Secure sign-in for every platform.
SingleSign is a free identity provider with OAuth 2.0 and OpenID Connect for developers and user-controlled privacy for consumers.
- Build sign‑in with OAuth 2.0 / OpenID Connect and modern security practices.
- Ask only for the data you need with scopes, and make consent clear.
- Give users real control: revoke access, manage devices, and enable MFA.
// 1. Generate PKCE challenge
const verifier = generateCodeVerifier();
const challenge = await sha256(verifier);
// 2. Redirect to SingleSign
window.location.href =
`https://api.singlesign.com/oauth/authorize?` +
`response_type=code&` +
`client_id=YOUR_CLIENT_ID&` +
`redirect_uri=${redirectUri}&` +
`scope=openid profile email&` +
`code_challenge=${challenge}&` +
`code_challenge_method=S256`;Integrate sign‑in without surprises.
Create an app, configure redirect URIs, and use Authorization Code with PKCE to protect the code exchange. SingleSign gives you predictable endpoints, clean errors, and practical docs.
Read the developer docs →Create an app
Register your application to receive a client ID and configure your integration settings.
Set redirect URIs
Define allowed callback URLs so authorization codes are only sent to destinations you control.
Ship sign‑in
Use Authorization Code with PKCE to exchange codes for tokens and authenticate users securely.
You stay in control.
SingleSign helps you understand what an app is requesting, approve only what you want to share, and remove access instantly.
Connected apps
See every app that can access your account in one place, with details about what data is shared.
Revoke access
Remove any app's access instantly. Tokens are invalidated and the app can no longer act on your behalf.
Account security
Enable multi‑factor authentication, review active sessions, and manage trusted devices.
Security is a product feature.
SingleSign is designed around modern sign‑in patterns like PKCE and redirect URI validation, with user consent and account security controls built in.
Frequently asked questions
Create your free account in minutes.
Start using SingleSign today, whether you're integrating sign‑in or securing your account across apps.
Start here
- SingleSign vs Google Sign-InSingleSign vs Google Sign-In: the same one-tap convenience, without an advertising business behind the identity.
- OAuth 2.0 & OpenID ConnectUnderstand the foundational protocols behind SingleSign: OAuth 2.0 for authorization and OpenID Connect for identity.
- Identity provider features, in fullThe identity provider features SingleSign ships: OAuth 2.0 and OpenID Connect endpoints, PKCE, scopes and consent, MFA, and instant revocation.
- the Scopes & Consent docsHow to request scopes, what data each scope grants, the consent UI, and the principle of least privilege.
- Firebase Auth comparisonSingleSign vs Firebase Authentication on lock-in, portability and consent, plus the cases where staying on Firebase is right.
- Auth0 comparisonSingleSign vs Auth0 compared on the difference that matters: who owns the account. A side-by-side table, then the three cases where each one is the right call.
- SSO for SaaS applicationsSSO for SaaS applications using OAuth 2.0 and OpenID Connect: the flow to pick, the scopes to request, and a working integration path with SingleSign.
- free identity providerSingleSign pricing in one line: sign-in is free, with no monthly-active-user meter. See exactly what is included, and what SingleSign Mail costs for businesses.