Skip to main content
Documentation - Discord Docs

Search documentation

Type to search this documentation.

On this pageOverview

Configuring Identity Providers

Unless you are using the Bot Token Endpoint, you must configure an identity provider before you can create provisional accounts. This applies to both Server Authentication with External Credentials Exchange and Public Client Integration.

Not sure which authentication method to use? See Choosing an Authentication Method.

Open the Discord app for your game in the Developer Portal. Find the External Auth page under the Discord Social SDK section in the sidebar.

Click on Add Auth Provider and choose the type of provider you're using (Steam, OIDC, etc.). Fill in the required details for your provider.

We currently support the following provider types:

  • OpenID Connect (OIDC)
  • Steam Session Tickets
  • Epic Online Services (EOS)
  • Unity
  • Apple
  • PlayStation Network (PSN)

If you are configuring OIDC, see OIDC Integration Requirements for the full list of requirements your issuer URL, discovery document, and ID tokens must meet.

Providers are represented in Discord's systems by the following types:

Type Description
OIDC OpenID Connect ID token
STEAM_SESSION_TICKET A Steam auth ticket for web generated with discord as the identity
EPIC_ONLINE_SERVICES_ACCESS_TOKEN Access token for Epic Online Services. Supports EOS Auth access tokens
EPIC_ONLINE_SERVICES_ID_TOKEN ID token for Epic Online Services. Supports both EOS Auth + Connect ID tokens
UNITY_SERVICES_ID_TOKEN Unity Services authentication ID token
APPLE_ID_TOKEN Apple sign-in authentication ID token
PLAYSTATION_NETWORK_ID_TOKEN PlayStation Network account authentication ID token
DISCORD_BOT_ISSUED_ACCESS_TOKEN An access token for a user authenticated via the Bot Token Endpoint

If you are using OpenID Connect (OIDC) as your identity provider, Discord validates your configuration and tokens against the requirements below. Meeting these requirements is necessary both when saving your OIDC configuration in the Developer Portal and at runtime when tokens are exchanged.

The issuer URL you configure in the Developer Portal must meet all of the following:

Requirement Details
HTTPS scheme Must use https:// — HTTP is not permitted
No query parameters The URL must not contain a ? character
No fragment The URL must not contain a # character
No embedded credentials The URL must not contain a username or password
Public hostname The hostname must have at least two segments (e.g. example.com). Bare hostnames such as localhost are not permitted
No private or reserved TLDs The hostname must not end in .local, .arpa, .internal, or .localhost
No IP addresses The hostname must not be a bare IP address (e.g. 192.168.1.1)

Non-standard ports (e.g. :8080) are permitted.

Discord fetches your OIDC configuration from {issuer_url}/.well-known/openid-configuration per RFC 8414. This endpoint must:

  • Be accessible over HTTPS
  • Not require HTTP redirects — Discord does not follow redirects when fetching this document or your JWKS endpoint
  • Return a valid JSON object (not an array)

The discovery document must include these fields:

Field Type Requirement
issuer HTTPS URL Must exactly match the issuer URL used to fetch the document
jwks_uri HTTPS URL URI to your JWKS signing key endpoint
id_token_signing_alg_values_supported Array of strings Must contain at least one supported algorithm

authorization_endpoint and token_endpoint are accepted but not used by Discord.

Your ID tokens must be signed using an asymmetric algorithm. Discord supports:

Algorithm family Algorithms
RSA RS256, RS384, RS512
ECDSA ES256, ES384, ES512
RSA-PSS PS256, PS384, PS512

Symmetric (HMAC) algorithms such as HS256 are not supported. Any unsupported algorithms listed in id_token_signing_alg_values_supported are silently ignored.

The OIDC ID token passed as external_auth_token must meet all of the following:

Requirement Details
kid header The JWT header must include a kid (Key ID) field that matches a key in your JWKS
Signing algorithm Must use one of the supported algorithms listed in your discovery document
iss claim Must exactly match the configured issuer URL
sub claim Required — the unique user identifier from your identity provider
aud claim Must include the client ID configured for this application in the Developer Portal
exp claim Required — token must not be expired
iat claim Required — token must have been issued within the past 7 days

The optional preferred_username claim (1–32 characters) sets the provisional account's display name if present. See Setting Display Names for how display names are chosen across providers.


Once your identity provider is configured, continue to the authentication method that matches your setup:

Need help? Join the Discord Developers Server and share questions in the #social-sdk-dev-help channel for support from the community.

If you encounter a bug while working with the Social SDK, please report it here: https://dis.gd/social-sdk-bug-report


Date Changes
July 14, 2026 Split the provisional accounts guide into its own section
March 17, 2025 Initial release
Suggest an edit

Propose a replacement for this page. The site team reviews it before applying any changes.

Export
Documentation menu