Google Login
Options
Example
React Component
GitHub Login
Options
Example
React Component
OAuth Flow
- User clicks social login button
- SDK sends the user to Gately, which checks
redirectTois allowed for your project - Gately redirects to the OAuth provider (Google/GitHub)
- User authorizes your application
- Provider redirects back to Gately, which signs the user in
- Gately redirects to
redirectTowith a single-usegately_code - SDK exchanges the code for the session and the user is logged in
Configuration
Enable OAuth Providers
- Go to Settings > Social Sign-On in your dashboard
- Enable Google and/or GitHub
- Add your OAuth credentials
Google Setup
- Go to Google Cloud Console
- Create a new project or select existing
- Enable Google+ API
- Create OAuth 2.0 credentials
- Add authorized redirect URI:
https://api.usegately.com/sdk/sso/google/callback - Copy Client ID and Client Secret to Gately
GitHub Setup
- Go to GitHub Developer Settings
- Create a new OAuth App
- Set Authorization callback URL:
https://api.usegately.com/api/auth/github/callback - Copy Client ID and Client Secret to Gately
If OAuth runs on your custom domain (see below), use that domain in place of
api.usegately.com in both callback URLs.Custom Domain
If you have a custom domain configured:Handling OAuth Redirect
The SDK automatically handles OAuth redirects. When the user lands onredirectTo with a gately_code parameter, the SDK:
- Removes
gately_codefrom the address bar - Exchanges the code for the session (codes are single-use and expire after 60 seconds)
- Saves the session to localStorage
- Dispatches the
gately:auth-successevent (orgately:auth-errorif the exchange fails)
Without the SDK
If you start OAuth yourself, addresponse_mode=code so Gately returns a one-time code instead of putting the session in the URL:
gately_code from the redirect within 60 seconds:
Without
response_mode=code, Gately falls back to the legacy behavior of adding gately_session and gately_user to the redirect URL. This is only kept for older SDK versions; the redirect URL must still be allowed.