Skip to main content
Hanko supports sign-in through OAuth 2.0 or OpenID Connect (OIDC) providers, either one of its built-in providers or any custom provider you configure yourself.

Built-in providers

The following providers are officially tested and supported out of the box:

Custom providers

Any other OAuth 2.0 or OIDC provider can be connected as a custom provider.

Attribute mapping

Both built-in and custom providers read a fixed set of standard profile fields from the provider - see Attribute mapping to map them if your provider sends them under different claim names.

Account provisioning and linking

On a successful sign-in, Hanko resolves it to a Hanko account based on the email address the connection provides:
  • If no Hanko account with that email address exists, a new one is created and the connection is linked to it. To prevent this automatic account creation and instead manage account creation yourself:
    1. Log in to Hanko Cloud and select your project.
    2. Navigate to Settings > User account.
    3. Find the Account self-service section.
    4. Use the Allow Account creation toggle to disable self-service account creation.
    1. Log in to Hanko Cloud and select your project.
    2. Navigate to Users.
    3. On the top right, click:
  • If a Hanko account with the same email address already exists, the connection is linked to it.
    A connection may allow account holders to use unverified email addresses, or may not report a verification status at all. Linking based on an unverified address is a security risk: it can let a bad actor hijack an existing Hanko account by authenticating through a connection using an address they don’t actually control but that happens to match. Make sure you trust the connection, and don’t skip email verification for it unless you’re confident it only ever reports verified addresses.