Apple OAuth setup for Authverse projects
This page details how to add and configure Apple OAuth for Authverse projects.
Execute the following command to add the Apple provider to your project:
npx authverse@latest oauth appleThe command installs jose, adds the Apple provider to your socialProviders, and adds https://appleid.apple.com to trustedOrigins in auth.ts.
To support Apple Sign-In, you need to configure your app in the Apple Developer Portal. Apple Sign In requires an active Apple Developer account.
APPLE_CLIENT_ID).https://yourdomain.com/api/auth/callback/apple.p8 file) and note the Key ID and your Team ID.[!WARNING] Apple does not support
localhostor non-HTTPS return URLs. During development you must use a domain with a valid HTTPS/TLS certificate. The Return URL must exactly match the callback URL used by your deployment.
[!IMPORTANT] Apple emits the
Add the following variables to your project's .env file:
APPLE_CLIENT_ID=
APPLE_TEAM_ID=
APPLE_KEY_ID=
APPLE_PRIVATE_KEY=
APPLE_BUNDLE_ID=.p8 key file. When stored in an environment variable, escaped \n newlines are handled automatically.The clientSecret JWT is generated automatically for you in auth.ts from these values using the jose package. You do not need to generate or commit a static client secret.
Import the prebuilt provider component and integrate it into your UI:
import { AppleOAuthButton } from "@/components/authverse/AppleOAuthButton";
<AppleOAuthButton />;This component renders the Apple sign-in button at its location.
https://yourdomain.com/api/auth/callback/apple. Localhost is not supported by Apple.https://appleid.apple.com to be in your trusted origins list. The CLI adds it without removing any user-defined origins.APPLE_BUNDLE_ID is set to your native app's bundle identifier.generateAppleClientSecret() function — no manual rotation needed.