | Env prefix | Extra variables | Docs |
|
||||
|----------|-----------|-----------------|------|
|
||||
| Apple | `APPLE_` | — | [Login with Apple](/docs/guides/auth/social-login/auth-apple) |
|
||||
| Apple | `APPLE_` | - | [Login with Apple](/docs/guides/auth/social-login/auth-apple) |
|
||||
| Azure (Microsoft) | `AZURE_` | `URL` (tenant URL) | [Login with Azure](/docs/guides/auth/social-login/auth-azure) |
|
||||
| Bitbucket | `BITBUCKET_` | — | [Login with Bitbucket](/docs/guides/auth/social-login/auth-bitbucket) |
|
||||
| Discord | `DISCORD_` | — | [Login with Discord](/docs/guides/auth/social-login/auth-discord) |
|
||||
| Facebook | `FACEBOOK_` | — | [Login with Facebook](/docs/guides/auth/social-login/auth-facebook) |
|
||||
| Figma | `FIGMA_` | — | [Login with Figma](/docs/guides/auth/social-login/auth-figma) |
|
||||
| Bitbucket | `BITBUCKET_` | - | [Login with Bitbucket](/docs/guides/auth/social-login/auth-bitbucket) |
|
||||
| Discord | `DISCORD_` | - | [Login with Discord](/docs/guides/auth/social-login/auth-discord) |
|
||||
| Facebook | `FACEBOOK_` | - | [Login with Facebook](/docs/guides/auth/social-login/auth-facebook) |
|
||||
| Figma | `FIGMA_` | - | [Login with Figma](/docs/guides/auth/social-login/auth-figma) |
|
||||
| GitHub | `GITHUB_` | `URL` (for GitHub Enterprise) | [Login with GitHub](/docs/guides/auth/social-login/auth-github) |
|
||||
| GitLab | `GITLAB_` | `URL` (for self-hosted GitLab) | [Login with GitLab](/docs/guides/auth/social-login/auth-gitlab) |
|
||||
| Google | `GOOGLE_` | — | [Login with Google](/docs/guides/auth/social-login/auth-google) |
|
||||
| Kakao | `KAKAO_` | — | [Login with Kakao](/docs/guides/auth/social-login/auth-kakao) |
|
||||
| Google | `GOOGLE_` | - | [Login with Google](/docs/guides/auth/social-login/auth-google) |
|
||||
| Kakao | `KAKAO_` | - | [Login with Kakao](/docs/guides/auth/social-login/auth-kakao) |
|
||||
| Keycloak (OIDC) | `KEYCLOAK_` | `URL` (realm URL, **required**) | [Login with Keycloak](/docs/guides/auth/social-login/auth-keycloak) |
|
||||
| LinkedIn (OIDC) | `LINKEDIN_OIDC_` | — | [Login with LinkedIn](/docs/guides/auth/social-login/auth-linkedin) |
|
||||
| Notion | `NOTION_` | — | [Login with Notion](/docs/guides/auth/social-login/auth-notion) |
|
||||
| Slack (OIDC) | `SLACK_OIDC_` | — | [Login with Slack](/docs/guides/auth/social-login/auth-slack) |
|
||||
| Snapchat | `SNAPCHAT_` | — | — |
|
||||
| Spotify | `SPOTIFY_` | — | [Login with Spotify](/docs/guides/auth/social-login/auth-spotify) |
|
||||
| Twitch | `TWITCH_` | — | [Login with Twitch](/docs/guides/auth/social-login/auth-twitch) |
|
||||
| Twitter | `TWITTER_` | — | [Login with Twitter](/docs/guides/auth/social-login/auth-twitter) |
|
||||
| WorkOS | `WORKOS_` | — | [Login with WorkOS](/docs/guides/auth/social-login/auth-workos) |
|
||||
| Zoom | `ZOOM_` | — | [Login with Zoom](/docs/guides/auth/social-login/auth-zoom) |
|
||||
| LinkedIn (OIDC) | `LINKEDIN_OIDC_` | - | [Login with LinkedIn](/docs/guides/auth/social-login/auth-linkedin) |
|
||||
| Notion | `NOTION_` | - | [Login with Notion](/docs/guides/auth/social-login/auth-notion) |
|
||||
| Slack (OIDC) | `SLACK_OIDC_` | - | [Login with Slack](/docs/guides/auth/social-login/auth-slack) |
|
||||
| Snapchat | `SNAPCHAT_` | - | - |
|
||||
| Spotify | `SPOTIFY_` | - | [Login with Spotify](/docs/guides/auth/social-login/auth-spotify) |
|
||||
| Twitch | `TWITCH_` | - | [Login with Twitch](/docs/guides/auth/social-login/auth-twitch) |
|
||||
| Twitter | `TWITTER_` | - | [Login with Twitter](/docs/guides/auth/social-login/auth-twitter) |
|
||||
| WorkOS | `WORKOS_` | - | [Login with WorkOS](/docs/guides/auth/social-login/auth-workos) |
|
||||
| Zoom | `ZOOM_` | - | [Login with Zoom](/docs/guides/auth/social-login/auth-zoom) |
|
||||
|
||||
For each provider, you need at minimum `ENABLED`, `CLIENT_ID`, `SECRET`, and `REDIRECT_URI` in `docker-compose.yml`. The `.env` variable names do not include the `GOTRUE_EXTERNAL_` prefix — that is added in the Docker Compose passthrough.
|
||||
For each provider, you need at minimum `ENABLED`, `CLIENT_ID`, `SECRET`, and `REDIRECT_URI` in `docker-compose.yml`. The `.env` variable names do not include the `GOTRUE_EXTERNAL_` prefix - that is added in the Docker Compose passthrough.
|
||||
|
||||
<Admonition type="note">
|
||||
|
||||
**LinkedIn (OIDC)** and **Slack (OIDC)** use multi-word env prefixes. The full Docker Compose variables are `GOTRUE_EXTERNAL_LINKEDIN_OIDC_CLIENT_ID` and `GOTRUE_EXTERNAL_SLACK_OIDC_CLIENT_ID` respectively — not `LINKEDIN_CLIENT_ID` or `SLACK_CLIENT_ID`.
|
||||
**LinkedIn (OIDC)** and **Slack (OIDC)** use multi-word env prefixes. The full Docker Compose variables are `GOTRUE_EXTERNAL_LINKEDIN_OIDC_CLIENT_ID` and `GOTRUE_EXTERNAL_SLACK_OIDC_CLIENT_ID` respectively - not `LINKEDIN_CLIENT_ID` or `SLACK_CLIENT_ID`.
|
||||
|
||||
</Admonition>
|
||||
|
||||
@@ -337,91 +335,11 @@ For each provider, you need at minimum `ENABLED`, `CLIENT_ID`, `SECRET`, and `RE
|
||||
|
||||
</Admonition>
|
||||
|
||||
## Complete example: Google OAuth
|
||||
## Test the login flow
|
||||
|
||||
This walkthrough starts from a fresh self-hosted Supabase setup and adds Google OAuth.
|
||||
You can test OAuth with the following minimal HTML page:
|
||||
|
||||
### 1. Create Google OAuth credentials
|
||||
|
||||
1. Open [Google Cloud Console](https://console.cloud.google.com/apis/credentials)
|
||||
2. Create a new project or select an existing one
|
||||
3. If prompted, configure the **OAuth consent screen** (External, fill in app name and email)
|
||||
4. Go to **Credentials** > **Create Credentials** > **OAuth client ID**
|
||||
5. Application type: **Web application**
|
||||
6. Authorized redirect URIs: add `https://supabase.example.com/auth/v1/callback` (replace with your `API_EXTERNAL_URL`)
|
||||
7. Click **Create** and note the **Client ID** and **Client Secret**
|
||||
|
||||
### 2. Edit `.env`
|
||||
|
||||
Add the following after the phone auth section:
|
||||
|
||||
```
|
||||
## OAuth - Google
|
||||
GOOGLE_ENABLED=true
|
||||
GOOGLE_CLIENT_ID=123456789-abcdef.apps.googleusercontent.com
|
||||
GOOGLE_SECRET=GOCSPX-your-secret-here
|
||||
```
|
||||
|
||||
### 3. Edit `docker-compose.yml`
|
||||
|
||||
In the `auth` service `environment:` block, add after the phone/SMS variables:
|
||||
|
||||
```
|
||||
services:
|
||||
auth:
|
||||
environment:
|
||||
# ... existing variables ...
|
||||
|
||||
GOTRUE_EXTERNAL_GOOGLE_ENABLED: ${GOOGLE_ENABLED}
|
||||
GOTRUE_EXTERNAL_GOOGLE_CLIENT_ID: ${GOOGLE_CLIENT_ID}
|
||||
GOTRUE_EXTERNAL_GOOGLE_SECRET: ${GOOGLE_SECRET}
|
||||
GOTRUE_EXTERNAL_GOOGLE_REDIRECT_URI: ${API_EXTERNAL_URL}/auth/v1/callback
|
||||
```
|
||||
|
||||
### 4. Restart the auth service
|
||||
|
||||
```sh
|
||||
docker compose up -d auth
|
||||
```
|
||||
|
||||
### 5. Verify
|
||||
|
||||
```sh
|
||||
curl https://<your-domain>/auth/v1/settings
|
||||
```
|
||||
|
||||
Confirm `"google": true` appears in the response under `external`.
|
||||
|
||||
### 6. Test the login flow
|
||||
|
||||
You can test without a full app by saving this as an HTML file and opening it in your browser:
|
||||
|
||||
```js name=test-oauth.js
|
||||
// Save as a .js file served by any static file server, or paste into your browser console.
|
||||
// Replace these with your actual values:
|
||||
const SUPABASE_URL = 'https://supabase.example.com'
|
||||
const SUPABASE_ANON_KEY = 'your-anon-key'
|
||||
|
||||
// Using supabase-js loaded via CDN or npm
|
||||
const supabase = window.supabase.createClient(SUPABASE_URL, SUPABASE_ANON_KEY)
|
||||
|
||||
// Trigger the OAuth flow
|
||||
const { data, error } = await supabase.auth.signInWithOAuth({
|
||||
provider: 'google',
|
||||
})
|
||||
|
||||
// After the redirect back, check for a session
|
||||
const { data: session } = await supabase.auth.getSession()
|
||||
if (session.session) {
|
||||
console.log('Logged in as:', session.session.user.email)
|
||||
}
|
||||
```
|
||||
|
||||
Or use a minimal HTML page. Create a file called `test-oauth.html`:
|
||||
|
||||
{/* supa-mdx-lint-disable Rule003Spelling */}
|
||||
|
||||
```text name=test-oauth.html
|
||||
```html
|
||||
<!DOCTYPE html>
|
||||
<html>
|
||||
<body>
|
||||
@@ -528,13 +446,8 @@ All OAuth-related environment variables for the `auth` service in `docker-compos
|
||||
|
||||
| Variable | Description | Required |
|
||||
|----------|------------|----------|
|
||||
| `GOTRUE_EXTERNAL_{PROVIDER}_ENABLED` | Enable the provider (`true`/`false`) | Yes |
|
||||
| `GOTRUE_EXTERNAL_{PROVIDER}_CLIENT_ID` | OAuth client ID from the provider | Yes |
|
||||
| `GOTRUE_EXTERNAL_{PROVIDER}_SECRET` | OAuth client secret from the provider | Yes |
|
||||
| `GOTRUE_EXTERNAL_{PROVIDER}_REDIRECT_URI` | Callback URL: `{API_EXTERNAL_URL}/auth/v1/callback` | Yes |
|
||||
| `GOTRUE_EXTERNAL_{PROVIDER}_URL` | Base URL for self-hosted or tenant-specific providers (Keycloak, Azure, GitLab, GitHub Enterprise) | Provider-dependent |
|
||||
| `GOTRUE_EXTERNAL_{PROVIDER}_API_URL` | API endpoint URL override | No |
|
||||
| `GOTRUE_EXTERNAL_{PROVIDER}_EMAIL_OPTIONAL` | Allow sign-up without email from this provider | No |
|
||||
| `GOTRUE_EXTERNAL_{PROVIDER}_SKIP_NONCE_CHECK` | Skip nonce verification for ID token flows | No |
|
||||
| `GOTRUE_EXTERNAL_*_ENABLED` | Enable the provider (`true`/`false`) | Yes |
|
||||
| `GOTRUE_EXTERNAL_*_CLIENT_ID` | OAuth client ID from the provider | Yes |
|
||||
| `GOTRUE_EXTERNAL_*_SECRET` | OAuth client secret from the provider | Yes |
|
||||
| `GOTRUE_EXTERNAL_*_REDIRECT_URI` | Callback URL: `${API_EXTERNAL_URL}/auth/v1/callback` | Yes |
|
||||
| `GOTRUE_SITE_URL` | Default redirect URL after authentication (set via `SITE_URL` in `.env`) | Yes |
|
||||
| `GOTRUE_URI_ALLOW_LIST` | Additional allowed redirect URLs (set via `ADDITIONAL_REDIRECT_URLS` in `.env`) | No |
|
||||
Reference in new issue
Block a user