Sign in with Apple uses a Services ID and a signing key. Authdog mints the short-lived client-secret JWT on every token exchange, so you paste the `.p8` once and do not rotate a static secret. If your iOS app offers any other social login, App Store review expects this connector alongside it.

## Before you start

You need a paid [Apple Developer Program](https://developer.apple.com/programs/) membership. The free account cannot create the Services ID or the key.

In the [Authdog console](https://console.authdog.com), select the project and environment, open **Authentication > Providers**, find **Apple**, and click **Enable**. Copy the redirect URI:

```url
https://identity.authdog.com/api/v1/callback/<connectionId>
```

> **Caution**
>
> Apple rejects `http://` and bare hostnames. `localhost` cannot be registered. Local development needs a public HTTPS host, or an environment with a [custom domain](/docs/custom-domains).

## Create the App ID and Services ID

1. Open [Certificates, Identifiers & Profiles](https://developer.apple.com/account/resources/identifiers/list).
2. Create an **App ID** and enable **Sign In with Apple**.
3. Create a **Services ID**. Note the identifier (for example `com.example.app.web`). It becomes the client ID.
4. Reopen the Services ID, enable **Sign In with Apple**, and **Configure** it.
5. Set **Primary App ID** to the App ID you just created.
6. Under **Domains and Subdomains**, add `identity.authdog.com`, or your custom domain host.
7. Under **Return URLs**, paste the redirect URI from Authdog.
8. Save.

## Create the sign-in key

1. Open **Keys** and select **+**.
2. Name the key, enable **Sign In with Apple**, and configure it against the primary App ID.
3. Register, then download the `.p8` file. Apple lets you download it once.
4. Note the **Key ID**. Your **Team ID** is in the top-right of the developer portal.

## Configure Authdog

| Field | Value |
| --- | --- |
| **Team ID** | The 10-character team identifier |
| **Service ID** | The Services ID identifier |
| **Key ID** | The 10-character key identifier |
| **Private Key** | The full `.p8` file, including the `BEGIN PRIVATE KEY` and `END PRIVATE KEY` lines |

Save, then toggle the connection **active**. Store the `.p8` in [Vault](/docs/console/vault). Apple will not issue a second copy.

Apple sends the user's name only on the first authorization, and only if they agree to share it. **Hide My Email** yields a stable `privaterelay.appleid.com` address. Persist the name the first time you see it.

## Test it

1. Open hosted sign-in, or `https://identity.authdog.com/api/v1/signin/<connectionId>`.
2. Select **Continue with Apple**.
3. Confirm the user appears under **Users** with an Apple identity.
4. Sign out and back in. You should land on the same user.

## Troubleshooting

| Symptom | Cause |
| --- | --- |
| `invalid_client` | Team ID, Key ID, or Services ID mismatch, or the key is not enabled for Sign In with Apple |
| `invalid_grant` | The `.p8` contents are truncated. Repaste the whole file |
| Apple redirect error | The Return URL does not match Authdog's redirect URI exactly |
| Domain verification prompt | The domain under **Domains and Subdomains** is missing or misspelled |

## Related

| Read | To learn how to |
| --- | --- |
| [Apple connector](/docs/connectors/apple) | The same setup in the connector catalog |
| [Marketplace](/marketplace/apple) | The listing for this integration |
| [Custom domains](/docs/custom-domains) | Serve the callback from your own HTTPS host |
