You must configure your application instance through the Clerk Dashboard for the social connection(s) that you want to use. Visit the appropriate guide for your platform to learn how to configure your instance.
Examples for this SDK aren't available yet. For now, try adapting the available example to fit your SDK.
First, in your .env file, set the CLERK_SIGN_IN_URL environment variable to tell Clerk where the sign-in page is being hosted. Otherwise, your app may default to using the Account Portal sign-in page instead. This guide uses the /sign-in route.
.env
NEXT_PUBLIC_CLERK_SIGN_IN_URL=/sign-in
The following example will both sign up and sign in users, eliminating the need for a separate sign-up page. However, if you want to have separate sign-up and sign-in pages, the sign-up and sign-in flows are equivalent, meaning that all you have to do is swap out the SignIn object for the SignUp object using the useSignUp() hook.
Starts the authentication process by calling SignIn.sso(params). This method requires the following params:
redirectUrl: The URL that the browser will be redirected to once the user authenticates with the identity provider if no additional requirements are needed, and a session has been created.
redirectCallbackUrl: The URL that the browser will be redirected to once the user authenticates with the identity provider if additional requirements are needed.
Creates a route at the URL that the redirectCallbackUrl param points to.
Sign in page
SSO callback page
app/sign-in/page.tsx
'use client'import { OAuthStrategy } from'@clerk/shared/types'import { useSignIn } from'@clerk/nextjs'exportdefaultfunctionPage() {const { signIn,errors } =useSignIn()constsignInWith=async (strategy:OAuthStrategy) => {const { error } =awaitsignIn.sso({ strategy, redirectCallbackUrl:'/sso-callback', redirectUrl:'/sign-in/tasks',// Learn more about session tasks at https://clerk.com/docs/guides/development/custom-flows/overview#session-tasks })if (error) {// See https://clerk.com/docs/guides/development/custom-flows/error-handling// for more info on error handlingconsole.error(JSON.stringify(error,null,2))return }if (signIn.status ==='needs_second_factor') {// See https://clerk.com/docs/guides/development/custom-flows/authentication/multi-factor-authentication } elseif (signIn.status ==='needs_client_trust') {// See https://clerk.com/docs/guides/development/custom-flows/authentication/client-trust } else {// Check why the sign-in is not completeconsole.error('Sign-in attempt not complete:', signIn) } }// Render a button for each supported OAuth provider// you want to add to your app. This example uses only Google.return ( <> <buttononClick={() =>signInWith('oauth_google')}>Sign in with Google</button> {/* For your debugging purposes. You can just console.log errors, but we put them in the UI for convenience */} {errors && <p>{JSON.stringify(errors,null,2)}</p>} </> )}
app/sso-callback/page.tsx
'use client'import { useClerk, useSignIn, useSignUp } from'@clerk/nextjs'import { useRouter } from'next/navigation'import { useEffect, useRef } from'react'exportdefaultfunctionPage() {constclerk=useClerk()const { signIn } =useSignIn()const { signUp } =useSignUp()constrouter=useRouter()consthasRun=useRef(false)constnavigateToSignIn= () => {router.push('/sign-in') }constnavigateToSignUp= () => {router.push('/sign-up') }useEffect(() => { ;(async () => {if (!clerk.loaded ||hasRun.current) {return }// Prevent Next.js from re-running this effect when the page is re-rendered during session activation.hasRun.current =true// If this was a sign-in, and it's complete, there's nothing else to do.if (signIn.status ==='complete') {awaitsignIn.finalize({navigate:async ({ session, decorateUrl }) => {if (session?.currentTask) {// Handle pending session tasks// See https://clerk.com/docs/guides/development/custom-flows/authentication/session-tasksconsole.log(session?.currentTask)return }consturl=decorateUrl('/')if (url.startsWith('http')) {window.location.href = url } else {router.push(url) } }, })return }// If the sign-up used an existing account, transfer it to a sign-in.if (signUp.isTransferable) {awaitsignIn.create({ transfer:true })constsignInStatus=signIn.status astypeofsignIn.status |'complete'if (signInStatus ==='complete') {awaitsignIn.finalize({navigate:async ({ session, decorateUrl }) => {if (session?.currentTask) {// Handle pending session tasks// See https://clerk.com/docs/guides/development/custom-flows/authentication/session-tasksconsole.log(session?.currentTask)return }consturl=decorateUrl('/')if (url.startsWith('http')) {window.location.href = url } else {router.push(url) } }, })return }// The sign-in requires additional verification, so we need to navigate to the sign-in page.returnnavigateToSignIn() }if (signIn.status ==='needs_first_factor'&&!signIn.supportedFirstFactors?.every((f) =>f.strategy ==='enterprise_sso') ) {// The sign-in requires the use of a configured first factor, so navigate to the sign-in page.returnnavigateToSignIn() }// If the sign-in used an external account not associated with an existing user, create a sign-up.if (signIn.isTransferable) {awaitsignUp.create({ transfer:true })if (signUp.status ==='complete') {awaitsignUp.finalize({navigate:async ({ session, decorateUrl }) => {if (session?.currentTask) {// Handle pending session tasks// See https://clerk.com/docs/guides/development/custom-flows/authentication/session-tasksconsole.log(session?.currentTask)return }consturl=decorateUrl('/')if (url.startsWith('http')) {window.location.href = url } else {router.push(url) } }, })return }returnnavigateToSignUp() }if (signUp.status ==='complete') {awaitsignUp.finalize({navigate:async ({ session, decorateUrl }) => {if (session?.currentTask) {// Handle pending session tasks// See https://clerk.com/docs/guides/development/custom-flows/authentication/session-tasksconsole.log(session?.currentTask)return }consturl=decorateUrl('/')if (url.startsWith('http')) {window.location.href = url } else {router.push(url) } }, })return }if (signIn.status ==='needs_second_factor'||signIn.status ==='needs_new_password') {// The sign-in requires a MFA token or a new password, so navigate to the sign-in page.returnnavigateToSignIn() }// The external account used to sign-in or sign-up was already associated with an existing user and active// session on this client, so activate the session and navigate to the application.if (signIn.existingSession ||signUp.existingSession) {constsessionId=signIn.existingSession?.sessionId ||signUp.existingSession?.sessionIdif (sessionId) {// Because we're activating a session that's not the result of a sign-in or sign-up, we need to use the// Clerk `setActive` API instead of the `finalize` API.awaitclerk.setActive({ session: sessionId,navigate:async ({ session, decorateUrl }) => {if (session?.currentTask) {// Handle pending session tasks// See https://clerk.com/docs/guides/development/custom-flows/authentication/session-tasksconsole.log(session?.currentTask)return }consturl=decorateUrl('/')if (url.startsWith('http')) {window.location.href = url } else {router.push(url) } }, })return } } })() }, [clerk, signIn, signUp])return ( <div> {/* Because a sign-in transferred to a sign-up might require captcha verification, make sure to render the captcha element. */} <divid="clerk-captcha"></div> </div> )}
The following example will both sign up and sign in users, eliminating the need for a separate sign-up page.
The following example:
Uses the useSSO()Expo Icon hook to access the startSSOFlow() method.
Calls the startSSOFlow() method with the strategy param set to oauth_google, but you can use any of the supported OAuth strategies. The optional redirect_url param is also set in order to redirect the user once they finish the authentication flow.
If authentication is successful, the setActive() method is called to set the active session with the new createdSessionId.
If authentication is not successful, you can handle the missing requirements, such as MFA, using the signIn or signUp object returned from startSSOFlow(), depending on if the user is signing in or signing up. These objects include properties, like status, that can be used to determine the next steps. See the respective linked references for more information.
app/(auth)/sign-in.tsx
import React, { useCallback, useEffect } from'react'import*as WebBrowser from'expo-web-browser'import*as AuthSession from'expo-auth-session'import { useSSO } from'@clerk/expo'import { useRouter } from'expo-router'import { View, Button, Platform } from'react-native'// Preloads the browser for Android devices to reduce authentication load time// See: https://docs.expo.dev/guides/authentication/#improving-user-experienceexportconstuseWarmUpBrowser= () => {useEffect(() => {if (Platform.OS!=='android') returnvoidWebBrowser.warmUpAsync()return () => {// Cleanup: closes browser when component unmountsvoidWebBrowser.coolDownAsync() } }, [])}// Handle any pending authentication sessionsWebBrowser.maybeCompleteAuthSession()exportdefaultfunctionPage() {useWarmUpBrowser()// Use the `useSSO()` hook to access the `startSSOFlow()` methodconst { startSSOFlow } =useSSO()constrouter=useRouter()constonPress=useCallback(async () => {try {// Start the authentication process by calling `startSSOFlow()`const { createdSessionId,setActive,signIn,signUp } =awaitstartSSOFlow({ strategy:'oauth_google',// For web, defaults to current path// For native, you must pass a scheme, like AuthSession.makeRedirectUri({ scheme, path })// For more info, see https://docs.expo.dev/versions/latest/sdk/auth-session/#authsessionmakeredirecturioptions redirectUrl:AuthSession.makeRedirectUri(), })// If sign in was successful, set the active sessionif (createdSessionId) {setActive!({ session: createdSessionId,// Handle session tasks// See https://clerk.com/docs/guides/development/custom-flows/authentication/session-tasksnavigate:async ({ session, decorateUrl }) => {if (session?.currentTask) {console.log(session?.currentTask)return }router.push(decorateUrl('/')) }, }) } else {// If there is no `createdSessionId`,// there are missing requirements, such as MFA// See https://clerk.com/docs/guides/development/custom-flows/authentication/oauth-connections#handle-missing-requirements } } catch (err) {// See https://clerk.com/docs/guides/development/custom-flows/error-handling// for more info on error handlingconsole.error(JSON.stringify(err,null,2)) } }, [])return ( <View> <Buttontitle="Sign in with Google"onPress={onPress} /> </View> )}
Sign in using an OAuth provider (e.g., Google, GitHub, see all providers):
OAuthView.swift
importSwiftUIimportClerkKitstructOAuthView:View {@Environment(Clerk.self)privatevar clerkvar body: some View {// Render a button for each supported OAuth provider// you want to add to your app. This example uses Google.Button("Sign In with Google") {Task { awaitsignInWithOAuth(provider: .google) } } } }extensionOAuthView {funcsignInWithOAuth(provider: OAuthProvider) async {do {// Start the sign-in process using the selected OAuth provider.let result =tryawait clerk.auth.signInWithOAuth(provider: provider)// It is common for users who are authenticating with OAuth to use// a sign-in button when they mean to sign-up, and vice versa.// Clerk will handle this transfer for you if possible.// Therefore, a TransferFlowResult can be either a SignIn or SignUp.switch result {case .signIn(let signIn):switch signIn.status {case .complete:// If sign-in process is complete, navigate the user as needed.dump(clerk.session)default:// If the status is not complete, check why. User may need to// complete further steps.dump(signIn.status) }case .signUp(let signUp):switch signUp.status {case .complete:// If sign-up process is complete, navigate the user as needed.dump(clerk.session)default:// If the status is not complete, check why. User may need to// complete further steps.dump(signUp.status) } } } catch {// See https://clerk.com/docs/guides/development/custom-flows/error-handling// for more info on error handling.dump(error) } } }
OAuthViewModel.kt
OAuthActivity.kt
OAuthViewModel.kt
package com.clerk.customflows.oauthimport android.util.Logimport androidx.lifecycle.ViewModelimport androidx.lifecycle.viewModelScopeimport com.clerk.api.Clerkimport com.clerk.api.log.ClerkLogimport com.clerk.api.network.serialization.errorMessageimport com.clerk.api.network.serialization.onFailureimport com.clerk.api.network.serialization.onSuccessimport com.clerk.api.signin.SignInimport com.clerk.api.signup.SignUpimport com.clerk.api.sso.OAuthProviderimport com.clerk.api.sso.ResultTypeimport kotlinx.coroutines.flow.MutableStateFlowimport kotlinx.coroutines.flow.asStateFlowimport kotlinx.coroutines.flow.combineimport kotlinx.coroutines.flow.launchInimport kotlinx.coroutines.launchclassOAuthViewModel : ViewModel() {privateval _uiState =MutableStateFlow<UiState>(UiState.Loading)val uiState = _uiState.asStateFlow()init {combine(Clerk.isInitialized, Clerk.userFlow) { isInitialized, user -> _uiState.value=when {!isInitialized -> UiState.Loading user !=null-> UiState.Authenticatedelse-> UiState.SignedOut } } .launchIn(viewModelScope)}funsignInWithOAuth(provider: OAuthProvider) { viewModelScope.launch { Clerk.auth .signInWithOAuth(provider) .onSuccess {when (it.resultType) { ResultType.SIGN_IN -> {// The OAuth flow resulted in a sign inif (it.signIn?.status == SignIn.Status.COMPLETE) { _uiState.value= UiState.Authenticated } else {// If the status is not complete, check why. User may need to// complete further steps. } } ResultType.SIGN_UP -> {// The OAuth flow resulted in a sign upif (it.signUp?.status == SignUp.Status.COMPLETE) { _uiState.value= UiState.Authenticated } else {// If the status is not complete, check why. User may need to// complete further steps. } } ResultType.UNKNOWN -> { ClerkLog.e("Unknown result type after OAuth redirect") } } } .onFailure {// See https://clerk.com/docs/guides/development/custom-flows/error-handling// for more info on error handling Log.e("OAuthViewModel", it.errorMessage, it.throwable) } }}sealedinterfaceUiState {dataobjectLoading : UiStatedataobjectSignedOut : UiStatedataobjectAuthenticated : UiState}}
Depending on your instance settings, users might need to provide extra information before their sign-up can be completed, such as when a username or accepting legal terms is required. In these cases, the SignUp object returns a status of "missing_requirements" along with a missingFields array. You can create a "Continue" page to collect these missing fields and complete the sign-up flow. Handling the missing requirements will depend on your instance settings. For example, if your instance settings require a phone number, you will need to handle verifying the phone number.
Quiz
Why does the "Continue" page use the useSignUp() hook? What if a user is using this flow to sign in?
With OAuth flows, it's common for users to try to sign in with an OAuth provider, but they don't have a Clerk account for your app yet. Clerk automatically transfers the flow from the SignIn object to the SignUp object, which returns the "missing_requirements" status and missingFields array needed to handle the missing requirements flow. This is why for the OAuth flow, the "Continue" page uses the useSignUp() hook and treats the missing requirements flow as a sign-up flow.
Tip
Examples for this SDK aren't available yet. For now, try adapting the available example to fit your SDK.
app/sign-in/continue/page.tsx
'use client'import { useState } from'react'import { useSignUp } from'@clerk/nextjs'import { useRouter } from'next/navigation'functionsnakeToCamel(str:string|undefined):string {return str ?str.replace(/([-_][a-z])/g, (match) =>match.toUpperCase().replace(/-|_/,'')) :''}exportdefaultfunctionPage() {constrouter=useRouter()// Use `useSignUp()` hook to access the `SignUp` object// `missing_requirements` and `missingFields` are only available on the `SignUp` objectconst { signUp } =useSignUp()consthandleSubmit=async (formData:FormData) => {constparams=Object.fromEntries(formData.entries()) asany// Update the `SignUp` object with the missing fields// The logic that goes here will depend on your instance settings// E.g. if your app requires a phone number, you will need to collect and verify it hereawaitsignUp.update(params)if (signUp.status ==='complete') {awaitsignUp.finalize({navigate:async ({ session, decorateUrl }) => {if (session?.currentTask) {// Handle session tasks// See https://clerk.com/docs/guides/development/custom-flows/authentication/session-tasksconsole.log(session?.currentTask)return }consturl=decorateUrl('/')if (url.startsWith('http')) {window.location.href = url } else {router.push(url) } }, }) } }if (signUp.status ==='missing_requirements') {// For simplicity, all missing fields in this example are text inputs.// In a real app, you might want to handle them differently:// - legal_accepted: checkbox// - username: text with validation// - phone_number: phone input, etc.return ( <div> <h1>Continue sign-up</h1> <formaction={handleSubmit}> {signUp.missingFields.map((field) => ( <divkey={field}> <label> {field}: <inputtype="text"name={snakeToCamel(field)} /> </label> </div> ))} {/* Required for sign-up flows Clerk's bot sign-up protection is enabled by default */} <divid="clerk-captcha" /> <buttontype="submit">Submit</button> </form> </div> ) }// Handle other statuses if neededreturn ( <> {/* Required for sign-up flows Clerk's bot sign-up protection is enabled by default */} <divid="clerk-captcha" /> </> )}