Docs menu: GitHub strategy
Provider strategy

vestibule_github

GitHub OAuth strategy with normalized profile data and verified-primary-email lookup.

When to use it

Use GitHub if users sign in with GitHub accounts. The strategy returns profile data and the verified primary email address when available.

Default scopes: user:email

Install

Vestibule packages are not available on Hex. Add them from GitHub with the moving v0 tag. Use Gleam 1.18 or later because companion packages use Git path dependencies.

[dependencies]
vestibule_github = { git = "https://github.com/tylerbutler/vestibule.git", ref = "v0", path = "packages/vestibule_github" }

Setup

  1. Create a GitHub OAuth App.
  2. Set the exact authorization callback URL for each environment you demo from.
  3. Copy the Client ID and generate a client secret.
  4. Request user:email when you need private verified primary email lookup.

Usage

import vestibule/config
import vestibule_github
let strategy = vestibule_github.strategy()
let client_config =
config.new(
client_id: "github-client-id",
redirect_uri: "http://localhost:8000/auth/github/callback",
auth: config.ClientSecret("github-client-secret"),
)

What Vestibule handles

  • Requests user:email by default.
  • Token scopes are parsed from GitHub's comma-separated scope response.
  • user_info.email is populated from the verified primary email endpoint when available.
  • The GitHub profile URL is exposed under the html_url key in user_info.urls.

What you handle

  • GitHub can omit the public email address from /user. The strategy then tries the /user/emails endpoint.
  • Authentication can succeed if the email lookup fails. In this case, user_info.email returns None.