Users and accounts

Social login

Social login lets people sign up and log in with an account they already have, instead of creating a new password.

Supported providers

You can enable Google, Facebook, GitHub and Discord. Apple is listed as Coming soon and cannot be turned on yet.

Each provider needs its own app in that provider's developer console. The app gives you a client ID and a client secret, which you paste into XFORG.

Connect a provider

1

Open onboarding

Go to Users and leads, then Users Onboarding.

2

Allow signups

Make sure Enable Signup is on. The Social Login Integrations switches can only be turned on while it is.

3

Enable the provider

Turn on the provider, for example Enable Google Signup/Login.

4

Follow the guide

Click How to get these credentials. It lists the steps for that provider, shows the Redirect URI to register, and has a button to open the provider's console.

5

Paste the credentials

Enter the Client ID and Client secret. Scopes can stay empty to use the provider's default.

6

Save

Click Update.

An enabled provider needs both a Client ID and a Client secret before you can save.

The redirect URI

The Redirect URI is where the provider sends people back after they approve the login. It is built from your site's own address and cannot be edited.

Register the redirect URI with the provider once for every address visitors use, for example with and without www. A missing one makes the login fail for visitors on that address.

A saved secret is kept hidden. Leave the field untouched to keep the stored secret.

Add the buttons

Add the Social logins element to your login and signup pages. It shows the providers you enabled in Users Onboarding.

Button wording

Sign in or Sign up.

Button style

Full label, Provider name or Icon only.

Colors

Brand colors or Match theme.

Divider

An optional line with the word or, above or below the buttons.

How accounts are matched

Someone who has signed in with that provider before goes straight to their account.

If the provider confirms an email that matches an existing account or lead, that record is linked and becomes a user.

If the email matches but the provider has not confirmed it, the login is refused. The person can still log in with their password.

Otherwise a new account is created, as long as Enable Signup is on.

After signing in, people go to your Profile completion page if required information is missing, otherwise to your Post-Auth Redirect Page.