Ory logo

Sign in with Apple Integration

Apple's privacy-focused federated authentication service for users with an Apple ID. It is mandatory for apps on Apple platforms that offer third-party social logins. A key feature is Hide My Email, which allows a user to share a unique, random, relay email address with the application instead of their personal email, prioritizing user privacy

Apple logo

Sign in with Apple

Benefits with Ory + Sign in with Apple Integration

Ory Kratos handles the OIDC flow, but importantly, it manages the private relay email from Apple. This ensures that even when a user chooses to hide their real email, your application can still uniquely identify and message them through the relay, all while storing the user's identity data securely within the Ory identity schema

Use Cases

CIAM

Solves the challenge of consumer privacy concerns by managing Apple's private relay emails securely, ensuring unique identification while respecting user preferences and App Store guidelines

Explore CIAM

Core Functionality

  1. Seamless Apple Integration

    Functions natively as a first-party OIDC provider, ensuring smooth authentication with automatic CSRF handling.

  2. Secure Credential Management

    Employs JWT-signed client assertions using Apple's specific credentials for robust security.

  3. Effortless Account Linking

    Automatically connects Apple consumer accounts to existing identities that share a verified email address.

  4. Native iOS Optimization

    Streamlines mobile authentication by validating tokens directly from Apple's SDK.

  5. Privacy-First Compatibility

    Fully supports Apple's "Hide My Email" feature by securely processing and persisting private relay addresses

Frequently Asked Questions