xmail

Sign in with xmail

OpenID Connect, zero registration. No developer console, no verification queue, no paid program, no secrets to rotate. Your users sign in with one click.

Two lines of config

issuer    = https://xmail.com
client_id = https://your-site.example   # your site's origin — that's the whole registration

Any redirect_uri on that exact origin is accepted (http://localhost:PORT works while developing). Public client, PKCE S256 required, no client secret. Scopes: openid email profile.

Discovery: https://xmail.com/.well-known/openid-configuration

Auth.js / NextAuth v5

import NextAuth from "next-auth";

export const { handlers, auth, signIn, signOut } = NextAuth({
  providers: [{
    id: "xmail",
    name: "xmail",
    type: "oidc",
    issuer: "https://xmail.com",
    clientId: "https://your-site.example",
    client: { token_endpoint_auth_method: "none" },
    checks: ["pkce", "state"],
    authorization: { params: { scope: "openid email profile" } },
  }],
});

Better Auth

import { betterAuth } from "better-auth";
import { genericOAuth } from "better-auth/plugins";

export const auth = betterAuth({
  plugins: [genericOAuth({ config: [{
    providerId: "xmail",
    discoveryUrl: "https://xmail.com/.well-known/openid-configuration",
    clientId: "https://your-site.example",
    clientSecret: "",
    pkce: true,
    scopes: ["openid", "email", "profile"],
  }]})],
});

Django (django-allauth)

SOCIALACCOUNT_PROVIDERS = {
  "openid_connect": {"APPS": [{
    "provider_id": "xmail", "name": "xmail",
    "client_id": "https://your-site.example", "secret": "",
    "settings": {"server_url": "https://xmail.com",
                 "token_auth_method": "none", "oauth_pkce_enabled": True},
  }]},
}

Need a client secret?

Some libraries (Keycloak broker, Supabase, some Passport strategies) insist on one, or your callback lives on a different host. Register once — no account needed:

curl -s https://xmail.com/api/oidc/register \
  -H 'Content-Type: application/json' \
  -d '{"client_name":"My App",
       "redirect_uris":["https://auth.your-site.example/callback"],
       "token_endpoint_auth_method":"client_secret_basic"}'

The secret is returned once. Registered clients use exact redirect URIs. Limits: 10 per hour, 30 per day per IP.

What you get

  • sub — stable for your site, different on other sites. Key your accounts on it, never on email.
  • email, email_verified: true — xmail owns the mailbox.
  • name, preferred_username (the @xmail.com handle), picture.
  • ID token RS256, keys at https://xmail.com/api/oidc/jwks. Access token (1 h) is only for userinfo; create your own session.

Rules

  • redirect_uri: https only (http only for localhost), no fragment, a domain name, never an xmail.com host.
  • PKCE S256 is mandatory. Authorization codes live 120 s and work once.
  • The consent screen shows the host of your redirect URI, not your app name. Users are told xmail never asks for their password elsewhere — never imitate the xmail login form.