docs
/
AppEngine API

OAuth and social login

Google, Facebook, GitHub and Microsoft — redirect flows and native token exchange.

Supported providers: Google, Facebook, GitHub and Microsoft, alongside password, magic-link and email-code sign-in.

Each provider offers two shapes. Redirect flows suit web apps; token exchange suits native apps that have already completed sign-in with the platform SDK.

Google

GET/profile/googleNo auth
GET/profile/google/redirectNo auth
POST/profile/customer/google/tokenNo auth

The token endpoint takes a Google ID token from a native sign-in and returns an AppEngine customer session — no browser round trip.

Facebook

GET/profile/facebook/urlNo auth
GET/profile/facebookNo auth
GET/profile/facebook/redirectNo auth
POST/profile/facebook/tokenNo auth

/facebook/url returns the authorization URL to open, for clients that want to control the redirect themselves rather than being bounced through the API.

GitHub

GET/profile/github/urlNo auth
GET/profile/githubNo auth
GET/profile/github/redirectNo auth
POST/profile/github/redirectNo auth
POST/profile/github/tokenNo auth

The callback accepts both GET and POST.

Generic customer social login

POST/profile/customer/social-loginNo auth

Validates a provider token and issues a customer session — the single entry point when the client already knows which provider it used.

After a successful flow

GET/profile/auth/successNo auth

Where redirect flows land. From here the client picks up the session.

OAuth for integrations

Provider connections for integrations — as opposed to sign-in — are handled by ConnectModule:

GET/connect/oauth2callback/:providerNo auth

These callbacks arrive without an orgid, so the middleware falls back to SHARED_ORG. Webhooks under /connect/webhook/* instead carry the org in the URL path, which the middleware parses out.

See Integrations.

Redirect URIs must be registered per provider

Every provider needs its callback registered in the provider's own console. Redirect URIs are environment-specific — a localhost callback registered for development will not work in production, and the failure surfaces at the provider, not in AppEngine's logs.