We connect sign-in for your application to Apple ID authentication, known as Sign in with Apple.

iPhone users are used to signing in with Face ID or Touch ID in one tap. Apple's App Store rules also expect apps that offer third-party sign-in, such as Google, to include a privacy-focused option, and Sign in with Apple meets that. For customer-facing iOS apps it is often part of passing App Store review.

What we build with it

  • User sign-in on iOS and web
  • Account creation with a private relay email
  • Linking an Apple sign-in to an existing customer account

How it works

  1. The user taps sign in with Apple in the app or on the website.
  2. Apple confirms their identity on the device, typically with Face ID, Touch ID or the device passcode.
  3. On first sign-in, the user chooses whether to share their real email or a private relay address.
  4. Apple returns a signed token with a stable user identifier, which the system verifies and uses to create or find the account.

Data exchanged

  • Apple user identifier
  • Email address, which may be a private relay address
  • Name, shared only on first sign-in
  • Authentication tokens

What is needed to set it up

  • An Apple Developer Program membership
  • A configured Service ID and key
  • Verified return URLs

Good to know

  • Apple shares the user's name and email only the first time they sign in, so the system must save them at that moment.
  • To send email to private relay addresses, your sending domain must be registered with Apple, otherwise those emails are not delivered.
  • Apps that let users create accounts must also let them delete their account from within the app, which we build in.