Google, Microsoft, Apple sign-in
Signing in to Hela with an account you already have.
For users
On the sign-in and sign-up pages, Continue with Google, Microsoft or Apple. On the first sign-in:
- if a Hela account already exists with that e-mail and the provider has verified it, it is linked: you find your companies;
- otherwise an account is created with the provider's name and address, and pending invitations to that address are attached.
The Hela password stays usable; an account created by Google can set one through Forgot password. Later sign-ins recognise the provider's identity, even if the e-mail changes there.
The browser never sees a token: the dance happens between the API and the provider, and the app receives a single-use code valid two minutes, which it trades for the usual session.
For companies: who has access
Identity says who signs in; Hela's roles say what they may do. A member invited with a Google account keeps the role given (cashier, accountant…), and removing them from the company is enough to cut their access, whatever their identity provider.
For whoever runs the server
The buttons appear only for providers whose keys are set, in the back office → Integrations and keys or in the environment:
| Provider | Keys | Where to create them | Return address to declare |
|---|---|---|---|
GOOGLE_CLIENT_ID, GOOGLE_CLIENT_SECRET — the same as for Drive and Sheets |
Google Cloud Console → Credentials → OAuth client (Web) | ${API_PUBLIC_URL}/auth/oauth/google/callback |
|
| Microsoft | MICROSOFT_CLIENT_ID, MICROSOFT_CLIENT_SECRET — the same as for OneDrive |
Entra → App registrations, multitenant and personal accounts | …/auth/oauth/microsoft/callback |
| Apple | APPLE_CLIENT_ID (Services ID), APPLE_TEAM_ID, APPLE_KEY_ID, APPLE_PRIVATE_KEY (the .p8 file) |
developer.apple.com → Certificates, Identifiers & Profiles: a Services ID with Sign in with Apple, a Sign in with Apple key | …/auth/oauth/apple/callback (Apple answers by POST) |
WEB_PUBLIC_URL says where to send the browser after signing in; by default the first origin of WEB_ORIGIN.
For developers
API keys do not go through identity: see Authentication and scopes. OAuth access for third-party applications ("Connect my Hela to your app" without copying a key) is planned for 3.1; until then a dedicated API key, named after the application, plays that role.