What Sign in with Apple is
Sign in with Apple lets people create an account and sign in with the Apple Account they already have, protected by Apple's two-factor authentication. On Apple devices they confirm with Face ID, Touch ID or their passcode; elsewhere, including Android and the web, they sign in with their Apple Account and a verification code.
It is built for privacy: an app asks only for a name and an email address, and the person can hide their real address behind Apple's private email relay. App Store rules ask apps that use another company's social sign-in for the main account to also offer a sign-in with those privacy features, which is why it is one of the social sign-in options of our authentication module.
What it does in your platform
Authentication
Adds the Apple button to your sign-up and sign-in screens. Customers on iPhone confirm with Face ID; everyone else uses Apple's web flow. The module turns Apple's identity token into a customer account and keeps the sessions, trusted devices and the second factor on payments.
How the connection works
On iPhone the app uses Apple's own sign-in sheet; on Android and the web, Apple's web flow. The platform verifies Apple's answers on the server.
A customer taps the button
Apple asks them to share their name and email, or to hide the email behind a private relay address, and to confirm with Face ID or Touch ID.
Apple answers the app
The app receives an identity token, a signed JSON web token, together with a one-time code and a stable user identifier, and passes them to the platform.
The platform verifies
The module checks the token against Apple's public keys, then redeems the one-time code with Apple, signing its request with your Sign in with Apple private key.
The account opens
The name arrives only on the first sign-in, so the module stores it at once. On that first sign-in, Apple also says whether the person is likely real.
Changes come back
If the customer stops using Sign in with Apple, deletes their Apple Account or changes email forwarding, Apple's server-to-server notification tells the platform.
Next to other providers
Sign in with Apple sits next to Google and Microsoft on the same sign-in screen, and next to passkeys and one-time codes. Each button opens the same kind of customer account in the platform, with the same sessions and checks.
Private relay addresses work like any other email once your sending domains are registered with Apple, so receipts and alerts from the notifications module reach every customer. Adding or removing the button later does not change your apps.
When Sign in with Apple fits best
A strong fit when
- Many of your customers use iPhones and expect to sign up with one tap.
- Your iOS app offers Google or another social sign-in, and App Store rules ask for a private option next to it.
- You want new accounts that arrive with Apple's two-factor protection already in place.
Also worth a look
- Passkeys, for one-tap sign-in on every platform without an outside account.
- Google sign-in, for customers who live in Android and Google's services.
How we get you live
The developer account
We set up Sign in with Apple in your Apple developer account with your account holder or an admin: the capability on your app's identifier, and a Services ID for the web and Android.
The email relay
We register your sending domains with Apple's private email relay, authenticated with SPF and DKIM, so mail reaches customers who hid their address.
The keys
Your Sign in with Apple private key goes into the platform's secrets and nowhere else, and we register the endpoint for Apple's account notifications.
A full test run
We test a sign-up, a returning sign-in, a hidden email and a revoked account on real devices before launch.
