59°F

Aaron Parecki

  • Articles
  • Notes
  • Photos
  • Aaron Parecki
    Initial test of the "Sign in with Apple" API:

    • It's more or less based on OAuth + OIDC
    • Their documentation is missing a lot of key info to use it right now, I had to guess at a lot of things
    • The `sub` claim includes some sort of unique user identifier, not an email
    Portland, Oregon, USA
    Mon, Jun 3, 2019 2:21pm -07:00 #oauth
    74 likes 23 reposts 8 replies
    • dansup
    • Dmitri Shuralyov
    • Kirill Zubovsky
    • Blaine Cook
    • Nate Barbettini
    • @herestomwiththeweather@mastodon.social
    • Andrew Pouliot
    • Eytan Schulman
    • kellan 🌊
    • Rosemary Orchard @ WWDC
    • ᛚᛖᛁᚠ Warner
    • Matt Raible
    • Aidan Britnell
    • Peter Steinberger @ WWDC
    • Karl Sander
    • Eduardo Raad
    • JaviAir
    • Craig Siemens
    • oz lubling
    • Jaime Lopez
    • Umar
    • Andrew Wooster
    • Markos Charatzas
    • josh avant 🤖 dub dub
    • Joel Yen
    • Kyle Howells
    • NODL
    • Morten Bøgh
    • Luna Graysen 🌻
    • Hernán Zalazar
    • Kofi Jim 🇬🇭
    • kim kwang yong
    • Andrés Aguiar
    • Jon Parise
    • Phil @WWDC
    • Ravi Shanker
    • Jeremy Gale
    • Mike VanDelinder
    • Cristian
    • Lisa Brewster
    • Noah Seger
    • Farasath Ahamed
    • David Stockley
    • Harimurti Prasetio
    • Alexey Plekhanov
    • Ashish Dasnurkar
    • Karl McGuinness
    • Carrick
    • Mickaël Rémond
    • Mariela
    • Gerry Weißbach
    • damienbod
    • Dr. Fett
    • Tom Jirinec
    • Dave Tonge
    • Rafał Sobolewski
    • Peter
    • Nicolas Beaussart
    • Bahri Okuroglu
    • Amirsh
    • vixentael 👩‍💻
    • real realDonaldTrump
    • Ben Hager
    • 🌈 Berta Devant 👩‍💻 🤖
    • Evan Prodromou
    • Asim Aslam
    • Cristian Douce
    • Jamie Tanna | www.jvt.me
    • Laura Rodríguez
    • Heather Downing
    • Atharva Vaidya
    • kazuki229
    • N Minnov
    • Eric Young
    • Kuba Suder
    • Eric Young
    • Iurii Pleskach
    • Asim Aslam
    • Didier Bathily
    • Amirsh
    • Tom Jirinec
    • Gerry Weißbach
    • Markus Eisele
    • Matt Raible
    • Yenkel
    • Hernán Zalazar
    • Luna Graysen 🌻
    • kim kwang yong
    • Kyle Howells
    • Sean Ho
    • Andrew Wooster
    • Luis Ascorbe @ Layers, AltConf
    • josh avant 🤖 dub dub
    • Don't @ me
    • Peter Steinberger @ WWDC
    • Rosemary Orchard @ WWDC
    • Andrew Pouliot
    • Marty McGuire martymcgui.re

      I am excited to see this as part of indielogin.com, but I don’t yet see a clear identifier that I could put on my homepage to say “yep, that’s my Apple account”!

      Tue, Jun 4, 2019 12:42pm -04:00
    • Marty McGuire martymcgui.re

      I am excited to see this as part of indielogin.com, but I don’t yet see a clear identifier that I could put on my homepage to say “yep, that’s my Apple account”!

      Tue, Jun 4, 2019 12:42pm -04:00
    • Jhonny twitter.com/JhonnyBillM
      Ugh, I understand.
      Thank you
      Mon, Jun 3, 2019 10:58pm +00:00 (via brid-gy.appspot.com)
    • Aaron Parecki twitter.com/aaronpk
      So far there is no indication that'll be possible.
      Mon, Jun 3, 2019 10:45pm +00:00 (via brid-gy.appspot.com)
    • Jhonny twitter.com/JhonnyBillM
      Do you know if I can request users profile picture ?
      Mon, Jun 3, 2019 10:43pm +00:00 (via brid-gy.appspot.com)
    • Even André Fiskvik twitter.com/grEvenX
      Thanks 🙏 Really interested in this one, hope it won’t be flawed by technical “sillyness” like in the previous incarnations of the AuthenticationServices
      Mon, Jun 3, 2019 9:56pm +00:00 (via brid-gy.appspot.com)
    • Aaron Parecki twitter.com/aaronpk
      They have some docs here developer.apple.com/sign-in-with-a… but their docs are missing quite a bit right now. I had to guess at some endpoints and things.
      Mon, Jun 3, 2019 9:31pm +00:00 (via brid-gy.appspot.com)
    • Aaron Parecki aaronparecki.com
      weirdnesses:

      • Their token endpoint requires setting a User-Agent header, otherwise responds with an HTML error
      • Client secrets are a signed JWT using ECDSA + SHA256
      • An email address isn't returned even when requesting the `email` scope
      Mon, Jun 3, 2019 2:24pm -07:00
Posted in /notes using quill.p3k.io

Hi, I'm Aaron Parecki, Director of Identity Standards at Okta, and co-founder of IndieWebCamp. I maintain oauth.net, write and consult about OAuth, and participate in the OAuth Working Group at the IETF. I also help people learn about video production and livestreaming. (detailed bio)

I've been tracking my location since 2008 and I wrote 100 songs in 100 days. I've spoken at conferences around the world about owning your data, OAuth, quantified self, and explained why R is a vowel. Read more.

  • Director of Identity Standards at Okta
  • IndieWebCamp Founder
  • OAuth WG Editor
  • OpenID Board Member

  • 🎥 YouTube Tutorials and Reviews
  • 🏠 We're building a triplex!
  • ⭐️ Life Stack
  • ⚙️ Home Automation
  • All
  • Articles
  • Bookmarks
  • Notes
  • Photos
  • Replies
  • Reviews
  • Trips
  • Videos
  • Contact
© 1999-2025 by Aaron Parecki. Powered by p3k. This site supports Webmention.
Except where otherwise noted, text content on this site is licensed under a Creative Commons Attribution 3.0 License.
IndieWebCamp Microformats Webmention W3C HTML5 Creative Commons
WeChat ID
aaronpk_tv