Sign in with Apple OAuth 2.0 Client Provider for The PHP League OAuth2-Client

0.2.1 2020-02-13 02:43 UTC

This package is auto-updated.

Last update: 2020-05-13 03:22:07 UTC


Latest Version Software License Build Status Coverage Status Quality Score Total Downloads

This package provides Apple ID OAuth 2.0 support for the PHP League's OAuth 2.0 Client.

Before You Begin

Here you can find the official Apple documentation:

If you request email address or name please note that you'll get this only in your first login. When you log in a second time you will only get the user id - nothing more. Maybe Apple changes this sometime.


To install, use composer:

composer require patrickbussmann/oauth2-apple


Usage is the same as The League's OAuth client, using \League\OAuth2\Client\Provider\Apple as the provider.

Authorization Code Flow

$provider = new League\OAuth2\Client\Provider\Apple([
    'clientId'          => '{apple-client-id}',
    'teamId'            => '{apple-team-id}', // 1A234BFK46 (Team ID)
    'keyFileId'         => '{apple-key-file-id}', // 1ABC6523AA (Key ID)
    'keyFilePath'       => '{apple-key-file-path}', // __DIR__ . '/AuthKey_1ABC6523AA.p8' -> Download key above 
    'redirectUri'       => '',

if (!isset($_POST['code'])) {

    // If we don't have an authorization code then get one
    $authUrl = $provider->getAuthorizationUrl();
    $_SESSION['oauth2state'] = $provider->getState();
    header('Location: '.$authUrl);

// Check given state against previously stored one to mitigate CSRF attack
} elseif (empty($_POST['state']) || ($_POST['state'] !== $_SESSION['oauth2state'])) {

    exit('Invalid state');

} else {

    // Try to get an access token (using the authorization code grant)
    /** @var AppleAccessToken $token */
    $token = $provider->getAccessToken('authorization_code', [
        'code' => $_POST['code']

    // Optional: Now you have a token you can look up a users profile data
    // Important: The most details are only visible in the very first login!
    // In the second and third and ... ones you'll only get the identifier of the user!
    try {

        // We got an access token, let's now get the user's details
        $user = $provider->getResourceOwner($token);

        // Use these details to create a new profile
        printf('Hello %s!', $user->getFirstName());

    } catch (Exception $e) {

        // Failed to get user details

    // Use this to interact with an API on the users behalf
    echo $token->getToken();

Managing Scopes

When creating your Apple authorization URL, you can specify the state and scopes your application may authorize.

$options = [
    // Scopes:
    'scope' => ['name', 'email'] // array or string

$authorizationUrl = $provider->getAuthorizationUrl($options);

If neither are defined, the provider will utilize internal defaults.

At the time of authoring this documentation, the following scopes are available.

  • name (default)
  • email (default)

Please note that you will get this informations only at the first log in of the user! In the following log ins you'll get only the user id!

Refresh Tokens

If your access token expires you can refresh them with the refresh token.

$refreshToken = $token->getRefreshToken();
$refreshTokenExpiration = $token->getRefreshTokenExpires();


$ ./vendor/bin/phpunit


Please see CONTRIBUTING for details.


Template for this repository was the LinkedIn.


The MIT License (MIT). Please see License File for more information.