Skip to main content

External identity providers

Klubero SSO supports authentication through external identity providers, letting users sign in with their existing accounts.

Supported providers​

ProviderDescription
GoogleSign in with a Google account
FacebookSign in with a Facebook account
Seznam.czSign in with a Seznam.cz account (Czech provider)

How external sign-in works​

┌──────────┐         ┌──────────┐         ┌──────────┐         ┌──────────┐
│ User │ │ Your App │ │ Klubero │ │ External │
│ │ │ │ │ SSO │ │ Provider │
└────┬─────┘ └────┬─────┘ └────┬─────┘ └────┬─────┘
│ │ │ │
│ 1. Clicks │ │ │
│ "Sign in │ │ │
│ with Google" │ │ │
│ ──────────────────►│ │ │
│ │ │ │
│ │ 2. Redirect to │ │
│ │ /authorize │ │
│ │ ──────────────────►│ │
│ │ │ │
│ 3. Redirect to Google │ │
│ ◄───────────────────────────────────────│ │
│ │ │ │
│ 4. Sign in at Google │ │
│ ────────────────────────────────────────────────────────────►│
│ │ │ │
│ 5. Redirect back with provider token │ │
│ ◄────────────────────────────────────────────────────────────│
│ │ │ │
│ 6. Provider callback │ │
│ ────────────────────────────────────────► │
│ │ │ │
│ 7. Continue OAuth flow │ │
│ ◄───────────────────────────────────────│ │

User scenarios​

Scenario 1: New user (registration)​

When a user signs in through an external provider for the first time:

  1. The user's identity is verified with the provider
  2. The user is prompted to complete registration (if additional information is needed)
  3. A new account is created and linked to the external provider
  4. The OAuth flow continues normally

Scenario 2: Existing user (linked account)​

When a user has a previously linked external account:

  1. The user's identity is verified with the provider
  2. The user is signed in immediately
  3. The OAuth flow continues normally

Scenario 3: Email already exists​

When the email from the provider matches an existing account (not linked):

  1. The user is informed that the email is already registered
  2. The user must first sign in with their existing credentials
  3. They can then link the external provider in their account settings

Linking external accounts​

Users can link multiple external providers to their account for greater flexibility.

Important limitation

A user cannot unlink an external provider if:

  • They have no password set, AND
  • It is their only sign-in method

Data received from providers​

ProviderData fields
GoogleUser ID, email, first name, last name
FacebookUser ID, email, name
Seznam.czUser ID, email, first name, last name

Implementation notes​

External sign-in is initiated through the Klubero SSO sign-in page. Your application redirects to the standard authorization endpoint, and users can choose their preferred sign-in method (including external providers) on the SSO sign-in page.

The external provider selection happens within Klubero SSO – your application does not need to implement any provider-specific logic.