OpenID Connect, zero registration. No developer console, no verification queue, no paid program, no secrets to rotate. Your users sign in with one click.
issuer = https://xmail.com
client_id = https://your-site.example # your site's origin — that's the whole registrationAny redirect_uri on that exact origin is accepted (http://localhost:PORT works while developing). Public client, PKCE S256 required, no client secret. Scopes: openid email profile.
Discovery: https://xmail.com/.well-known/openid-configuration
import NextAuth from "next-auth";
export const { handlers, auth, signIn, signOut } = NextAuth({
providers: [{
id: "xmail",
name: "xmail",
type: "oidc",
issuer: "https://xmail.com",
clientId: "https://your-site.example",
client: { token_endpoint_auth_method: "none" },
checks: ["pkce", "state"],
authorization: { params: { scope: "openid email profile" } },
}],
});import { betterAuth } from "better-auth";
import { genericOAuth } from "better-auth/plugins";
export const auth = betterAuth({
plugins: [genericOAuth({ config: [{
providerId: "xmail",
discoveryUrl: "https://xmail.com/.well-known/openid-configuration",
clientId: "https://your-site.example",
clientSecret: "",
pkce: true,
scopes: ["openid", "email", "profile"],
}]})],
});SOCIALACCOUNT_PROVIDERS = {
"openid_connect": {"APPS": [{
"provider_id": "xmail", "name": "xmail",
"client_id": "https://your-site.example", "secret": "",
"settings": {"server_url": "https://xmail.com",
"token_auth_method": "none", "oauth_pkce_enabled": True},
}]},
}Some libraries (Keycloak broker, Supabase, some Passport strategies) insist on one, or your callback lives on a different host. Register once — no account needed:
curl -s https://xmail.com/api/oidc/register \
-H 'Content-Type: application/json' \
-d '{"client_name":"My App",
"redirect_uris":["https://auth.your-site.example/callback"],
"token_endpoint_auth_method":"client_secret_basic"}'The secret is returned once. Registered clients use exact redirect URIs. Limits: 10 per hour, 30 per day per IP.
sub — stable for your site, different on other sites. Key your accounts on it, never on email.email, email_verified: true — xmail owns the mailbox.name, preferred_username (the @xmail.com handle), picture.https://xmail.com/api/oidc/jwks. Access token (1 h) is only for userinfo; create your own session.redirect_uri: https only (http only for localhost), no fragment, a domain name, never an xmail.com host.