Apple Sign-In Integration
Add Sign in with Apple to your Firebase app, satisfy Apple's App Store requirement for social logins, and handle Apple's privacy-focused email relay correctly.
Apple Sign-In Integration is a free Firebase Auth & Realtime Database Apps lesson on CoddyKit — lesson 4 of 4. You can read the complete lesson below for free — then practise it hands-on in the browser with a built-in code editor and a 24/7 AI tutor. It is part of the Firebase Auth & Realtime Database Apps learning path, one of 4 lessons in the course, and your progress syncs across the web and the CoddyKit app.
Why Apple Sign-In
If your iOS app offers any third-party social login (Google, Facebook, etc.), Apple's App Store guidelines require you to also offer Sign in with Apple. Beyond compliance, it is a fast, privacy-respecting option users trust.
How It Differs
Apple Sign-In has unique traits compared to other providers:
- Users can hide their real email via a private relay address
- Name and email are only returned on the first sign-in
- Requires an Apple Developer account to configure
Enabling the Provider
In the Firebase console open Authentication > Sign-in method and enable Apple. For web you must also supply your Apple Service ID, Team ID, Key ID, and a private key generated in the Apple Developer portal.
Configuring the OAuth Provider
On the web you use Firebase's OAuthProvider with the Apple provider ID and request the scopes you need.
import { OAuthProvider } from 'firebase/auth';
const provider = new OAuthProvider('apple.com');
provider.addScope('email');
provider.addScope('name');Triggering the Sign-In
Use signInWithPopup (or redirect on mobile web) to launch the Apple flow and receive a Firebase user.
import { getAuth, signInWithPopup } from 'firebase/auth';
const result = await signInWithPopup(getAuth(), provider);
const user = result.user;
console.log('Signed in as', user.uid);Capturing Name on First Sign-In
Apple sends the user's full name only once, on the very first authorization. Persist it immediately, because subsequent sign-ins will not include it.
const credential = OAuthProvider.credentialFromResult(result);
const fullName = result._tokenResponse?.displayName;
if (fullName) saveProfileName(user.uid, fullName);The Private Email Relay
If a user chooses to hide their email, Apple returns a relay address like abc123@privaterelay.appleid.com. Email sent to it is forwarded to the user.
- Treat it as a valid, stable email
- Do not require the 'real' address
Account Linking
A user may sign in with Apple after previously using email/password with the same address. Use Firebase account linking to merge identities into a single account rather than creating duplicates.
import { linkWithCredential } from 'firebase/auth';
const cred = OAuthProvider.credentialFromResult(result);
await linkWithCredential(existingUser, cred);Native iOS Considerations
In a native iOS app you generate a nonce and pass Apple's identity token plus that nonce to Firebase. The nonce protects against replay attacks and is required by Firebase for native Apple credentials.
Handling Cancellation
Users can dismiss the Apple sheet. This surfaces as an error you should treat as a silent no-op, not a failure to display loudly.
try {
await signInWithPopup(getAuth(), provider);
} catch (e) {
if (e.code === 'auth/popup-closed-by-user') return;
showError('Sign-in failed, please try again.');
}Testing and Review
Apple reviewers actively check that Sign in with Apple is offered when other social logins exist. Test the full flow, including the hide-email path, before submitting your app for review.
Quick Check
Test your understanding of Apple Sign-In.
Recap
You can now add Apple Sign-In correctly.
- Required when other social logins are offered on iOS
- Configure the provider with Service/Team/Key IDs
- Capture the name on first sign-in only
- Support the private email relay
- Use nonces natively and link duplicate accounts
Frequently asked questions
Is the “Apple Sign-In Integration” lesson free?
Yes — the full text of “Apple Sign-In Integration” is free to read here on the web, and the Firebase Auth & Realtime Database Apps course includes 4 lessons in total. To practise it interactively (a built-in code editor and a 24/7 AI tutor) and unlock the rest of the Firebase Auth & Realtime Database Apps course, upgrade to CoddyKit PRO.
What will I learn in “Apple Sign-In Integration”?
Add Sign in with Apple to your Firebase app, satisfy Apple's App Store requirement for social logins, and handle Apple's privacy-focused email relay correctly. You practise Firebase Auth & Realtime Database Apps with hands-on code you run directly in the browser, and a 24/7 AI tutor answers your questions as you work through the lesson.
Do I need any experience to start Firebase Auth & Realtime Database Apps?
No prior experience is required. Firebase Auth & Realtime Database Apps on CoddyKit is structured for beginners through advanced learners; this is — lesson 4 of 4, so you can start here or from the beginning and move at your own pace.
How long does the “Apple Sign-In Integration” lesson take?
Most CoddyKit lessons take about 5–10 minutes. Each one is bite-sized and interactive, so you make steady progress and pick up exactly where you left off across the web and the app.
Can I write and run code in this Firebase Auth & Realtime Database Apps lesson?
Yes. Every Firebase Auth & Realtime Database Apps lesson includes a built-in code editor, so you write and run real code right in your browser and get instant AI feedback — no local setup required.
All lessons in this course
- Google Sign-In Integration
- Facebook & GitHub Authentication
- Anonymous & Custom Auth
- Apple Sign-In Integration