Last updated
Last updated
OAuth plugins allow you log users in using a third-party platform such as Google, Facebook, LinkedIn, X (formerly Twitter), Instagram and others.
This article series covers how to set up the official plugins developed by Bubble or the third party offering the external service.
This article series covers the Bubble-made/provider-made OAuth plugins. There may be other plugins available in the plugin stores the offer different features on the same OAuth providers, or additional OAuth providers. For documentation and the latest updates on these plugins, please reach out to the plugin creators.
Throughout this article, we will refer to you as the Bubble developer as the user, and the users of your app as end-users.
Imagine you're at a party and someone you trust (like a friend) vouches for someone new, saying they're cool. You're more likely to trust this new person because your friend says they're okay. That's kind of like what OAuth does, but in the digital world.
OAuth stands for "Open Authorization", and is a standard for delegating access to apps and systems. In simpler terms, it lets an end-user give an app permission to access their information on another app without giving away the password to that app.
In this context, it means that the user can use that third-party platform to sign up and log in to your Bubble app. It sometimes means that your app can fetch information about that end-user, such as their email, name, social media posts and profile picture too, removing the need for a manual form. In some cases, the user can choose what information to reveal.
Requesting Permission: When an end-user uses your app, and needs to access information from another service (like Google, Facebook, etc.), the web app will redirect the end-user to a form hosted by that app/system, and ask for permission. This is like asking, "Hey, can I check your info on Google?"
Approval and Tokens: If the end-user says "Yes," Google (in this case) gives your app a special code, called an access . Think of this token like a temporary VIP pass; it lets the web app access only what the end-user agreed to share and nothing more.
Access and Security: The web app uses this token to get the information it needs. Your app never knows the end-user's password for Google, giving the user a secure way to sign up/log in.
Security: It keeps passwords safe. The end-users password with the OAuth provider is never revealed to your Bubble app.
Control: End-users can control what information they share and can revoke access at any time.
Convenience: It's easier for end-users. They don’t need to create new accounts for every web app they use.
Most of your end-users are not aware of what OAuth is and how it works, and in most cases, they don't have it, as long as it provides an easy-to-use and secure way to sign up and log in.
Here's how the process typically unfolds:
Choosing to connect: The end-user arrives at your app and sees an option to log in or sign up using services like Google or Facebook.
Clicking to proceed: They select this option, often presented as a button labeled "Sign in with Google" or similar.
Reviewing permissions: A pop-up window appears, asking the end-user to confirm if they are comfortable sharing certain information with your app, such as their email address.
Consenting to share: If the end-user agrees, they click "Allow" or a similar confirmation button.
Access granted: Your app now accesses the necessary information, and the end-user is directed to their account, ready to use your app's features.
Managing access: The end-user can always manage what information they've shared with various apps, including yours, through their account settings on the service they used to log in.
The end-user's full name and/or nickname
Profile picture
Social media posts
Some plugins also add new elements to the Bubble editor. For example, the Facebook plugin offers an element to show a number of likes for a given Facebook page.
We have individual articles on each of the official OAuth plugins created by Bubble or the third-party provider:
Note that this is not an extensive list of all Bubble-made plugins, but only the ones that offer authentication.
Throughout this article series, we often point to external documentation. This approach is taken to guarantee that the information provided is both current and accurate. For instance, the method for generating and retrieving an API token or key can vary based on the specific service you're linking to. In these cases, the documentation from the respective third-party service is the definitive and up-to-date source for such procedures.
Please note that Bubble is not responsible for the content found in these third-party links.
Yes, OAuth is considered highly secure, equal to using a username and password. All communication with the third-party is encrypted and routed through Bubble's server.
Yes, you can offer as many as you like, but the end-user's selected choice is permanent. If the end-user wants to connect to a different provider after signing up, they will need to create a new account.
Users in Bubble can use traditional logins and social logins at the same time. There are a few cases here:
Signing up when logged in: When a user already logged in with their email and password chooses to link their account with an OAuth provider, their existing account gets updated with the new authentication credentials. This means no new user account is created. After completing this linking process, the user has the flexibility to log in either with their email and password or through the OAuth flow.
Email already exists: However, if a user tries to sign up by linking an account with OAuth and another user in the database already has the same email as the one provided by the external service, the process won't succeed. Instead, the user will receive a notification about the issue.
Signing up without being logged in (existing account): On the other hand, if a user isn't logged in and goes through the OAuth flow, the system will create a new user account. But, if there's an existing user in the app's database with the same email as the one registered with the external service (like Facebook), this action will also fail, and the user will be informed.
Adding password to existing OAuth account: For users who initially signed up using an external service and want to add a password to their account, they can do so by initiating a 'reset the user's password' action. This step adds email and password credentials to their account, which previously only used OAuth for authentication.
Signing up/logging in using a third-party OAuth app can add new to your app, relevant to the app the end-user is using to authenticate. For example, the Slack plugin allows you to post bot messages in a given Slack channel.
Some OAuth providers provide new that can provide basic or extensive data about the end-user on that platform, such as:
Article series: