Docs menu: Overview
Demo-ready OAuth sign-in for Gleam
Real OAuth sign-in for your Gleam demo, in minutes.
Vestibule gives demos and prototypes a real provider round-trip: a consistent request and callback flow with normalized auth results, PKCE, CSRF state, provider strategies, and Wisp or Mist middleware. It has not been security audited — keep it out of production. Your app remains responsible for its user accounts and sessions.
See how the callback flow works
Identity provider
- RequestURL, state, PKCE verifier
- StoreBind transient callback data
- CallbackValidate and normalize user info
Signed-in session in your app
Start here
Build the dependency block for your app.
Choose your server and identity provider. Vestibule prepares the Git dependencies and links to the applicable implementation path.
Keep the callback boundary explicit.
Vestibule validates provider callbacks. Your app stores callback data and manages user sessions.
Vestibule handles
- Strong state values and PKCE
- Callback state validation
- Normalized provider identities
Your app handles
- Short-lived callback storage
- Account and session mapping
- Safe failure and retry UX
Ready to wire sign-in into your demo?
Follow the request and callback path. Then connect the normalized auth result to your application's session.