Skip to main content

Social login providers (django-allauth)

identity-service stores OAuth client credentials in django-allauth SocialApp rows (linked to companies via CompanyOAuthClient). The service depends on django-allauth 65.14.1 (pyproject.toml / uv.lock).

Source of truth for provider setup steps: the upstream django-allauth socialaccount provider index. Each provider page documents IdP registration, optional Python/OS packages, and SOCIALACCOUNT_PROVIDERS settings.

This page mirrors that catalog for operators planning IdP coverage. It does not imply Shellui ships credentials for every IdP — you still register each client with the provider and attach it to a company.


How this relates to Shellui OAuth​

LayerWhat it does
django-allauthProvider modules, SocialApp model, optional vanilla /accounts/… routes (not mounted by default in identity-service)
identity-service OAuth APIIdentity-hosted flow: GET /api/v1/authorize → IdP → GET /api/v1/oauth/callback → confirmation (optional; Google skips by default) → redirect_to?shellui_auth_code=… — see OAuth login
Per-company enablementActive CompanyOAuthClient rows; GET /api/v1/settings?company_id=… lists providers that have credentials for that company

IdP callback URL (Shellui flow)​

Register one authorization callback on the IdP — the identity host, no query string:

EnvironmentCallback URL
Localhttp://localhost:8000/api/v1/oauth/callback
Productionhttps://<identity-host>/api/v1/oauth/callback

django-allauth’s default callback pattern (when using stock allauth URLs) is …/accounts/<provider>/login/callback/. identity-service does not expose that path for the Shellui authorize flow; use the table above instead.

Enabling a provider (operator checklist)​

  1. Read the allauth provider page linked from the provider index (scopes, tenant IDs, SAML metadata, etc.).
  2. Install optional dependencies called out on that page (for example SAML stacks, crypto, or provider-specific libraries). Add OS packages in your container image when allauth documents Debian requirements.
  3. Enable the provider module in Django: add allauth.socialaccount.providers.<provider_id> to INSTALLED_APPS (see the provider page — identity-service ships with github, google, and microsoft only).
  4. Configure SOCIALACCOUNT_PROVIDERS in settings when the provider page shows non-default scopes or endpoints (see config/settings.py for the stock three).
  5. Create credentials per company: Django admin → Company → OAuth clients, or POST /api/v1/admin/oauth-social-apps + company mapping. Each IdP needs its own client id/secret (or SAML metadata) on a SocialApp.
  6. Allowlist shell origins for token delivery (CompanyOAuthRedirect) — OAuth login → Redirect allowlist.

Stock release wiring: GET /api/v1/authorize, the method picker, and server-side code exchange are implemented for github, google, and microsoft only (apps/authapi/oauth.py). Additional allauth providers are available in the library but require extending that OAuth integration (and SUPPORTED_OAUTH_PROVIDERS) in a custom deploy or future release before they appear in the Shellui login UI. Lower-level APIs (/api/v1/providers/<provider>/authorize/ and /api/v1/providers/<provider>/login/) follow the same provider allowlist today.

Listing a provider here is not a security or legal attestation for that IdP.


These are typical enterprise, consumer, and developer IdPs. Only GitHub, Google, and Microsoft are wired end-to-end in the stock image; the rest follow the same allauth + SocialApp pattern once your deploy enables the module and OAuth wiring.

Providerallauth idProtocolNotes
GooglegoogleOAuth 2 / OIDCStock — common consumer & Workspace
MicrosoftmicrosoftOAuth 2 / OIDCStock — Entra ID (Azure AD) & personal accounts; set tenant on SocialApp.settings
GitHubgithubOAuth 2Stock — developer teams
AppleappleOAuth 2 / OIDCSign in with Apple; extra Apple developer setup
GitLabgitlabOAuth 2Self-hosted or gitlab.com
SlackslackOAuth 2Workspace apps
OktaoktaOAuth 2 / OIDCWorkforce IdP
Auth0auth0OAuth 2 / OIDCAuth0 tenant
Keycloakopenid_connectOIDCConfigure Keycloak as an OpenID Connect provider (allauth Keycloak guide)
OpenID Connectopenid_connectOIDCGeneric OIDC IdPs
SAMLsamlSAML 2.0Enterprise SSO; often extra Python/XML dependencies
DiscorddiscordOAuth 2Communities
FacebookfacebookOAuth 2Consumer login
LinkedInlinkedin_oauth2OAuth 2 / OIDCPrefer OpenID Connect per allauth LinkedIn; legacy module id linkedin_oauth2
Amazon Cognitoamazon_cognitoOAuth 2 / OIDCAWS user pools

For provisioning (not social login), many teams pair OAuth with SCIM for Okta, Entra ID, or similar directories.


Also available (full django-allauth 65.14.1 catalog)​

The tables below list provider modules shipped inside django-allauth 65.14.1 (the version pinned in this repository). Primary starters above are omitted here to avoid duplication. Names follow the official provider index where they differ from the Python package slug.

Generic protocol adapters
Providerallauth idProtocol
OpenIDopenidOpenID 2.0
OAuth 2 (generic)oauth2OAuth 2
Enterprise, education & workforce
Providerallauth idProtocol
AtlassianatlassianOAuth 2
AuthentiqauthentiqOAuth 2
AutheliaautheliaOAuth 2
CilogoncilogonOAuth 2
ClevercleverOAuth 2
DataportendataportenOAuth 2
EdmodoedmodoOAuth 2
EdxedxOAuth 2
GlobusglobusOAuth 2
JupyterHubjupyterhubOAuth 2
LemonLDAP::NGlemonldapOAuth 2
NetiqnetiqOAuth 2
NextcloudnextcloudOAuth 2
ORCIDorcidOAuth 2
SalesforcesalesforceOAuth 2
SharefilesharefileOAuth 2
Windows LivewindowsliveOAuth 2
ZohozohoOAuth 2
CerncernOAuth 2
Developer tools & collaboration
Providerallauth idProtocol
Bitbucketbitbucket_oauth2OAuth 2
BoxboxOAuth 2
DropboxdropboxOAuth 2
GiteagiteaOAuth 2
MediawikimediawikiOAuth 2
MiromiroOAuth 2
NotionnotionOAuth 2
StackexchangestackexchangeOAuth 2
TrellotrelloOAuth 1
ZoomzoomOAuth 2
Consumer, social & media
Providerallauth idProtocol
23andMetwentythreeandmeOAuth 2
500pxfivehundredpxOAuth 2
AngellistangellistOAuth 2
DisqusdisqusOAuth 2
DoubandoubanOAuth 2
FlickrflickrOAuth 1
FoursquarefoursquareOAuth 2
InstagraminstagramOAuth 2
KakaokakaoOAuth 2
LinelineOAuth 2
MeetupmeetupOAuth 2
OdnoklassnikiodnoklassnikiOAuth 2
PinterestpinterestOAuth 2
RedditredditOAuth 2
SnapchatsnapchatOAuth 2
SoundcloudsoundcloudOAuth 2
SpotifyspotifyOAuth 2
SteamsteamOpenID
TiktoktiktokOAuth 2
TumblrtumblrOAuth 2
Tumblr (OAuth 2)tumblr_oauth2OAuth 2
TwitchtwitchOAuth 2
UntappduntappdOAuth 2
VimeovimeoOAuth 1
Vimeo (OAuth 2)vimeo_oauth2OAuth 2
VkvkOAuth 2
WeiboweiboOAuth 2
Weixin (WeChat)weixinOAuth 2
X / Twitter (OAuth 1)twitterOAuth 1
X / Twitter (OAuth 2)twitter_oauth2OAuth 2
XingxingOAuth 1
YahooyahooOAuth 2
YandexyandexOAuth 2
Commerce, finance & productivity
Providerallauth idProtocol
AmazonamazonOAuth 2
AsanaasanaOAuth 2
CoinbasecoinbaseOAuth 2
DwolladwollaOAuth 2
EventbriteeventbriteOAuth 2
FeedlyfeedlyOAuth 2
FeishufeishuOAuth 2
FigmafigmaOAuth 2
GumroadgumroadOAuth 2
HubspothubspotOAuth 2
KlaviyoklaviyoOAuth 2
MailchimpmailchimpOAuth 2
MailrumailruOAuth 2
PatreonpatreonOAuth 2
PaypalpaypalOAuth 2
PocketpocketOAuth 1
QuestradequestradeOAuth 2
QuickbooksquickbooksOAuth 2
RobinhoodrobinhoodOAuth 2
ShopifyshopifyOAuth 2
StocktwitsstocktwitsOAuth 2
StravastravaOAuth 2
StripestripeOAuth 2
TrainingpeakstrainingpeaksOAuth 2
YnabynabOAuth 2
Regional, specialty & other
Providerallauth idProtocol
AgaveagaveOAuth 2
BaidubaiduOAuth 2
BasecampbasecampOAuth 2
BattlenetbattlenetOAuth 2
BitlybitlyOAuth 2
DaumdaumOAuth 2
DigitaloceandigitaloceanOAuth 2
DingtalkdingtalkOAuth 2
DiscogsdiscogsOAuth 1
DoximitydoximityOAuth 2
DraugiemdraugiemOAuth 2
DripdripOAuth 2
EveonlineeveonlineOAuth 2
EvernoteevernoteOAuth 1
ExistexistOAuth 2
Firefox AccountsfxaOAuth 2
FrontierfrontierOAuth 2
HubichubicOAuth 2
LichesslichessOAuth 2
MailcowmailcowOAuth 2
NavernaverOAuth 2
OpenstreetmapopenstreetmapOAuth 1
TelegramtelegramLogin widget
WahoowahooOAuth 2

Upstream index vs this pin​

The latest allauth provider index may document providers before they appear in a given release. This repository pins django-allauth 65.14.1 — module lists above reflect that wheel. Upstream pages for Authelia, CERN, and Klaviyo are included in the enterprise/commerce tables for planning; upgrade django-allauth before enabling those modules.

Some package modules (for example angellist, spotify, tumblr) do not yet have dedicated upstream doc pages — use the provider index and module source in the allauth package.


See also​

  • OAuth login — Shellui authorize/callback flow, redirect allowlist, upgrades
  • Company access — join modes after a successful login
  • Configuration — environment variables and production checklist