diff --git a/apps/docs/pages/guides/auth/social-login.mdx b/apps/docs/pages/guides/auth/social-login.mdx index 1c950411577..8864a1b6dc9 100644 --- a/apps/docs/pages/guides/auth/social-login.mdx +++ b/apps/docs/pages/guides/auth/social-login.mdx @@ -43,6 +43,12 @@ Supabase supports a suite of social providers. Follow these guides to configure ))} + +## Provider Tokens + +Once the OAuth flow completes, Supabase Auth will sign your user in. You will receive a copy of the provider token used in the OAuth flow in case you need to use it further. For example, you can use the Google provider token to access Google APIs on behalf of your user. + +Provider tokens are intentionally not stored in your project's database, however. This is because provider tokens give access to potentially sensitive user data in third-party systems. Different applications have different needs, and one application's OAuth scopes may be significantly more permissive than another. If you do want to use the provider token outside of the browser that completed the OAuth flow, you will have to send it manually to a secure server under your control. export const Page = ({ children }) =>