Identity providers

One page per provider: what the operator registers elsewhere, what am.toml carries for it, how it names an account, and where it deviates from the shape. The shape itself, and why, is ADR-030.

ProviderKindAccountOperator setup
Googleredirectgoogle:<sub>an OAuth client in Google's console
Appleredirectapple:<sub>a Services ID and a signing key in Apple's portal
Mastodonredirectthe profile URLnone
atprotocredentialthe DIDnone

A redirect provider sends the person to the provider's own page and back. A credential provider is asked at the door with something the person types.