Prepare social sign-in for app review
Understand Apple’s login-service rule, configure the right app identity and test Google or Apple sign-in in a native build.
A sign-in button needs a complete account journey behind it. Decide how people create an account, return to the app, recover access and delete it before submitting.
Apple publishing access and Sign in with Apple serve different purposes. Connecting an App Store Connect API key to RNBlocks does not add Apple login to your app.
On this page
Does Google login mean I need Sign in with Apple?
Apple’s rule 4.8 applies when third-party/social login creates or authenticates the app’s primary user account. It requires an equivalent login option that limits collection to name/email, lets people hide their email and does not use app interactions for advertising without consent. Sign in with Apple is a common way to provide that option.
Exceptions include an exclusively own-account system; qualifying education/enterprise accounts; government or industry-backed identity; a client accessing a specific third-party service; and qualifying alternative-marketplace login. Check the exact rule against your app. Email/password alone does not automatically trigger it.
Prepare the app identity and provider setup
Describe the intended account journey
In the app’s Studio conversation, name the login methods, target platforms and where account data is stored. Ask the agent to inspect the existing implementation before adding another login system.
Configure the actual native app
For native Apple sign-in, enable Sign in with Apple on the app’s Apple App ID. The Expo project also needs the matching native capability/configuration before building. A visual button alone cannot supply this.
Match provider callbacks
For browser-based OAuth, confirm the provider client configuration, app scheme and permitted return URL for the build being tested. Use the project’s actual values; an Expo project ID, bundle ID and web client ID are different identifiers.
Keep server credentials on the server
Have the implementation exchange and verify credentials through the appropriate trusted backend. Do not paste a provider client secret or private signing key into app source or the conversation.
If Apple sign-in uses a web return URL
Apple’s web flow uses a Services ID associated with a primary App ID enabled for Sign in with Apple. In Certificates, Identifiers & Profiles → Identifiers, register the Services ID, enable Sign in with Apple and choose Configure. Select the primary app and enter the required domains and return URLs, then review and Save.
Use this path only when your authentication architecture needs it. It is separate from the App Store Connect Team API key used for publishing.
Use the correct test environment
New account, returning account and a cancelled sign-in.
The browser returns to the intended app and screen.
Hidden-email accounts work without forcing a public email address.
Signing out and reopening the app behave correctly.
An existing account is not silently replaced with an empty duplicate.
Account deletion removes the intended data and revokes Apple access when used.
| Flow | Test it with |
|---|---|
OAuth/OpenID through Expo AuthSession | A development build with the app’s custom scheme. Expo Go cannot test that redirect setup. |
Native expo-apple-authentication on iOS | Expo Go supports limited testing, but identifiers can differ and simulator behavior is incomplete. Validate the configured build on a real iPhone. |
Android or web Apple sign-in | The iOS native Apple library does not implement these platforms. Check the separate supported authentication path in your app. |
Before you ask for review
Return to Publish with the tested build and a short account-access explanation. Point out which login paths work, how a reviewer reaches the main features, and where privacy and deletion controls are found.
Keep the provider configuration and backend available during review. If a login fails only in the installed build, investigate its app identity and return configuration rather than repeatedly resubmitting the same build.