From b81ef0adf0765686f45eca4e66ab7f5c1fa1268f Mon Sep 17 00:00:00 2001 From: "Andrey A." <56412611+aantti@users.noreply.github.com> Date: Fri, 27 Feb 2026 19:22:36 +0100 Subject: [PATCH] chore: remove redundant example section --- .../guides/self-hosting/docker-oauth.mdx | 141 ++++-------------- 1 file changed, 27 insertions(+), 114 deletions(-) diff --git a/apps/docs/content/guides/self-hosting/docker-oauth.mdx b/apps/docs/content/guides/self-hosting/docker-oauth.mdx index 4f22c9e02af..36c15f97496 100644 --- a/apps/docs/content/guides/self-hosting/docker-oauth.mdx +++ b/apps/docs/content/guides/self-hosting/docker-oauth.mdx @@ -6,8 +6,6 @@ subtitle: 'Set up social login (OAuth/OIDC) providers for self-hosted Supabase w This guide covers the **server-side configuration** required to enable social login providers on a self-hosted Supabase instance running with Docker Compose. This applies to all OAuth and OIDC-based providers, including third-party identity providers like Keycloak. -For client-side implementation details, see [Social Login](/docs/guides/auth/social-login). - ## Before you begin You need: @@ -296,38 +294,38 @@ GOTRUE_EXTERNAL_KEYCLOAK_URL: ${KEYCLOAK_URL} -### Other supported providers +## Other supported providers -The Auth service supports 20+ OAuth providers. Each follows the same `GOTRUE_EXTERNAL_{PROVIDER}_*` pattern. Below is a reference for all providers: +The Auth service supports many OAuth providers. Below is a reference for all providers: | Provider | Env prefix | Extra variables | Docs | |----------|-----------|-----------------|------| -| Apple | `APPLE_` | — | [Login with Apple](/docs/guides/auth/social-login/auth-apple) | +| Apple | `APPLE_` | - | [Login with Apple](/docs/guides/auth/social-login/auth-apple) | | Azure (Microsoft) | `AZURE_` | `URL` (tenant URL) | [Login with Azure](/docs/guides/auth/social-login/auth-azure) | -| Bitbucket | `BITBUCKET_` | — | [Login with Bitbucket](/docs/guides/auth/social-login/auth-bitbucket) | -| Discord | `DISCORD_` | — | [Login with Discord](/docs/guides/auth/social-login/auth-discord) | -| Facebook | `FACEBOOK_` | — | [Login with Facebook](/docs/guides/auth/social-login/auth-facebook) | -| Figma | `FIGMA_` | — | [Login with Figma](/docs/guides/auth/social-login/auth-figma) | +| Bitbucket | `BITBUCKET_` | - | [Login with Bitbucket](/docs/guides/auth/social-login/auth-bitbucket) | +| Discord | `DISCORD_` | - | [Login with Discord](/docs/guides/auth/social-login/auth-discord) | +| Facebook | `FACEBOOK_` | - | [Login with Facebook](/docs/guides/auth/social-login/auth-facebook) | +| Figma | `FIGMA_` | - | [Login with Figma](/docs/guides/auth/social-login/auth-figma) | | GitHub | `GITHUB_` | `URL` (for GitHub Enterprise) | [Login with GitHub](/docs/guides/auth/social-login/auth-github) | | GitLab | `GITLAB_` | `URL` (for self-hosted GitLab) | [Login with GitLab](/docs/guides/auth/social-login/auth-gitlab) | -| Google | `GOOGLE_` | — | [Login with Google](/docs/guides/auth/social-login/auth-google) | -| Kakao | `KAKAO_` | — | [Login with Kakao](/docs/guides/auth/social-login/auth-kakao) | +| Google | `GOOGLE_` | - | [Login with Google](/docs/guides/auth/social-login/auth-google) | +| Kakao | `KAKAO_` | - | [Login with Kakao](/docs/guides/auth/social-login/auth-kakao) | | Keycloak (OIDC) | `KEYCLOAK_` | `URL` (realm URL, **required**) | [Login with Keycloak](/docs/guides/auth/social-login/auth-keycloak) | -| LinkedIn (OIDC) | `LINKEDIN_OIDC_` | — | [Login with LinkedIn](/docs/guides/auth/social-login/auth-linkedin) | -| Notion | `NOTION_` | — | [Login with Notion](/docs/guides/auth/social-login/auth-notion) | -| Slack (OIDC) | `SLACK_OIDC_` | — | [Login with Slack](/docs/guides/auth/social-login/auth-slack) | -| Snapchat | `SNAPCHAT_` | — | — | -| Spotify | `SPOTIFY_` | — | [Login with Spotify](/docs/guides/auth/social-login/auth-spotify) | -| Twitch | `TWITCH_` | — | [Login with Twitch](/docs/guides/auth/social-login/auth-twitch) | -| Twitter | `TWITTER_` | — | [Login with Twitter](/docs/guides/auth/social-login/auth-twitter) | -| WorkOS | `WORKOS_` | — | [Login with WorkOS](/docs/guides/auth/social-login/auth-workos) | -| Zoom | `ZOOM_` | — | [Login with Zoom](/docs/guides/auth/social-login/auth-zoom) | +| LinkedIn (OIDC) | `LINKEDIN_OIDC_` | - | [Login with LinkedIn](/docs/guides/auth/social-login/auth-linkedin) | +| Notion | `NOTION_` | - | [Login with Notion](/docs/guides/auth/social-login/auth-notion) | +| Slack (OIDC) | `SLACK_OIDC_` | - | [Login with Slack](/docs/guides/auth/social-login/auth-slack) | +| Snapchat | `SNAPCHAT_` | - | - | +| Spotify | `SPOTIFY_` | - | [Login with Spotify](/docs/guides/auth/social-login/auth-spotify) | +| Twitch | `TWITCH_` | - | [Login with Twitch](/docs/guides/auth/social-login/auth-twitch) | +| Twitter | `TWITTER_` | - | [Login with Twitter](/docs/guides/auth/social-login/auth-twitter) | +| WorkOS | `WORKOS_` | - | [Login with WorkOS](/docs/guides/auth/social-login/auth-workos) | +| Zoom | `ZOOM_` | - | [Login with Zoom](/docs/guides/auth/social-login/auth-zoom) | -For each provider, you need at minimum `ENABLED`, `CLIENT_ID`, `SECRET`, and `REDIRECT_URI` in `docker-compose.yml`. The `.env` variable names do not include the `GOTRUE_EXTERNAL_` prefix — that is added in the Docker Compose passthrough. +For each provider, you need at minimum `ENABLED`, `CLIENT_ID`, `SECRET`, and `REDIRECT_URI` in `docker-compose.yml`. The `.env` variable names do not include the `GOTRUE_EXTERNAL_` prefix - that is added in the Docker Compose passthrough. -**LinkedIn (OIDC)** and **Slack (OIDC)** use multi-word env prefixes. The full Docker Compose variables are `GOTRUE_EXTERNAL_LINKEDIN_OIDC_CLIENT_ID` and `GOTRUE_EXTERNAL_SLACK_OIDC_CLIENT_ID` respectively — not `LINKEDIN_CLIENT_ID` or `SLACK_CLIENT_ID`. +**LinkedIn (OIDC)** and **Slack (OIDC)** use multi-word env prefixes. The full Docker Compose variables are `GOTRUE_EXTERNAL_LINKEDIN_OIDC_CLIENT_ID` and `GOTRUE_EXTERNAL_SLACK_OIDC_CLIENT_ID` respectively - not `LINKEDIN_CLIENT_ID` or `SLACK_CLIENT_ID`. @@ -337,91 +335,11 @@ For each provider, you need at minimum `ENABLED`, `CLIENT_ID`, `SECRET`, and `RE -## Complete example: Google OAuth +## Test the login flow -This walkthrough starts from a fresh self-hosted Supabase setup and adds Google OAuth. +You can test OAuth with the following minimal HTML page: -### 1. Create Google OAuth credentials - -1. Open [Google Cloud Console](https://console.cloud.google.com/apis/credentials) -2. Create a new project or select an existing one -3. If prompted, configure the **OAuth consent screen** (External, fill in app name and email) -4. Go to **Credentials** > **Create Credentials** > **OAuth client ID** -5. Application type: **Web application** -6. Authorized redirect URIs: add `https://supabase.example.com/auth/v1/callback` (replace with your `API_EXTERNAL_URL`) -7. Click **Create** and note the **Client ID** and **Client Secret** - -### 2. Edit `.env` - -Add the following after the phone auth section: - -``` -## OAuth - Google -GOOGLE_ENABLED=true -GOOGLE_CLIENT_ID=123456789-abcdef.apps.googleusercontent.com -GOOGLE_SECRET=GOCSPX-your-secret-here -``` - -### 3. Edit `docker-compose.yml` - -In the `auth` service `environment:` block, add after the phone/SMS variables: - -``` -services: - auth: - environment: - # ... existing variables ... - - GOTRUE_EXTERNAL_GOOGLE_ENABLED: ${GOOGLE_ENABLED} - GOTRUE_EXTERNAL_GOOGLE_CLIENT_ID: ${GOOGLE_CLIENT_ID} - GOTRUE_EXTERNAL_GOOGLE_SECRET: ${GOOGLE_SECRET} - GOTRUE_EXTERNAL_GOOGLE_REDIRECT_URI: ${API_EXTERNAL_URL}/auth/v1/callback -``` - -### 4. Restart the auth service - -```sh -docker compose up -d auth -``` - -### 5. Verify - -```sh -curl https:///auth/v1/settings -``` - -Confirm `"google": true` appears in the response under `external`. - -### 6. Test the login flow - -You can test without a full app by saving this as an HTML file and opening it in your browser: - -```js name=test-oauth.js -// Save as a .js file served by any static file server, or paste into your browser console. -// Replace these with your actual values: -const SUPABASE_URL = 'https://supabase.example.com' -const SUPABASE_ANON_KEY = 'your-anon-key' - -// Using supabase-js loaded via CDN or npm -const supabase = window.supabase.createClient(SUPABASE_URL, SUPABASE_ANON_KEY) - -// Trigger the OAuth flow -const { data, error } = await supabase.auth.signInWithOAuth({ - provider: 'google', -}) - -// After the redirect back, check for a session -const { data: session } = await supabase.auth.getSession() -if (session.session) { - console.log('Logged in as:', session.session.user.email) -} -``` - -Or use a minimal HTML page. Create a file called `test-oauth.html`: - -{/* supa-mdx-lint-disable Rule003Spelling */} - -```text name=test-oauth.html +```html @@ -528,13 +446,8 @@ All OAuth-related environment variables for the `auth` service in `docker-compos | Variable | Description | Required | |----------|------------|----------| -| `GOTRUE_EXTERNAL_{PROVIDER}_ENABLED` | Enable the provider (`true`/`false`) | Yes | -| `GOTRUE_EXTERNAL_{PROVIDER}_CLIENT_ID` | OAuth client ID from the provider | Yes | -| `GOTRUE_EXTERNAL_{PROVIDER}_SECRET` | OAuth client secret from the provider | Yes | -| `GOTRUE_EXTERNAL_{PROVIDER}_REDIRECT_URI` | Callback URL: `{API_EXTERNAL_URL}/auth/v1/callback` | Yes | -| `GOTRUE_EXTERNAL_{PROVIDER}_URL` | Base URL for self-hosted or tenant-specific providers (Keycloak, Azure, GitLab, GitHub Enterprise) | Provider-dependent | -| `GOTRUE_EXTERNAL_{PROVIDER}_API_URL` | API endpoint URL override | No | -| `GOTRUE_EXTERNAL_{PROVIDER}_EMAIL_OPTIONAL` | Allow sign-up without email from this provider | No | -| `GOTRUE_EXTERNAL_{PROVIDER}_SKIP_NONCE_CHECK` | Skip nonce verification for ID token flows | No | +| `GOTRUE_EXTERNAL_*_ENABLED` | Enable the provider (`true`/`false`) | Yes | +| `GOTRUE_EXTERNAL_*_CLIENT_ID` | OAuth client ID from the provider | Yes | +| `GOTRUE_EXTERNAL_*_SECRET` | OAuth client secret from the provider | Yes | +| `GOTRUE_EXTERNAL_*_REDIRECT_URI` | Callback URL: `${API_EXTERNAL_URL}/auth/v1/callback` | Yes | | `GOTRUE_SITE_URL` | Default redirect URL after authentication (set via `SITE_URL` in `.env`) | Yes | -| `GOTRUE_URI_ALLOW_LIST` | Additional allowed redirect URLs (set via `ADDITIONAL_REDIRECT_URLS` in `.env`) | No |