Social sign-in
Use googleLogin() or appleLogin() after your application has completed the corresponding provider sign-in and received a provider result. The SDK sends that result to the configured Ovok environment and returns an authenticated result.
The SDK does not display a provider sign-in screen or obtain provider credentials. Your application owns that interaction and must pass the result supplied by the provider's SDK.
Configure the client and project
Set the socialLoginClientId client option to the client ID configured for the target environment. Keep the value aligned with the API URL and project configuration. Both methods also require an internalId associated with the project's external-auth configuration; obtain the value from your Ovok project configuration.
Start with the official authentication overview and project setup guide to confirm the environment and account flows.
Google
Call googleLogin() with the provider's idToken and the configured internalId. The request can also include the provider's access token, token lifetime, OAuth scope, and token type when those values are available.
The ID token is the primary credential for this method. Do not substitute an authorization code or an access token for idToken.
The example assumes the provider flow has returned a credential and the application has the configured internalId.
async function finishGoogleSignIn(googleCredential) {
const authenticated = await client.googleLogin({
internalId,
idToken: googleCredential.idToken,
});
onSignedIn(authenticated);
}
Apple
Call appleLogin() with Apple's identity result and the configured internalId. The method accepts:
| Field | What it represents |
|---|---|
identityToken | Signed identity information returned by Apple. |
user | Apple user identifier for the app's development team. |
state | The state value associated with the sign-in request, when supplied. |
fullName | Name information, which may be unavailable after the first authorization or when the scope was not requested. |
email | Email returned by Apple; it may be hidden or unavailable depending on the user's choice and authorization. |
authorizationCode | Short-lived authorization code, when returned. |
realUserStatus | Provider signal about whether the user appears to be a real person. |
Pass the provider result as received and account for optional or unavailable values in your application.
async function finishAppleSignIn(appleCredential) {
const authenticated = await client.appleLogin({
internalId,
identityToken: appleCredential.identityToken,
user: appleCredential.user,
state: appleCredential.state,
fullName: appleCredential.fullName,
email: appleCredential.email,
realUserStatus: appleCredential.realUserStatus,
authorizationCode: appleCredential.authorizationCode,
});
onSignedIn(authenticated);
}
Handle first-time sign-in
The first Google or Apple sign-in can create a patient account when the project is configured for that behavior. Review the patient registration and invitation settings before making provider sign-in available. The patient registration guide describes this behavior, and PATIENT_INVITATION_ENABLED controls invitation behavior.
Handle errors and completion
Provider cancellation or provider-side errors should be handled before calling the SDK method. If the SDK call succeeds, use the returned profile and project to enter the signed-in experience. If it fails, keep the user on the sign-in path and show a useful recovery action without exposing provider tokens or sensitive error details.