Single sign-on
Social login in, OIDC provider out.
Sign in with Google, GitHub, or Microsoft — or let your other apps sign in with Oidot. Same platform, both directions.
Identity provider and identity consumer, at once
Most platforms only need to consume identity: Oidot supports Google, GitHub, and Microsoft as OAuth providers, with full PKCE, state, and nonce handling so a social login can't be replayed or intercepted.
Some platforms also need to provide identity — Oidot can act as the OIDC provider for a customer's other applications, running the standard authorization-code and consent flow so those apps can say "log in with Oidot" the same way yours can say "log in with Google."
Features
Google, GitHub, and Microsoft login
Full PKCE, state, and nonce handling on every social login flow.
Oidot as an OIDC provider
Authorization-code and consent flow, so other applications can authenticate against Oidot.
One identity, many apps
A signed-in user carries one identity across every application that trusts Oidot.
No secrets in the browser
Authorization codes are exchanged server-side — access tokens are never exposed to a redirect URL.
Bring SSO to your platform
Talk to us about wiring Oidot in as your identity provider.