At the end of the day, the benefit of signing in to apps is to be able to save stuff to your account so you can restore it later, and to get email notifications.
1
3
"Sign In with Apple" provides apps with both those features without revealing any more information about you than necessary.
1
1
2
So yes, Sign In with Apple is a good thing for user privacy, and will be a better user experience overall.
1
3
Is Apple using their position as gatekeepers of the App Store to force adoption of "Sign In with Apple"? Yes. Is this a bad thing? No. Does this affect you if you don't use an iOS device? No. Does this benefit people who have an iOS device? Yes.
1
3
7
Will we see other OAuth providers follow suit and start randomizing email addresses and user IDs returned to apps? I hope so! Ironically, Facebook first started doing this a few years ago when they launched app-scoped user IDs.
3
1
1
3
That is all. Thanks for listening.
2
10
Now I would just love to have a quick guide for using Apple Sign In as an Okta generic oidc inbound provider. Is this possible already ?
1
I actually just got this working last night!
2
1
Do you know where you can find the .well-known/openid-configuration on the apple url? Do they even use it?
1
I haven't found it yet. I wouldn't be surprised if they just don't have that endpoint

Jun 6, 2019 · 5:46 PM UTC

2
1
So talked with the Apple engineers here at WWDC: They don't have that endpoint, they also will not expose user_info or a revocation endpoint. The user_info will only be sent once and only once then you will only get a unique id again. Only scopes available now are name and email
3
Brilliant, thanks for the info! Have you been able to successfully request name and email scope yet? It wasn't working in my testing.
Thanks, I will see if I can find it either way.