Skip the OAuth consoles.
Ship sign-in today.
Google, GitHub and email codes on Passkin's verified apps — no client ids to register, no consent screen to get reviewed, no secrets to rotate. Standard OpenID Connect, for your website and your iOS, Android and desktop apps, in Arabic and English.
Passkin's Google and GitHub apps by default. Your own, whenever you want.
Your own issuer and signing key. Any library, any language.
One project, one set of users, every platform.
Walk through what happens between the click and a signed-in person — every step is one the service really takes.
- Press “Run a sign-in”.
Works with
The work you no longer do
Sign-in is a week of consoles, secrets and edge cases before the first person signs in. Passkin has already done it, once, for everyone.
Doing it yourself
Before the first person signs in
- Register an OAuth app at Google, another at GitHub — one per environment
- Fill in Google's consent screen, publish it, wait for review
- Store client secrets, rotate them, keep them out of git
- Implement PKCE, state, nonce, token refresh and its rotation
- Build the email-code flow: generation, expiry, attempts, deliverability
- Build a sign-in page, in Arabic too, right to left
With Passkin
Four steps, then back to your product
- 1.Create a project: a publishable key and your own OpenID Connect issuer
- 2.Add your site's redirect URL
- 3.Paste three files, or one script tag
- 4.Switch methods on and off in the dashboard — no deploy
Every website and app of a project shares its users: sub is the same person on the website and in the iPhone app, and your API checks one kind of token.
See your sign-in page
This is the page your users get — the same layout and words. Switch methods, change the language, open it from an app, and press the buttons.
Sign-in methods
3 onSign in to Acme
to continue
https://auth.passk.in/p/pk_live_…/authorize?client_id=pk_live_…&redirect_uri=https://acme.com/api/auth/callback&response_type=code&scope=openid+email+profile&code_challenge_method=S256&code_challenge=…&state=…The SDK builds this for you. connection=email opens straight on the email form; connection=google skips the page entirely.
Your website and your apps, one set of users
Add each as an application of the same project. Each gets its own client id; all of them share the people.
Websites
Next.js SDK — the session in an encrypted cookie on your server, refreshed for you. Any other server: any OpenID Connect library.
Single-page apps
widget.js with one script tag, or oidc-client-ts. No secret in the browser: PKCE protects the exchange.
iPhone and iPad
Your own buttons open Passkin in the system sheet over the app (ASWebAuthenticationSession). Sign in with Apple's own sheet, optional.
Android
Custom Tabs over the app — or the phone's own Google account sheet, with Passkin registering your app at Google for you.
Desktop
The system browser and a loopback redirect, the way RFC 8252 says a native app should sign in.
Start with no keys.
Bring your own when you want.
Passkin's apps are the default, and they are enough to run in production. Your own Google or GitHub app is there for one reason: your name on the provider's screen instead of Passkin's.
Nobody signs up again
People are matched by the provider's account and their verified email, so switching keeps every user and their id.
One callback for everything
Your own app registers auth.passk.in/callback/google — the same for your website and every app.
Switch back any time
Your keys are encrypted at rest; remove them and the project is on Passkin's apps again.
Google, in Sign-in methodssame users
Passkin's app
Google's screen says “Passkin”. Nothing to set up.
My own app
Google's screen says your name. Client id and secret from your Google Cloud.
GitHub works the same way
Passkin's OAuth app, or yours.
Built for both directions
The sign-in pages follow the person's language — or the one your app asks for with ui_locales — right to left where it should be, with Latin addresses kept readable.
Sign in to Acme
to continue
سجّل الدخول إلى متجر الواحة
للمتابعة
Written down, and tested
- PKCE (S256) for every client; codes single-use, bound to the client and redirect URL
- Redirect URLs compared exactly — never by prefix
- Sessions, codes and refresh tokens stored hashed; a reused refresh token ends the session
- Sign-in pages with no JavaScript, a strict CSP, and no framing
- The sign-in page shows the domain or app that will receive the person
- Each project signs with its own key; a person's id is different on every project
- An unverified email never links to an existing account
- A production start refuses an unsafe configuration
Each of these has a test. The whole model is in the security notes.
The code you paste
The dashboard shows each application these snippets with its own keys filled in.
// lib/passkin.ts
import { createPasskin } from "@unipass/nextjs/server";
export const { handlers, auth, currentUser, protect, verifyRequest } = createPasskin();
// app/api/auth/[...passkin]/route.ts
import { handlers } from "@/lib/passkin";
export const { GET, POST } = handlers;
// middleware.ts
import { passkinMiddleware } from "@unipass/nextjs/middleware";
export default passkinMiddleware({ protect: ["/dashboard"] });
// app/layout.tsx — <SignInButton />, <UserButton />, useUser() anywhere below
<PasskinProvider initialUser={await currentUser()}>{children}</PasskinProvider>Free during early access
No card, no plan to pick. Everything below is included.
Early access
For every project you create now.
- Google, GitHub and email codes
- Passkin's apps, or your own
- Websites, SPAs, iOS, Android, desktop
- Native Google and Sign in with Apple in apps
- Users, sessions, bans, activity log
- Backend and Management APIs
- Your logo, colour, Arabic and English
- Development and production projects
Questions developers ask
Sign-in, done.
Back to your product.
Create a project, add a redirect URL, paste three files. Your first user can sign in in minutes.