Stack53
IDENTITY

OAuth

Let users sign in with third-party providers, and issue OAuth clients so other apps can access your API — with scopes, redirects and tokens managed for you.

OAuth clients
acme / my-app / production
CLIENTTYPEREDIRECT
web-dashboard Confidentialapp.acme.com/callback
mobile-app Publicacme://callback
partner-api Confidentialapi.acme.com/oauth
Scopes · web-dashboard profile:read · orders:read · orders:write
WHAT IT DOES

OAuth without the plumbing.

Connect third-party login providers to your app, register OAuth applications and clients, define scopes and redirect URLs, and let Stack53 issue, refresh and revoke tokens.

Signs in your application's end users — not members of your Stack53 workspace.Separate clients and redirect URLs for each environment.Third-party providers: [Supported providers].Configure everything from the dashboard, API or CLI.
KEY CAPABILITIES

Everything OAuth, in one place.

Third-party login providers Let users sign in with [Supported providers].
OAuth applications Register apps that sign users in or call your API.
OAuth clients Public and confidential clients with their own credentials.
Scopes Define what each client is allowed to access.
Redirect URLs Allow-list redirect URLs per client and environment.
Token lifecycle Issue, refresh, expire and revoke access tokens.
Client secrets Generate and rotate secrets for confidential clients.
Integrations Works with Users, Roles & Permissions and your API.
OAuth API Manage clients, scopes and tokens from the API and SDKs.
HOW IT WORKS

Connect OAuth in four steps.

  1. 01 Register an application In a project environment, from the dashboard or CLI.
  2. 02 Create a client Choose a client type and set redirect URLs.
  3. 03 Define scopes Decide what each client can access.
  4. 04 Issue tokens Stack53 handles exchange, refresh and revocation.
COMMON USE CASES

What teams build with OAuth.

Social sign-in Offer sign-in with [Supported providers] alongside email and password.
Public API access Let partners and third-party apps call your API with scoped tokens.
First-party apps One sign-in across your web dashboard, mobile app and CLI.
DEVELOPER INTEGRATION

Built for code.

Register clients, set redirect URLs and scopes, and exchange codes for tokens from the REST API or the SDKs.

oauth.ts
const client = await stack53.oauth.clients.create({ name: 'web-dashboard', redirectUris: ['https://app.acme.com/callback'], scopes: ['profile:read', 'orders:read'], }) // Exchange an authorization code for tokens const tokens = await stack53.oauth.token({ code, client })
SECURITY Tokens you control. Redirects only go to allow-listed URLs.Scoped tokens that expire and can be revoked.Client secrets can be rotated or revoked at any time.Client and token changes recorded in audit logs. Security at Stack53 →
AVAILABILITY Where it runs.
REGIONOPERATED BYSTATUS
Canada Central[Partner / Stack53][Status]
Canada East[Partner / Stack53][Status]

Connect your first OAuth client.

Start building on Stack53, or talk to us about identity requirements and data residency.