Skip to main content
Gately supports OAuth authentication with Google and GitHub, allowing users to sign in with their existing accounts.
redirectTo must be on a domain your project owns. Add your site under Allowed Redirect URLs before going live, or sign-in will be rejected.

Google Login

Options

Example

React Component

GitHub Login

Options

Example

React Component

OAuth Flow

  1. User clicks social login button
  2. SDK sends the user to Gately, which checks redirectTo is allowed for your project
  3. Gately redirects to the OAuth provider (Google/GitHub)
  4. User authorizes your application
  5. Provider redirects back to Gately, which signs the user in
  6. Gately redirects to redirectTo with a single-use gately_code
  7. SDK exchanges the code for the session and the user is logged in

Configuration

Enable OAuth Providers

  1. Go to Settings > Social Sign-On in your dashboard
  2. Enable Google and/or GitHub
  3. Add your OAuth credentials

Google Setup

  1. Go to Google Cloud Console
  2. Create a new project or select existing
  3. Enable Google+ API
  4. Create OAuth 2.0 credentials
  5. Add authorized redirect URI: https://api.usegately.com/sdk/sso/google/callback
  6. Copy Client ID and Client Secret to Gately

GitHub Setup

  1. Go to GitHub Developer Settings
  2. Create a new OAuth App
  3. Set Authorization callback URL: https://api.usegately.com/api/auth/github/callback
  4. Copy Client ID and Client Secret to Gately
If OAuth runs on your custom domain (see below), use that domain in place of api.usegately.com in both callback URLs.

Custom Domain

If you have a custom domain configured:

Handling OAuth Redirect

The SDK automatically handles OAuth redirects. When the user lands on redirectTo with a gately_code parameter, the SDK:
  1. Removes gately_code from the address bar
  2. Exchanges the code for the session (codes are single-use and expire after 60 seconds)
  3. Saves the session to localStorage
  4. Dispatches the gately:auth-success event (or gately:auth-error if the exchange fails)
Make sure the SDK is initialized on the page you redirect to.

Without the SDK

If you start OAuth yourself, add response_mode=code so Gately returns a one-time code instead of putting the session in the URL:
Then exchange the gately_code from the redirect within 60 seconds:
Without response_mode=code, Gately falls back to the legacy behavior of adding gately_session and gately_user to the redirect URL. This is only kept for older SDK versions; the redirect URL must still be allowed.

Error Handling

User Data from OAuth

OAuth providers return user profile data:

Google

GitHub

Linking Accounts

If a user signs up with email and later tries to login with OAuth using the same email, the accounts are automatically linked. Linking only happens with a verified email address: Google accounts must have a verified email, and for GitHub Gately uses the account’s primary verified email (an unverified profile email is ignored). Users without one see an error asking them to verify their email with the provider.