# Prepare social sign-in for app review

> Understand Apple’s login-service rule, configure the right app identity and test Google or Apple sign-in in a native build.

Canonical: https://www.rnblocks.dev/docs/publishing/social-sign-in
Updated: 2026-10-01

A sign-in button needs a complete account journey behind it. Decide how people create an account, return to the app, recover access and delete it before submitting.

Apple publishing access and Sign in with Apple serve different purposes. Connecting an App Store Connect API key to RNBlocks does not add Apple login to your app.

## Does Google login mean I need Sign in with Apple?

Section: https://www.rnblocks.dev/docs/publishing/social-sign-in#apple-rule

Apple’s rule 4.8 applies when third-party/social login creates or authenticates the app’s primary user account. It requires an equivalent login option that limits collection to name/email, lets people hide their email and does not use app interactions for advertising without consent. Sign in with Apple is a common way to provide that option.

Exceptions include an exclusively own-account system; qualifying education/enterprise accounts; government or industry-backed identity; a client accessing a specific third-party service; and qualifying alternative-marketplace login. Check the exact rule against your app. Email/password alone does not automatically trigger it.

> **Review the actual login purpose**
> Ask: ‘Does this provider identify the person using my app, or connect an existing service they came here to use?’ Describe that distinction to the publishing agent, including any exception you believe applies.

- [Apple review rule 4.8: Login Services](https://developer.apple.com/app-store/review/guidelines/#login-services)

## Prepare the app identity and provider setup

Section: https://www.rnblocks.dev/docs/publishing/social-sign-in#configure

1. **Describe the intended account journey** — In the app’s Studio conversation, name the login methods, target platforms and where account data is stored. Ask the agent to inspect the existing implementation before adding another login system.

2. **Configure the actual native app** — For native Apple sign-in, enable Sign in with Apple on the app’s Apple App ID. The Expo project also needs the matching native capability/configuration before building. A visual button alone cannot supply this.

3. **Match provider callbacks** — For browser-based OAuth, confirm the provider client configuration, app scheme and permitted return URL for the build being tested. Use the project’s actual values; an Expo project ID, bundle ID and web client ID are different identifiers.

4. **Keep server credentials on the server** — Have the implementation exchange and verify credentials through the appropriate trusted backend. Do not paste a provider client secret or private signing key into app source or the conversation.

- [Configure Sign in with Apple](https://developer.apple.com/help/account/capabilities/about-sign-in-with-apple/)
- [Expo OAuth and OpenID testing](https://docs.expo.dev/guides/authentication/)
- [Expo native Apple authentication](https://docs.expo.dev/versions/latest/sdk/apple-authentication/)

## If Apple sign-in uses a web return URL

Section: https://www.rnblocks.dev/docs/publishing/social-sign-in#web-apple

Apple’s web flow uses a Services ID associated with a primary App ID enabled for Sign in with Apple. In Certificates, Identifiers & Profiles → Identifiers, register the Services ID, enable Sign in with Apple and choose Configure. Select the primary app and enter the required domains and return URLs, then review and Save.

Use this path only when your authentication architecture needs it. It is separate from the App Store Connect Team API key used for publishing.

- [Apple web authentication and return URLs](https://developer.apple.com/help/account/capabilities/configure-sign-in-with-apple-for-the-web/)

## Use the correct test environment

Section: https://www.rnblocks.dev/docs/publishing/social-sign-in#test

- New account, returning account and a cancelled sign-in.
- The browser returns to the intended app and screen.
- Hidden-email accounts work without forcing a public email address.
- Signing out and reopening the app behave correctly.
- An existing account is not silently replaced with an empty duplicate.
- Account deletion removes the intended data and revokes Apple access when used.

| Flow | Test it with |
| --- | --- |
| OAuth/OpenID through Expo AuthSession | A development build with the app’s custom scheme. Expo Go cannot test that redirect setup. |
| Native expo-apple-authentication on iOS | Expo Go supports limited testing, but identifiers can differ and simulator behavior is incomplete. Validate the configured build on a real iPhone. |
| Android or web Apple sign-in | The iOS native Apple library does not implement these platforms. Check the separate supported authentication path in your app. |

- [Expo OAuth and OpenID testing](https://docs.expo.dev/guides/authentication/)
- [Expo native Apple authentication](https://docs.expo.dev/versions/latest/sdk/apple-authentication/)
- [Apple account deletion](https://developer.apple.com/support/offering-account-deletion-in-your-app/)

## Before you ask for review

Section: https://www.rnblocks.dev/docs/publishing/social-sign-in#review

Return to Publish with the tested build and a short account-access explanation. Point out which login paths work, how a reviewer reaches the main features, and where privacy and deletion controls are found.

Keep the provider configuration and backend available during review. If a login fails only in the installed build, investigate its app identity and return configuration rather than repeatedly resubmitting the same build.

- [Privacy, support and review access](https://www.rnblocks.dev/docs/publishing/privacy-and-support)
- [Build and device testing](https://www.rnblocks.dev/docs/publishing/testing)

## Continue

- [Apple publishing access](https://www.rnblocks.dev/docs/publishing/accounts/apple)
- [Privacy and deletion](https://www.rnblocks.dev/docs/publishing/privacy-and-support)
- [Submit and review](https://www.rnblocks.dev/docs/publishing/submit-and-review)

## Official references

- [Apple App Review Guidelines](https://developer.apple.com/app-store/review/guidelines/)
- [Configure Sign in with Apple](https://developer.apple.com/help/account/capabilities/about-sign-in-with-apple/)
- [Apple web authentication and return URLs](https://developer.apple.com/help/account/capabilities/configure-sign-in-with-apple-for-the-web/)
- [Expo OAuth and OpenID testing](https://docs.expo.dev/guides/authentication/)
- [Expo native Apple authentication](https://docs.expo.dev/versions/latest/sdk/apple-authentication/)
- [Apple account deletion](https://developer.apple.com/support/offering-account-deletion-in-your-app/)
