Docs menu: Apple strategy
Provider strategy

vestibule_apple

Sign in with Apple strategy that verifies ID tokens with JWKS and supports form_post callbacks.

When to use it

Use Apple if your web application needs Sign in with Apple and can generate a client-secret JWT.

Default scopes: name email

Install

Vestibule packages are not available on Hex. Add them from GitHub with the moving v0 tag. Use Gleam 1.18 or later because companion packages use Git path dependencies.

[dependencies]
vestibule_apple = { git = "https://github.com/tylerbutler/vestibule.git", ref = "v0", path = "packages/vestibule_apple" }

Setup

  1. Create an Apple App ID and enable Sign In with Apple.
  2. Create a Services ID for the OAuth client_id.
  3. Register an HTTPS return URL. Apple does not permit localhost callbacks.
  4. Create a Sign in with Apple key and generate an ES256 client-secret JWT.

Usage

import vestibule_apple
let assert Ok(apple) = vestibule_apple.initialize()
let strategy = vestibule_apple.strategy(apple)

What Vestibule handles

  • init initializes the JWKS cache used to verify Apple ID tokens.
  • Use initialize to handle duplicate initialization explicitly.
  • Apple sends name and email only on first consent.
  • User info comes from the verified id_token, not a userinfo endpoint.

What you handle

  • Generate the client_secret JWT from the Team ID, Key ID, Services ID, and .p8 private key.
  • Do not commit the Apple private key. Generate the client-secret JWT in your app or deployment pipeline.