//Apple Sign-In
Apple Sign-In via Apple-tagged OIDC
Apple login is supported through the same federated OIDC engine that powers Google and Microsoft sign-in. To expose an Apple button on your login page, configure an Apple-tagged OpenID Connect connection and ensure it is enabled through your organization security policy.
1. Register with Apple and create a Services ID.
- Client ID: use the Apple Services ID (e.g.
com.example.app). - Client secret: generate an Apple JWT (signed with your private key) that is valid for the connection.
- The platform treats this connection like the Google sign-in connection, just with Apple metadata.
- Allow the
appleprovider in the org security policy so that the Apple-tagged connection can surface on the login screen. - Once the connection exists and Apple is allowed by policy, the login page shows Continue with Apple automatically.
- If the connection is configured but Apple has been disabled in policy, the button remains hidden and the org admin error message will mention the disabled provider.
- The workflow keeps hitting the OIDC endpoints for Apple for both login and token refresh, so existing Google-based logic applies. Any policy requiring Apple login for particular user groups can be enforced through the same organization security policy rules you already use for Google.
2. Create an OIDC connection in the ButtrBase organization security page and mark it with the apple provider tag.
3. Update organization policy.
4. Enable the button.
5. Match Google-like behavior.
Refer to the Apple client documentation inside the platform at /appleClientDoc for screenshots and exact parameter names.