From b81ef0adf0765686f45eca4e66ab7f5c1fa1268f Mon Sep 17 00:00:00 2001
From: "Andrey A." <56412611+aantti@users.noreply.github.com>
Date: Fri, 27 Feb 2026 19:22:36 +0100
Subject: [PATCH] chore: remove redundant example section
---
.../guides/self-hosting/docker-oauth.mdx | 141 ++++--------------
1 file changed, 27 insertions(+), 114 deletions(-)
diff --git a/apps/docs/content/guides/self-hosting/docker-oauth.mdx b/apps/docs/content/guides/self-hosting/docker-oauth.mdx
index 4f22c9e02af..36c15f97496 100644
--- a/apps/docs/content/guides/self-hosting/docker-oauth.mdx
+++ b/apps/docs/content/guides/self-hosting/docker-oauth.mdx
@@ -6,8 +6,6 @@ subtitle: 'Set up social login (OAuth/OIDC) providers for self-hosted Supabase w
This guide covers the **server-side configuration** required to enable social login providers on a self-hosted Supabase instance running with Docker Compose. This applies to all OAuth and OIDC-based providers, including third-party identity providers like Keycloak.
-For client-side implementation details, see [Social Login](/docs/guides/auth/social-login).
-
## Before you begin
You need:
@@ -296,38 +294,38 @@ GOTRUE_EXTERNAL_KEYCLOAK_URL: ${KEYCLOAK_URL}
-### Other supported providers
+## Other supported providers
-The Auth service supports 20+ OAuth providers. Each follows the same `GOTRUE_EXTERNAL_{PROVIDER}_*` pattern. Below is a reference for all providers:
+The Auth service supports many OAuth providers. Below is a reference for all providers:
| Provider | Env prefix | Extra variables | Docs |
|----------|-----------|-----------------|------|
-| Apple | `APPLE_` | — | [Login with Apple](/docs/guides/auth/social-login/auth-apple) |
+| Apple | `APPLE_` | - | [Login with Apple](/docs/guides/auth/social-login/auth-apple) |
| Azure (Microsoft) | `AZURE_` | `URL` (tenant URL) | [Login with Azure](/docs/guides/auth/social-login/auth-azure) |
-| Bitbucket | `BITBUCKET_` | — | [Login with Bitbucket](/docs/guides/auth/social-login/auth-bitbucket) |
-| Discord | `DISCORD_` | — | [Login with Discord](/docs/guides/auth/social-login/auth-discord) |
-| Facebook | `FACEBOOK_` | — | [Login with Facebook](/docs/guides/auth/social-login/auth-facebook) |
-| Figma | `FIGMA_` | — | [Login with Figma](/docs/guides/auth/social-login/auth-figma) |
+| Bitbucket | `BITBUCKET_` | - | [Login with Bitbucket](/docs/guides/auth/social-login/auth-bitbucket) |
+| Discord | `DISCORD_` | - | [Login with Discord](/docs/guides/auth/social-login/auth-discord) |
+| Facebook | `FACEBOOK_` | - | [Login with Facebook](/docs/guides/auth/social-login/auth-facebook) |
+| Figma | `FIGMA_` | - | [Login with Figma](/docs/guides/auth/social-login/auth-figma) |
| GitHub | `GITHUB_` | `URL` (for GitHub Enterprise) | [Login with GitHub](/docs/guides/auth/social-login/auth-github) |
| GitLab | `GITLAB_` | `URL` (for self-hosted GitLab) | [Login with GitLab](/docs/guides/auth/social-login/auth-gitlab) |
-| Google | `GOOGLE_` | — | [Login with Google](/docs/guides/auth/social-login/auth-google) |
-| Kakao | `KAKAO_` | — | [Login with Kakao](/docs/guides/auth/social-login/auth-kakao) |
+| Google | `GOOGLE_` | - | [Login with Google](/docs/guides/auth/social-login/auth-google) |
+| Kakao | `KAKAO_` | - | [Login with Kakao](/docs/guides/auth/social-login/auth-kakao) |
| Keycloak (OIDC) | `KEYCLOAK_` | `URL` (realm URL, **required**) | [Login with Keycloak](/docs/guides/auth/social-login/auth-keycloak) |
-| LinkedIn (OIDC) | `LINKEDIN_OIDC_` | — | [Login with LinkedIn](/docs/guides/auth/social-login/auth-linkedin) |
-| Notion | `NOTION_` | — | [Login with Notion](/docs/guides/auth/social-login/auth-notion) |
-| Slack (OIDC) | `SLACK_OIDC_` | — | [Login with Slack](/docs/guides/auth/social-login/auth-slack) |
-| Snapchat | `SNAPCHAT_` | — | — |
-| Spotify | `SPOTIFY_` | — | [Login with Spotify](/docs/guides/auth/social-login/auth-spotify) |
-| Twitch | `TWITCH_` | — | [Login with Twitch](/docs/guides/auth/social-login/auth-twitch) |
-| Twitter | `TWITTER_` | — | [Login with Twitter](/docs/guides/auth/social-login/auth-twitter) |
-| WorkOS | `WORKOS_` | — | [Login with WorkOS](/docs/guides/auth/social-login/auth-workos) |
-| Zoom | `ZOOM_` | — | [Login with Zoom](/docs/guides/auth/social-login/auth-zoom) |
+| LinkedIn (OIDC) | `LINKEDIN_OIDC_` | - | [Login with LinkedIn](/docs/guides/auth/social-login/auth-linkedin) |
+| Notion | `NOTION_` | - | [Login with Notion](/docs/guides/auth/social-login/auth-notion) |
+| Slack (OIDC) | `SLACK_OIDC_` | - | [Login with Slack](/docs/guides/auth/social-login/auth-slack) |
+| Snapchat | `SNAPCHAT_` | - | - |
+| Spotify | `SPOTIFY_` | - | [Login with Spotify](/docs/guides/auth/social-login/auth-spotify) |
+| Twitch | `TWITCH_` | - | [Login with Twitch](/docs/guides/auth/social-login/auth-twitch) |
+| Twitter | `TWITTER_` | - | [Login with Twitter](/docs/guides/auth/social-login/auth-twitter) |
+| WorkOS | `WORKOS_` | - | [Login with WorkOS](/docs/guides/auth/social-login/auth-workos) |
+| Zoom | `ZOOM_` | - | [Login with Zoom](/docs/guides/auth/social-login/auth-zoom) |
-For each provider, you need at minimum `ENABLED`, `CLIENT_ID`, `SECRET`, and `REDIRECT_URI` in `docker-compose.yml`. The `.env` variable names do not include the `GOTRUE_EXTERNAL_` prefix — that is added in the Docker Compose passthrough.
+For each provider, you need at minimum `ENABLED`, `CLIENT_ID`, `SECRET`, and `REDIRECT_URI` in `docker-compose.yml`. The `.env` variable names do not include the `GOTRUE_EXTERNAL_` prefix - that is added in the Docker Compose passthrough.
-**LinkedIn (OIDC)** and **Slack (OIDC)** use multi-word env prefixes. The full Docker Compose variables are `GOTRUE_EXTERNAL_LINKEDIN_OIDC_CLIENT_ID` and `GOTRUE_EXTERNAL_SLACK_OIDC_CLIENT_ID` respectively — not `LINKEDIN_CLIENT_ID` or `SLACK_CLIENT_ID`.
+**LinkedIn (OIDC)** and **Slack (OIDC)** use multi-word env prefixes. The full Docker Compose variables are `GOTRUE_EXTERNAL_LINKEDIN_OIDC_CLIENT_ID` and `GOTRUE_EXTERNAL_SLACK_OIDC_CLIENT_ID` respectively - not `LINKEDIN_CLIENT_ID` or `SLACK_CLIENT_ID`.
@@ -337,91 +335,11 @@ For each provider, you need at minimum `ENABLED`, `CLIENT_ID`, `SECRET`, and `RE
-## Complete example: Google OAuth
+## Test the login flow
-This walkthrough starts from a fresh self-hosted Supabase setup and adds Google OAuth.
+You can test OAuth with the following minimal HTML page:
-### 1. Create Google OAuth credentials
-
-1. Open [Google Cloud Console](https://console.cloud.google.com/apis/credentials)
-2. Create a new project or select an existing one
-3. If prompted, configure the **OAuth consent screen** (External, fill in app name and email)
-4. Go to **Credentials** > **Create Credentials** > **OAuth client ID**
-5. Application type: **Web application**
-6. Authorized redirect URIs: add `https://supabase.example.com/auth/v1/callback` (replace with your `API_EXTERNAL_URL`)
-7. Click **Create** and note the **Client ID** and **Client Secret**
-
-### 2. Edit `.env`
-
-Add the following after the phone auth section:
-
-```
-## OAuth - Google
-GOOGLE_ENABLED=true
-GOOGLE_CLIENT_ID=123456789-abcdef.apps.googleusercontent.com
-GOOGLE_SECRET=GOCSPX-your-secret-here
-```
-
-### 3. Edit `docker-compose.yml`
-
-In the `auth` service `environment:` block, add after the phone/SMS variables:
-
-```
-services:
- auth:
- environment:
- # ... existing variables ...
-
- GOTRUE_EXTERNAL_GOOGLE_ENABLED: ${GOOGLE_ENABLED}
- GOTRUE_EXTERNAL_GOOGLE_CLIENT_ID: ${GOOGLE_CLIENT_ID}
- GOTRUE_EXTERNAL_GOOGLE_SECRET: ${GOOGLE_SECRET}
- GOTRUE_EXTERNAL_GOOGLE_REDIRECT_URI: ${API_EXTERNAL_URL}/auth/v1/callback
-```
-
-### 4. Restart the auth service
-
-```sh
-docker compose up -d auth
-```
-
-### 5. Verify
-
-```sh
-curl https:///auth/v1/settings
-```
-
-Confirm `"google": true` appears in the response under `external`.
-
-### 6. Test the login flow
-
-You can test without a full app by saving this as an HTML file and opening it in your browser:
-
-```js name=test-oauth.js
-// Save as a .js file served by any static file server, or paste into your browser console.
-// Replace these with your actual values:
-const SUPABASE_URL = 'https://supabase.example.com'
-const SUPABASE_ANON_KEY = 'your-anon-key'
-
-// Using supabase-js loaded via CDN or npm
-const supabase = window.supabase.createClient(SUPABASE_URL, SUPABASE_ANON_KEY)
-
-// Trigger the OAuth flow
-const { data, error } = await supabase.auth.signInWithOAuth({
- provider: 'google',
-})
-
-// After the redirect back, check for a session
-const { data: session } = await supabase.auth.getSession()
-if (session.session) {
- console.log('Logged in as:', session.session.user.email)
-}
-```
-
-Or use a minimal HTML page. Create a file called `test-oauth.html`:
-
-{/* supa-mdx-lint-disable Rule003Spelling */}
-
-```text name=test-oauth.html
+```html
@@ -528,13 +446,8 @@ All OAuth-related environment variables for the `auth` service in `docker-compos
| Variable | Description | Required |
|----------|------------|----------|
-| `GOTRUE_EXTERNAL_{PROVIDER}_ENABLED` | Enable the provider (`true`/`false`) | Yes |
-| `GOTRUE_EXTERNAL_{PROVIDER}_CLIENT_ID` | OAuth client ID from the provider | Yes |
-| `GOTRUE_EXTERNAL_{PROVIDER}_SECRET` | OAuth client secret from the provider | Yes |
-| `GOTRUE_EXTERNAL_{PROVIDER}_REDIRECT_URI` | Callback URL: `{API_EXTERNAL_URL}/auth/v1/callback` | Yes |
-| `GOTRUE_EXTERNAL_{PROVIDER}_URL` | Base URL for self-hosted or tenant-specific providers (Keycloak, Azure, GitLab, GitHub Enterprise) | Provider-dependent |
-| `GOTRUE_EXTERNAL_{PROVIDER}_API_URL` | API endpoint URL override | No |
-| `GOTRUE_EXTERNAL_{PROVIDER}_EMAIL_OPTIONAL` | Allow sign-up without email from this provider | No |
-| `GOTRUE_EXTERNAL_{PROVIDER}_SKIP_NONCE_CHECK` | Skip nonce verification for ID token flows | No |
+| `GOTRUE_EXTERNAL_*_ENABLED` | Enable the provider (`true`/`false`) | Yes |
+| `GOTRUE_EXTERNAL_*_CLIENT_ID` | OAuth client ID from the provider | Yes |
+| `GOTRUE_EXTERNAL_*_SECRET` | OAuth client secret from the provider | Yes |
+| `GOTRUE_EXTERNAL_*_REDIRECT_URI` | Callback URL: `${API_EXTERNAL_URL}/auth/v1/callback` | Yes |
| `GOTRUE_SITE_URL` | Default redirect URL after authentication (set via `SITE_URL` in `.env`) | Yes |
-| `GOTRUE_URI_ALLOW_LIST` | Additional allowed redirect URLs (set via `ADDITIONAL_REDIRECT_URLS` in `.env`) | No |