Social login providers (django-allauth)
identity-service stores OAuth client credentials in django-allauth SocialApp rows (linked to companies via CompanyOAuthClient). The service depends on django-allauth 65.14.1 (pyproject.toml / uv.lock).
Source of truth for provider setup steps: the upstream django-allauth socialaccount provider index. Each provider page documents IdP registration, optional Python/OS packages, and SOCIALACCOUNT_PROVIDERS settings.
This page mirrors that catalog for operators planning IdP coverage. It does not imply Shellui ships credentials for every IdP — you still register each client with the provider and attach it to a company.
How this relates to Shellui OAuth
| Layer | What it does |
|---|---|
| django-allauth | Provider modules, SocialApp model, optional vanilla /accounts/… routes (not mounted by default in identity-service) |
| identity-service OAuth API | Identity-hosted flow: GET /api/v1/authorize → IdP → GET /api/v1/oauth/callback → confirmation (optional; Google skips by default) → redirect_to?shellui_auth_code=… — see OAuth login |
| Per-company enablement | Active CompanyOAuthClient rows; GET /api/v1/settings?company_id=… lists providers that have credentials for that company |
IdP callback URL (Shellui flow)
Register one authorization callback on the IdP — the identity host, no query string:
| Environment | Callback URL |
|---|---|
| Local | http://localhost:8000/api/v1/oauth/callback |
| Production | https://<identity-host>/api/v1/oauth/callback |
django-allauth’s default callback pattern (when using stock allauth URLs) is …/accounts/<provider>/login/callback/. identity-service does not expose that path for the Shellui authorize flow; use the table above instead.
Enabling a provider (operator checklist)
- Read the allauth provider page linked from the provider index (scopes, tenant IDs, SAML metadata, etc.).
- Install optional dependencies called out on that page (for example SAML stacks, crypto, or provider-specific libraries). Add OS packages in your container image when allauth documents Debian requirements.
- Enable the provider module in Django: add
allauth.socialaccount.providers.<provider_id>toINSTALLED_APPS(see the provider page — identity-service ships withgithub,google, andmicrosoftonly). - Configure
SOCIALACCOUNT_PROVIDERSin settings when the provider page shows non-default scopes or endpoints (seeconfig/settings.pyfor the stock three). - Create credentials per company: Django admin → Company → OAuth clients, or
POST /api/v1/admin/oauth-social-apps+ company mapping. Each IdP needs its own client id/secret (or SAML metadata) on aSocialApp. - Allowlist shell origins for token delivery (
CompanyOAuthRedirect) — OAuth login → Redirect allowlist.
Stock release wiring: GET /api/v1/authorize, the method picker, and server-side code exchange are implemented for github, google, and microsoft only (apps/authapi/oauth.py). Additional allauth providers are available in the library but require extending that OAuth integration (and SUPPORTED_OAUTH_PROVIDERS) in a custom deploy or future release before they appear in the Shellui login UI. Lower-level APIs (/api/v1/providers/<provider>/authorize/ and /api/v1/providers/<provider>/login/) follow the same provider allowlist today.
Listing a provider here is not a security or legal attestation for that IdP.
Primary / recommended (common starters)
These are typical enterprise, consumer, and developer IdPs. Only GitHub, Google, and Microsoft are wired end-to-end in the stock image; the rest follow the same allauth + SocialApp pattern once your deploy enables the module and OAuth wiring.
| Provider | allauth id | Protocol | Notes |
|---|---|---|---|
google | OAuth 2 / OIDC | Stock — common consumer & Workspace | |
| Microsoft | microsoft | OAuth 2 / OIDC | Stock — Entra ID (Azure AD) & personal accounts; set tenant on SocialApp.settings |
| GitHub | github | OAuth 2 | Stock — developer teams |
| Apple | apple | OAuth 2 / OIDC | Sign in with Apple; extra Apple developer setup |
| GitLab | gitlab | OAuth 2 | Self-hosted or gitlab.com |
| Slack | slack | OAuth 2 | Workspace apps |
| Okta | okta | OAuth 2 / OIDC | Workforce IdP |
| Auth0 | auth0 | OAuth 2 / OIDC | Auth0 tenant |
| Keycloak | openid_connect | OIDC | Configure Keycloak as an OpenID Connect provider (allauth Keycloak guide) |
| OpenID Connect | openid_connect | OIDC | Generic OIDC IdPs |
| SAML | saml | SAML 2.0 | Enterprise SSO; often extra Python/XML dependencies |
| Discord | discord | OAuth 2 | Communities |
facebook | OAuth 2 | Consumer login | |
linkedin_oauth2 | OAuth 2 / OIDC | Prefer OpenID Connect per allauth LinkedIn; legacy module id linkedin_oauth2 | |
| Amazon Cognito | amazon_cognito | OAuth 2 / OIDC | AWS user pools |
For provisioning (not social login), many teams pair OAuth with SCIM for Okta, Entra ID, or similar directories.
Also available (full django-allauth 65.14.1 catalog)
The tables below list provider modules shipped inside django-allauth 65.14.1 (the version pinned in this repository). Primary starters above are omitted here to avoid duplication. Names follow the official provider index where they differ from the Python package slug.
Generic protocol adapters
| Provider | allauth id | Protocol |
|---|---|---|
| OpenID | openid | OpenID 2.0 |
| OAuth 2 (generic) | oauth2 | OAuth 2 |
Enterprise, education & workforce
| Provider | allauth id | Protocol |
|---|---|---|
| Atlassian | atlassian | OAuth 2 |
| Authentiq | authentiq | OAuth 2 |
| Authelia | authelia | OAuth 2 |
| Cilogon | cilogon | OAuth 2 |
| Clever | clever | OAuth 2 |
| Dataporten | dataporten | OAuth 2 |
| Edmodo | edmodo | OAuth 2 |
| Edx | edx | OAuth 2 |
| Globus | globus | OAuth 2 |
| JupyterHub | jupyterhub | OAuth 2 |
| LemonLDAP::NG | lemonldap | OAuth 2 |
| Netiq | netiq | OAuth 2 |
| Nextcloud | nextcloud | OAuth 2 |
| ORCID | orcid | OAuth 2 |
| Salesforce | salesforce | OAuth 2 |
| Sharefile | sharefile | OAuth 2 |
| Windows Live | windowslive | OAuth 2 |
| Zoho | zoho | OAuth 2 |
| Cern | cern | OAuth 2 |
Developer tools & collaboration
Consumer, social & media
| Provider | allauth id | Protocol |
|---|---|---|
| 23andMe | twentythreeandme | OAuth 2 |
| 500px | fivehundredpx | OAuth 2 |
| Angellist | angellist | OAuth 2 |
| Disqus | disqus | OAuth 2 |
| Douban | douban | OAuth 2 |
| Flickr | flickr | OAuth 1 |
| Foursquare | foursquare | OAuth 2 |
instagram | OAuth 2 | |
| Kakao | kakao | OAuth 2 |
| Line | line | OAuth 2 |
| Meetup | meetup | OAuth 2 |
| Odnoklassniki | odnoklassniki | OAuth 2 |
pinterest | OAuth 2 | |
reddit | OAuth 2 | |
| Snapchat | snapchat | OAuth 2 |
| Soundcloud | soundcloud | OAuth 2 |
| Spotify | spotify | OAuth 2 |
| Steam | steam | OpenID |
| Tiktok | tiktok | OAuth 2 |
| Tumblr | tumblr | OAuth 2 |
| Tumblr (OAuth 2) | tumblr_oauth2 | OAuth 2 |
| Twitch | twitch | OAuth 2 |
| Untappd | untappd | OAuth 2 |
| Vimeo | vimeo | OAuth 1 |
| Vimeo (OAuth 2) | vimeo_oauth2 | OAuth 2 |
| Vk | vk | OAuth 2 |
weibo | OAuth 2 | |
| Weixin (WeChat) | weixin | OAuth 2 |
| X / Twitter (OAuth 1) | twitter | OAuth 1 |
| X / Twitter (OAuth 2) | twitter_oauth2 | OAuth 2 |
xing | OAuth 1 | |
| Yahoo | yahoo | OAuth 2 |
| Yandex | yandex | OAuth 2 |
Commerce, finance & productivity
| Provider | allauth id | Protocol |
|---|---|---|
| Amazon | amazon | OAuth 2 |
| Asana | asana | OAuth 2 |
| Coinbase | coinbase | OAuth 2 |
| Dwolla | dwolla | OAuth 2 |
| Eventbrite | eventbrite | OAuth 2 |
| Feedly | feedly | OAuth 2 |
| Feishu | feishu | OAuth 2 |
| Figma | figma | OAuth 2 |
| Gumroad | gumroad | OAuth 2 |
| Hubspot | hubspot | OAuth 2 |
| Klaviyo | klaviyo | OAuth 2 |
| Mailchimp | mailchimp | OAuth 2 |
| Mailru | mailru | OAuth 2 |
| Patreon | patreon | OAuth 2 |
| Paypal | paypal | OAuth 2 |
pocket | OAuth 1 | |
| Questrade | questrade | OAuth 2 |
| Quickbooks | quickbooks | OAuth 2 |
| Robinhood | robinhood | OAuth 2 |
| Shopify | shopify | OAuth 2 |
| Stocktwits | stocktwits | OAuth 2 |
| Strava | strava | OAuth 2 |
| Stripe | stripe | OAuth 2 |
| Trainingpeaks | trainingpeaks | OAuth 2 |
| Ynab | ynab | OAuth 2 |
Regional, specialty & other
| Provider | allauth id | Protocol |
|---|---|---|
| Agave | agave | OAuth 2 |
| Baidu | baidu | OAuth 2 |
| Basecamp | basecamp | OAuth 2 |
| Battlenet | battlenet | OAuth 2 |
| Bitly | bitly | OAuth 2 |
| Daum | daum | OAuth 2 |
| Digitalocean | digitalocean | OAuth 2 |
| Dingtalk | dingtalk | OAuth 2 |
| Discogs | discogs | OAuth 1 |
| Doximity | doximity | OAuth 2 |
| Draugiem | draugiem | OAuth 2 |
| Drip | drip | OAuth 2 |
| Eveonline | eveonline | OAuth 2 |
| Evernote | evernote | OAuth 1 |
| Exist | exist | OAuth 2 |
| Firefox Accounts | fxa | OAuth 2 |
| Frontier | frontier | OAuth 2 |
| Hubic | hubic | OAuth 2 |
| Lichess | lichess | OAuth 2 |
| Mailcow | mailcow | OAuth 2 |
| Naver | naver | OAuth 2 |
| Openstreetmap | openstreetmap | OAuth 1 |
| Telegram | telegram | Login widget |
| Wahoo | wahoo | OAuth 2 |
Upstream index vs this pin
The latest allauth provider index may document providers before they appear in a given release. This repository pins django-allauth 65.14.1 — module lists above reflect that wheel. Upstream pages for Authelia, CERN, and Klaviyo are included in the enterprise/commerce tables for planning; upgrade django-allauth before enabling those modules.
Some package modules (for example angellist, spotify, tumblr) do not yet have dedicated upstream doc pages — use the provider index and module source in the allauth package.
See also
- OAuth login — Shellui authorize/callback flow, redirect allowlist, upgrades
- Company access — join modes after a successful login
- Configuration — environment variables and production checklist