Self-hosting
Log in with Google, GitHub, and more
Let people log in with Google, Microsoft, GitHub, GitLab, or your own single sign-on (OIDC) provider.
Let people log in with Google, Microsoft, GitHub, GitLab, or your own single sign-on (OIDC) provider.
OneDrop can show Continue with … buttons on the log-in and sign-up pages. Each provider appears once you add its OAuth client ID and secret to .env. With none set, the pages look as they do out of the box.
| Provider | Email treated as verified when… |
|---|---|
Google reports email_verified | |
| GitHub | Always. OneDrop only reads the account’s primary, verified email |
| GitLab | The account’s email is confirmed (confirmed_at) |
| OIDC | The issuer reports email_verified |
| Microsoft | Never. People confirm the email by link, like a normal sign-up |
When you create the OAuth app at each provider, use this redirect (callback) URL, with your APP_URL:
https://zap.example.com/login/{provider}/callback
where {provider} is google, microsoft, github, gitlab, or oidc.
After changing .env on a server, run php artisan config:cache (the deploy script does this for you).
Sign-up rules still apply. If you turn off registration, providers only log in people who already have an account.
https://zap.example.com/login/google/callback as an authorized redirect URI..env:GOOGLE_CLIENT_ID=...
GOOGLE_CLIENT_SECRET=...