· 2 min read
One sign-in for many apps
How The Circular Net's products moved onto a single OAuth 2.0 sign-in service, and the rules that keep it safe.
At The Circular Net, every product used to have its own login. That works with one app. With a web app, a mobile app, an events product and a marketing site, it means four places to fix every auth bug, and people juggling several passwords for one company.
The shape
Sign-in moved to its own app on its own domain. Products no longer show a login form. They send people to the SSO service with their client ID and a redirect URL; the service signs them in and sends them back with a short-lived code, which the product exchanges for tokens.
Rules that matter
- Validate the client and the redirect URL against a registry, every time. A sign-in page that redirects anywhere is a phishing kit with your logo on it.
- Send a state value out and check it when the person comes back. It stops forged callbacks from signing someone in.
- Keep social providers behind the SSO. Products never talk to Google or Apple directly, so adding a provider is one change.
- Make the hand-off visible. A short “taking you back” page beats a blank redirect when something is slow.
Trade-offs
A separate service is one more thing to deploy and monitor, and every product depends on it. In exchange, auth fixes happen once, security reviews have one target, and a new product gets sign-in by registering a client instead of building a form.
If I did it again, I'd introduce SSO with the second product, not the fourth.
Related case study
Social App