Docs menu: Overview

Demo-ready OAuth sign-in for Gleam

Real OAuth sign-in for your Gleam demo, in minutes.

Vestibule gives demos and prototypes a real provider round-trip: a consistent request and callback flow with normalized auth results, PKCE, CSRF state, provider strategies, and Wisp or Mist middleware. It has not been security audited — keep it out of production. Your app remains responsible for its user accounts and sessions.

See how the callback flow works

Identity provider

  1. RequestURL, state, PKCE verifier
  2. StoreBind transient callback data
  3. CallbackValidate and normalize user info

Signed-in session in your app

Start here

Build the dependency block for your app.

Choose your server and identity provider. Vestibule prepares the Git dependencies and links to the applicable implementation path.

Keep the callback boundary explicit.

Vestibule validates provider callbacks. Your app stores callback data and manages user sessions.

Vestibule handles

  • Strong state values and PKCE
  • Callback state validation
  • Normalized provider identities

Your app handles

  • Short-lived callback storage
  • Account and session mapping
  • Safe failure and retry UX
Review your app's responsibilities

Ready to wire sign-in into your demo?

Follow the request and callback path. Then connect the normalized auth result to your application's session.

Open the quick start