Skip to main content
theauth-go ships 12 built-in OAuth/OIDC providers. Each provider is a separate subpackage under provider/, so a consumer only pulls in the HTTP surface for the providers it actually wires.

Install a provider

All provider packages are included in the main module. No separate install is needed.

Wire a provider

Available providers

Each exposes a Config struct and a New(Config) theauth.Provider constructor. Each also ships its own runnable example under examples/oauth-<provider>/ (see Example Apps).

Multiple providers at once

See examples/oauth-multi-provider/ for a full runnable example.

Endpoints

When providers are configured, a.Mount(r) adds:
Where {name} is any registered provider’s Name(), e.g. github, google, microsoft, discord, apple, facebook, slack, gitlab, bitbucket, twitch, linkedin, or x.

Provider tokens

Provider access tokens are encrypted with AES-256-GCM before storage. The Config.EncryptionKey (32-byte) is required if you want provider token storage. Without it, the OAuth state is stored as-is and provider tokens are not persisted.

Custom provider

Implement the theauth.Provider interface:
Pass your implementation to Config.Providers alongside the built-in providers.
Last modified on October 7, 2026