External identity providers
Klubero SSO supports authentication through external identity providers, letting users sign in with their existing accounts.
Supported providers
| Provider | Description |
|---|---|
| Sign in with a Google account | |
| Sign in with a Facebook account | |
| Seznam.cz | Sign in with a Seznam.cz account (Czech provider) |
How external sign-in works
┌──────────┐ ┌──────────┐ ┌──────────┐ ┌──────────┐
│ User │ │ Your App │ │ Klubero │ │ External │
│ │ │ │ │ SSO │ │ Provider │
└────┬─────┘ └────┬─────┘ └────┬─────┘ └────┬─────┘
│ │ │ │
│ 1. Clicks │ │ │
│ "Sign in │ │ │
│ with Google" │ │ │
│ ──────────────────►│ │ │
│ │ │ │
│ │ 2. Redirect to │ │
│ │ /authorize │ │
│ │ ──────────────────►│ │
│ │ │ │
│ 3. Redirect to Google │ │
│ ◄───────────────────────────────────────│ │
│ │ │ │
│ 4. Sign in at Google │ │
│ ────────────────────────────────────────────────────────────►│
│ │ │ │
│ 5. Redirect back with provider token │ │
│ ◄────────────────────────────────────────────────────────────│
│ │ │ │
│ 6. Provider callback │ │
│ ────────────────────────────────────────► │
│ │ │ │
│ 7. Continue OAuth flow │ │
│ ◄───────────────────────────────────────│ │
User scenarios
Scenario 1: New user (registration)
When a user signs in through an external provider for the first time:
- The user's identity is verified with the provider
- The user is prompted to complete registration (if additional information is needed)
- A new account is created and linked to the external provider
- The OAuth flow continues normally
Scenario 2: Existing user (linked account)
When a user has a previously linked external account:
- The user's identity is verified with the provider
- The user is signed in immediately
- The OAuth flow continues normally
Scenario 3: Email already exists
When the email from the provider matches an existing account (not linked):
- The user is informed that the email is already registered
- The user must first sign in with their existing credentials
- They can then link the external provider in their account settings
Linking external accounts
Users can link multiple external providers to their account for greater flexibility.
A user cannot unlink an external provider if:
- They have no password set, AND
- It is their only sign-in method
Data received from providers
| Provider | Data fields |
|---|---|
| User ID, email, first name, last name | |
| User ID, email, name | |
| Seznam.cz | User ID, email, first name, last name |
Implementation notes
External sign-in is initiated through the Klubero SSO sign-in page. Your application redirects to the standard authorization endpoint, and users can choose their preferred sign-in method (including external providers) on the SSO sign-in page.
The external provider selection happens within Klubero SSO – your application does not need to implement any provider-specific logic.