Google, Microsoft, Apple sign-in

Signing in to Hela with an account you already have.

For users

On the sign-in and sign-up pages, Continue with Google, Microsoft or Apple. On the first sign-in:

  • if a Hela account already exists with that e-mail and the provider has verified it, it is linked: you find your companies;
  • otherwise an account is created with the provider's name and address, and pending invitations to that address are attached.

The Hela password stays usable; an account created by Google can set one through Forgot password. Later sign-ins recognise the provider's identity, even if the e-mail changes there.

The browser never sees a token: the dance happens between the API and the provider, and the app receives a single-use code valid two minutes, which it trades for the usual session.

For companies: who has access

Identity says who signs in; Hela's roles say what they may do. A member invited with a Google account keeps the role given (cashier, accountant…), and removing them from the company is enough to cut their access, whatever their identity provider.

For whoever runs the server

The buttons appear only for providers whose keys are set, in the back office → Integrations and keys or in the environment:

Provider Keys Where to create them Return address to declare
Google GOOGLE_CLIENT_ID, GOOGLE_CLIENT_SECRET — the same as for Drive and Sheets Google Cloud Console → Credentials → OAuth client (Web) ${API_PUBLIC_URL}/auth/oauth/google/callback
Microsoft MICROSOFT_CLIENT_ID, MICROSOFT_CLIENT_SECRET — the same as for OneDrive Entra → App registrations, multitenant and personal accounts …/auth/oauth/microsoft/callback
Apple APPLE_CLIENT_ID (Services ID), APPLE_TEAM_ID, APPLE_KEY_ID, APPLE_PRIVATE_KEY (the .p8 file) developer.apple.com → Certificates, Identifiers & Profiles: a Services ID with Sign in with Apple, a Sign in with Apple key …/auth/oauth/apple/callback (Apple answers by POST)

WEB_PUBLIC_URL says where to send the browser after signing in; by default the first origin of WEB_ORIGIN.

For developers

API keys do not go through identity: see Authentication and scopes. OAuth access for third-party applications ("Connect my Hela to your app" without copying a key) is planned for 3.1; until then a dedicated API key, named after the application, plays that role.

Something wrong or missing? Write to us.