GitHub
Learn how to configure GitHub OAuth for authentication in your Floot app.
The GitHub button is already on the sign-in and sign-up screens, beside email and password. It is the simplest of the three providers: one OAuth app, two values, and the same browser flow on every platform, since GitHub has no native SDK, so there is nothing platform-specific to configure.
There is no ENABLE_ flag for GitHub
Unlike Google Sign-In, GitHub is not behind a feature flag.
Nothing to flip in .env.local; what gates it is
[auth.external.github].enabled in supabase/config.toml, which ships
false.
GitHub Developer Settings
Register a new OAuth app
Go to OAuth apps page → New OAuth App
- Application name > give a meaningful name
- Homepage URL > type the full URL to your app's website
- Authorization callback URL > options:
http://127.0.0.1:54321/auth/v1/callback- Enable Device Flow > unchecked
→ Register application
That callback is Supabase's, not your app's
The URL above is where GitHub returns the user to Supabase Auth. Getting the user from there back into your app is a second, separate hop over a deep link; see Deep Links.
Get Credentials
Open your created OAuth app
Client ID
Copy and save your Client ID
Client Secret
- Click
Generate a new client secret - Copy and save your Client secret
When using Supabase Cloud, register the Client ID and Secret that will be using your Supabase project in the GitHub provider configuration in the Supabase dashboard.
Floot App Setup
The Supabase environment
Both values are backend-only: the Flutter app never sees a GitHub credential.
OAUTH_GITHUB_CLIENT_ID=Ov23li...
OAUTH_GITHUB_SECRET=...
SB_AUTH_EXTERNAL_REDIRECT_URI=http://127.0.0.1:54321/auth/v1/callbackSB_AUTH_EXTERNAL_REDIRECT_URI is the same callback you registered as the
Authorization callback URL, and it is shared with Google
Sign-In. It is also one of the values the Edge Functions require at
startup: blank it out and supabase functions serve refuses to boot, taking
sign-up confirmation and password-reset emails with it. floot create prefills
the local value.
The Supabase config
supabase/config.toml already wires every key to a variable. Only enabled
needs your hand:
[auth.external.github]
enabled = true| Key | Ships as | What to do |
|---|---|---|
enabled | false | Flip it to true |
client_id | env(OAUTH_GITHUB_CLIENT_ID) | Leave it; fill the variable |
secret | env(OAUTH_GITHUB_SECRET) | Leave it; fill the variable |
redirect_uri | env(SB_AUTH_EXTERNAL_REDIRECT_URI) | Leave it; fill the variable |
config.toml configures your local stack only. On a hosted project the same
provider is configured in the dashboard, under Authentication → Sign In /
Providers → GitHub.
OAuth deep link redirection
The return trip uses OAUTH_REDIRECT_URL, and Supabase only honours it because
the same URL is on the additional_redirect_urls allow-list. Both are already
wired by floot create.
→ Check them against Deep Links.