> ## Documentation Index
> Fetch the complete documentation index at: https://docs.hanko.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Using social SSO with Hanko

> Learn how social SSO connections work with Hanko.

<div class="hidden">
  **Hanko Social SSO Overview**:

  **About Hanko**:

  Hanko is a modern open source authentication solution and the fastest way you integrate passkeys, 2FA, SSO, and more—with full control over your data. Move between self-hosted and Hanko Cloud anytime. No lock-in. Just Auth how it should be: secure, user friendly, and fully yours.

  **What This Guide Covers**: This guide provides an overview of social SSO connections, covering both Hanko's
  built-in providers and custom OAuth/OIDC providers you configure yourself, plus how sign-ins through them are
  provisioned and linked to accounts.

  **Prerequisites**:

  * Active Hanko project

  **Tasks You'll Complete**:

  * Understand the difference between built-in and custom providers
  * Access provider-specific integration guides
  * Understand account provisioning and linking behavior
</div>

Hanko supports sign-in through OAuth 2.0 or OpenID Connect (OIDC) providers, either one of its built-in providers or
any custom provider you configure yourself.

## Built-in providers

The following providers are officially tested and supported out of the box:

* [Apple](/guides/social-sso/apple)
* [Discord](/guides/social-sso/discord)
* [Facebook](/guides/social-sso/facebook)
* [GitHub](/guides/social-sso/github)
* [Google](/guides/social-sso/google)
* [LinkedIn](/guides/social-sso/linkedin)
* [Microsoft](/guides/social-sso/microsoft)

## Custom providers

Any other OAuth 2.0 or OIDC provider can be connected as a [custom provider](/guides/social-sso/custom-providers).

## Attribute mapping

Both built-in and custom providers read a fixed set of standard profile fields from the provider - see
[Attribute mapping](/guides/user-data/attribute-mapping) to map them if your provider sends them under different
claim names.

## Account provisioning and linking

On a successful sign-in, Hanko resolves it to a Hanko account based on the email address the connection provides:

* If no Hanko account with that email address exists, a new one is created and the connection is linked to it.

  To prevent this automatic account creation and instead manage account creation yourself:

  <AccordionGroup>
    <Accordion title="Disabling self-service signup">
      1. Log in to [Hanko Cloud](https://cloud.hanko.io) and select your project.
      2. Navigate to `Settings > User account`.
      3. Find the `Account self-service` section.
      4. Use the `Allow Account creation` toggle to disable self-service account creation.
    </Accordion>

    <Accordion title="Creating or importing users">
      1. Log in to [Hanko Cloud](https://cloud.hanko.io) and select your project.
      2. Navigate to `Users`.
      3. On the top right, click:
         * `Create new` to manually create a user.
         * `Import` to bulk import users. See also: [Import and export users](/guides/import-export-users)
    </Accordion>
  </AccordionGroup>
* If a Hanko account with the same email address already exists, the connection is linked to it.

  <Warning>
    A connection may allow account holders to use unverified email addresses, or may not report a verification
    status at all. Linking based on an unverified address is a security risk: it can let a bad actor hijack an
    existing Hanko account by authenticating through a connection using an address they don't actually control but
    that happens to match. Make sure you trust the connection, and don't skip email verification for it unless
    you're confident it only ever reports verified addresses.
  </Warning>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.