🚀 Join the waitlist now! waitlist.floot.dev
LogoFlootdocs
AuthSocial

GitHub

Learn how to configure GitHub OAuth for authentication in your Floot app.

The GitHub button is already on the sign-in and sign-up screens, beside email and password. It is the simplest of the three providers: one OAuth app, two values, and the same browser flow on every platform, since GitHub has no native SDK, so there is nothing platform-specific to configure.

There is no ENABLE_ flag for GitHub

Unlike Google Sign-In, GitHub is not behind a feature flag. Nothing to flip in .env.local; what gates it is [auth.external.github].enabled in supabase/config.toml, which ships false.

GitHub Developer Settings

Register a new OAuth app

Go to OAuth apps page → New OAuth App

  • Application name > give a meaningful name
  • Homepage URL > type the full URL to your app's website
  • Authorization callback URL > options:
http://127.0.0.1:54321/auth/v1/callback
  • Enable Device Flow > unchecked

→ Register application

That callback is Supabase's, not your app's

The URL above is where GitHub returns the user to Supabase Auth. Getting the user from there back into your app is a second, separate hop over a deep link; see Deep Links.

Get Credentials

Open your created OAuth app

Client ID

Copy and save your Client ID

Client Secret

  • Click Generate a new client secret
  • Copy and save your Client secret

When using Supabase Cloud, register the Client ID and Secret that will be using your Supabase project in the GitHub provider configuration in the Supabase dashboard.

Floot App Setup

The Supabase environment

Both values are backend-only: the Flutter app never sees a GitHub credential.

supabase/.env.local
OAUTH_GITHUB_CLIENT_ID=Ov23li...
OAUTH_GITHUB_SECRET=...
SB_AUTH_EXTERNAL_REDIRECT_URI=http://127.0.0.1:54321/auth/v1/callback

SB_AUTH_EXTERNAL_REDIRECT_URI is the same callback you registered as the Authorization callback URL, and it is shared with Google Sign-In. It is also one of the values the Edge Functions require at startup: blank it out and supabase functions serve refuses to boot, taking sign-up confirmation and password-reset emails with it. floot create prefills the local value.

The Supabase config

supabase/config.toml already wires every key to a variable. Only enabled needs your hand:

supabase/config.toml
[auth.external.github]
enabled = true
KeyShips asWhat to do
enabledfalseFlip it to true
client_idenv(OAUTH_GITHUB_CLIENT_ID)Leave it; fill the variable
secretenv(OAUTH_GITHUB_SECRET)Leave it; fill the variable
redirect_urienv(SB_AUTH_EXTERNAL_REDIRECT_URI)Leave it; fill the variable

config.toml configures your local stack only. On a hosted project the same provider is configured in the dashboard, under Authentication → Sign In / Providers → GitHub.

OAuth deep link redirection

The return trip uses OAUTH_REDIRECT_URL, and Supabase only honours it because the same URL is on the additional_redirect_urls allow-list. Both are already wired by floot create.

→ Check them against Deep Links.

On this page