Overview
Custom Social Login allows you to use your own OAuth applications for Google, Apple, and X (Twitter) authentication instead of CDP’s default OAuth providers. This gives you complete control over the OAuth experience, including branding, rate limits, and compliance requirements. By default, Embedded Wallets uses CDP-managed OAuth applications for social login, allowing users to recognize and trust Coinbase’s brand during authentication. Custom Social Login enables you to replace these defaults with your own OAuth applications while maintaining the same seamless authentication experience.Why use custom OAuth?
Brand consistency
Brand consistency
When users authenticate, they’ll see your application name and branding in the OAuth consent screen instead of Coinbase’s. This creates a more cohesive experience for users who identify your application as the primary service they’re using.
Control over OAuth configuration
Control over OAuth configuration
Manage your own OAuth applications and configurations, including:
- Consent screen branding and messaging
- OAuth scopes and permissions
- Application review and approval timelines
- Access to provider-specific features and settings
Compliance and audit requirements
Compliance and audit requirements
Some organizations require:
- Full ownership of authentication infrastructure
- Direct relationships with OAuth providers
- Detailed audit logs from OAuth providers
- Compliance with specific regulatory frameworks
Rate limit control
Rate limit control
OAuth providers apply rate limits per application. Using your own OAuth applications allows you to:
- Scale authentication to your specific needs
- Request rate limit increases directly from providers
- Avoid shared rate limits with other CDP users
- Monitor and optimize usage patterns
How it works
Default behavior: CDP's OAuth applications
Default behavior: CDP's OAuth applications
By default, when users authenticate with social login:
- Users click “Sign in with Google” (or Apple/X)
- They’re redirected to the provider’s OAuth flow
- The OAuth consent screen shows “Coinbase” or “CDP” as the requesting application
- Upon approval, users are authenticated and their wallet is accessed
- All rate limits and quotas are managed by CDP
Custom behavior: Your OAuth applications
Custom behavior: Your OAuth applications
When you configure custom OAuth applications:
- Users click “Sign in with Google” (or Apple/X)
- They’re redirected to the provider’s OAuth flow
- The OAuth consent screen shows your application name as the requesting application
- Upon approval, users are authenticated using your OAuth credentials
- Rate limits and quotas are based on your OAuth application configuration
Identity continuity during migration
Identity continuity during migration
If your users are already authenticated with CDP’s default social login and you enable custom OAuth:
- Existing users retain full access to their wallets and identities
- No wallet re-creation or migration required
- User identities remain consistent across the transition
- Authentication simply switches from CDP’s OAuth app to yours
- All wallet addresses, assets, and transaction history are preserved
Critical disclaimers
Identity continuity guarantee:Switching from CDP’s default social login to custom OAuth preserves user identities. Users who authenticated with CDP’s Google OAuth application will seamlessly continue to access the same wallet when you configure your custom Google OAuth application.The same applies for Apple and X - user wallets are linked to their social identity (email, user ID), not to the specific OAuth application used for authentication.
Provider comparison
| Provider | Setup Complexity | Verification Time | Redirect URL | Special Requirements |
|---|---|---|---|---|
| Moderate | Instant (may require app verification for production) | https://api.cdp.coinbase.com/platform/v2/end-users/auth/oauth/google/callback | OAuth consent screen configuration | |
| Apple | High | Instant | https://api.cdp.coinbase.com/platform/v2/end-users/auth/oauth/apple/callback | Apple Developer account ($99/year), Private key (.p8 file) |
| X | Moderate | Instant (may require approval for additional permissions) | https://api.cdp.coinbase.com/platform/v2/end-users/auth/oauth/x/callback | Rate limits apply even on free tier |
Prerequisites
Before configuring custom OAuth, ensure you have:- CDP Project ID: Available in the CDP Portal
- Access to CDP Portal: Permission to configure Embedded Wallets settings
- Developer accounts: Accounts with each OAuth provider you plan to use:
- Google: Google Cloud Platform account
- Apple: Apple Developer account ($99/year required)
- X: X Developer account (free tier available)
- OAuth 2.0 understanding: Basic familiarity with OAuth flows and terminology
Quick start
Choose a provider to get started with custom OAuth configuration:Set up Google OAuth with Client ID and Client Secret
Apple
Configure Apple Sign In with Services ID and private key
X
Enable X OAuth for Twitter/X authentication