# SingleSign > SingleSign is a free identity provider that implements OAuth 2.0 and OpenID Connect. Developers use it to add sign-in to web, mobile and single-page applications using the Authorization Code flow with PKCE; account holders use it to see exactly which applications can reach their data, approve each scope individually, and revoke any application instantly. SingleSign is operated by Kraferd and also runs SingleSign Mail, a consent-first email service. ## About - [About SingleSign — the company and the products](https://singlesign.com/about): What SingleSign is, who operates it, which products it runs, and where its verified profiles live. The canonical reference for the SingleSign entity. ## Start here - [SingleSign — Secure sign-in for every platform](https://singlesign.com/): SingleSign is a free identity provider with OAuth 2.0 and OpenID Connect for developers, and per-app consent and instant revocation for everyone signing in. ## Product - [Identity provider features — OAuth 2.0, PKCE, MFA](https://singlesign.com/features): The identity provider features SingleSign ships: OAuth 2.0 and OpenID Connect endpoints, PKCE, scopes and consent, MFA, and instant revocation. - [SingleSign pricing — free sign-in, no MAU meter](https://singlesign.com/pricing): SingleSign pricing in one line: sign-in is free, with no monthly-active-user meter. See exactly what is included, and what SingleSign Mail costs for businesses. - [Identity provider security at SingleSign](https://singlesign.com/security): Identity provider security at SingleSign: PKCE-protected code exchange, redirect URI allow-lists, MFA, session and device control, and rate limiting. ## Topic hubs - [Identity provider alternatives — a switching guide](https://singlesign.com/alternatives): Identity provider alternatives, by the provider you are leaving: what actually has to change in your code, and what does not. - [Identity provider comparison — SingleSign vs others](https://singlesign.com/compare): How SingleSign differs from Auth0, Okta, Firebase Authentication and Google Sign-In on model, consent, portability and price. - [SingleSign Developer Documentation](https://singlesign.com/docs): Learn how to integrate SingleSign identity and authentication into your applications using OAuth 2.0 and OpenID Connect. - [Help Center](https://singlesign.com/help): Find answers about using SingleSign to sign in, manage your privacy, and secure your account. - [Authentication solutions by scenario](https://singlesign.com/solutions): Authentication solutions grouped by what you are building: SaaS single sign-on, a startup MVP, a React single-page app, or a native mobile application. ## Comparisons - [SingleSign vs Auth0 — which model fits your app](https://singlesign.com/compare/singlesign-vs-auth0): SingleSign vs Auth0 compared on the difference that matters: who owns the account. A side-by-side table, then the three cases where each one is the right call. - [SingleSign vs Firebase Authentication](https://singlesign.com/compare/singlesign-vs-firebase-authentication): SingleSign vs Firebase Authentication on lock-in, portability and consent, plus the cases where staying on Firebase is right. - [SingleSign vs Google Sign-In — the privacy difference](https://singlesign.com/compare/singlesign-vs-google-sign-in): SingleSign vs Google Sign-In: the same one-tap convenience, without an advertising business behind the identity. - [SingleSign vs Okta — workforce vs consumer identity](https://singlesign.com/compare/singlesign-vs-okta): SingleSign vs Okta: Okta is built for workforce identity inside a company, SingleSign for consumer sign-in across applications. ## Alternatives - [Auth0 alternatives — what migrating actually costs](https://singlesign.com/alternatives/auth0): Auth0 alternatives compared, plus the part most listicles skip: what migrating off Auth0 actually involves, which code changes, and which does not. - [Firebase Authentication alternatives](https://singlesign.com/alternatives/firebase-authentication): Firebase Authentication alternatives for teams leaving Google Cloud or wanting a standalone OIDC provider. Comparison table, then the real migration path. - [Okta alternatives for customer sign-in](https://singlesign.com/alternatives/okta): Okta alternatives for teams that need customer sign-in rather than workforce identity. The table first, then what changes when you move consumer auth off Okta. ## By scenario - [Mobile app authentication with OAuth 2.0](https://singlesign.com/solutions/mobile-app-authentication): Mobile app authentication for iOS and Android: Authorization Code with PKCE in a system browser, custom scheme redirects, and secure token storage on device. - [React authentication with OAuth 2.0 and PKCE](https://singlesign.com/solutions/react-authentication): React authentication done the recommended way: Authorization Code with PKCE, and no client secret in your JavaScript bundle. - [SSO for SaaS applications — ship it this week](https://singlesign.com/solutions/saas-sso): SSO for SaaS applications using OAuth 2.0 and OpenID Connect: the flow to pick, the scopes to request, and a working integration path with SingleSign. - [Authentication for startups — free, and standards-based](https://singlesign.com/solutions/startup-authentication): Authentication for startups without a monthly-active-user meter: standards-based OAuth 2.0 sign-in you will not have to replace when the product finds traction. ## Developer documentation - [OAuth 2.0 & OpenID Connect](https://singlesign.com/docs/concepts/oauth-oidc): Understand the foundational protocols behind SingleSign: OAuth 2.0 for authorization and OpenID Connect for identity. - [Proof Key for Code Exchange (PKCE)](https://singlesign.com/docs/concepts/pkce): Why PKCE exists, how the S256 challenge method works, and when to use it with SingleSign. - [Redirect URIs](https://singlesign.com/docs/concepts/redirect-uris): Rules for redirect URIs in SingleSign: HTTPS requirements, exact matching, allow-listing, and common mistakes to avoid. - [Tokens & Claims](https://singlesign.com/docs/concepts/tokens-and-claims): Understand access tokens, ID tokens, and refresh tokens issued by SingleSign, including JWT structure, claims, and introspection. - [Quickstart Guide](https://singlesign.com/docs/getting-started): Go from zero to authenticated in six steps. Complete JavaScript/TypeScript code samples included. - [Inviting Users to Your Platform](https://singlesign.com/docs/guides/inviting-users): Build an end-to-end email invitation flow on top of SingleSign — register your invitees, send them a link, and onboard them when they accept. - [Mobile & Native Apps](https://singlesign.com/docs/guides/mobile): Integrate SingleSign into iOS, Android, and desktop applications using PKCE with custom URI schemes and deep links. - [Scopes & Consent](https://singlesign.com/docs/guides/scopes-consent): How to request scopes, what data each scope grants, the consent UI, and the principle of least privilege. - [Server-Side Web App](https://singlesign.com/docs/guides/server-web-app): Integrate SingleSign into a server-rendered web application using the confidential client flow with Node.js and Express. - [SPA with PKCE](https://singlesign.com/docs/guides/spa-pkce): Complete guide to integrating SingleSign into a single-page application using the Authorization Code flow with PKCE. - [Endpoint Reference](https://singlesign.com/docs/reference/endpoints): Complete API reference for all SingleSign OAuth 2.0 and OpenID Connect endpoints with methods, parameters, and curl examples. - [Error Reference](https://singlesign.com/docs/reference/errors): Complete reference of SingleSign OAuth error codes, error response format, and troubleshooting tips for each error. - [Rate Limits](https://singlesign.com/docs/reference/rate-limits): Per-endpoint rate limits, 429 response format, Retry-After header, and best practices for staying within limits. - [Scopes Reference](https://singlesign.com/docs/reference/scopes): Complete reference of all SingleSign OAuth scopes, the claims each scope returns, example values, and when to use each scope. - [Register an Application](https://singlesign.com/docs/register-an-app): Create your application in the SingleSign developer portal, get a client ID, configure redirect URIs, and set scopes. - [Troubleshooting OAuth errors](https://singlesign.com/docs/troubleshooting): Common SingleSign integration errors with causes and fixes: PKCE mismatch, redirect URI errors, expired codes, invalid scopes, and CORS problems. ## Help articles - [SingleSign Business](https://singlesign.com/help/business): The SingleSign Business help hub: company mail on a free .singlesign.com address or your own domain — DNS, members, mailboxes, roles and pricing. - [Company mailboxes](https://singlesign.com/help/business/company-mailboxes): How company mailboxes work on SingleSign Business: assigning an address, aliases, suspend, transfer, forward, and the 20-day restore window. - [Deleting an organization](https://singlesign.com/help/business/deleting-an-organization): How the Owner deletes an organization on SingleSign Business: what has to happen first, what is purged immediately, and what is never touched. - [Domains and DNS records](https://singlesign.com/help/business/domains-and-dns): Your free name.singlesign.com subdomain, plus every record your own domain needs: ownership TXT, MX, SPF, DKIM, DMARC, and registrar walkthroughs. - [Business FAQ](https://singlesign.com/help/business/faq): Common questions about SingleSign Business: the free .singlesign.com address, your own domain, pricing, who owns a mailbox, and whether admins read mail. - [Forwarders and parked domains](https://singlesign.com/help/business/forwarders-and-parked-domains): Role addresses like support@ and sales@ on SingleSign Business: where they deliver, how the Screener treats them, catch-all, and parked domains. - [Getting started as a business](https://singlesign.com/help/business/getting-started): Set up SingleSign Business: start an organization with a free name.singlesign.com address, get your mailbox, invite people, add your own domain any time. - [Joining an organization](https://singlesign.com/help/business/joining-an-organization): What to do when a colleague invites you to their SingleSign Business organization: accepting, signing in, and getting your company address. - [Members and invites](https://singlesign.com/help/business/members-and-invites): How people join your SingleSign Business organization: sending invites, the roles available, resending or revoking, and removing a member. - [Plans and pricing](https://singlesign.com/help/business/plans-and-pricing): SingleSign Business plans and pricing: Personal is free, Business is $5 per user per month ($4 prepaid annually), Enterprise covers 500+ users. - [Admin roles and permissions](https://singlesign.com/help/business/roles-and-permissions): Who can do what in a SingleSign Business organization: Owner, Admin, Member and Auditor, the delegated admin roles, and why no role can read mail. - [The Screener for businesses](https://singlesign.com/help/business/screener-for-businesses): How the Screener behaves inside an organization: colleagues skip it, customers and strangers still wait, and exactly what admins can and cannot see. - [Managing Connected Apps](https://singlesign.com/help/connected-apps): How to view, review, and revoke the apps connected to your SingleSign account. - [Creating an Account](https://singlesign.com/help/getting-started/creating-an-account): How to create a free SingleSign account: pick an address, set a password, verify it, and turn on multi-factor authentication. - [Deleting your account](https://singlesign.com/help/getting-started/deleting-your-account): How to delete your SingleSign account from My Data: the 20-day cancellation window, what is erased, and why owning an organization blocks it. - [Signing In](https://singlesign.com/help/getting-started/signing-in): How to sign in to an app with your SingleSign account, what the consent screen is asking for, and what to do if sign-in does not finish. - [What is SingleSign?](https://singlesign.com/help/getting-started/what-is-singlesign): A plain-language explanation of what SingleSign is and how it works for consumers. - [SingleSign Mail](https://singlesign.com/help/mail): The SingleSign Mail help hub — your @singlesign.com mailbox, the Screener, phones, Writer, Spreadsheets, Chat and company mail for your organization. - [Your Accounts & Organizations](https://singlesign.com/help/mail/accounts-and-organizations): One SingleSign sign-in, several mailboxes: your personal address plus a company mailbox per organization. Switching, All inboxes and signing out. - [AI features](https://singlesign.com/help/mail/ai-features): Help me write, Translate document and Dictionary in Writer; AI(), GOOGLETRANSLATE, Help me organize and formula help in Spreadsheets. - [Chat: getting started](https://singlesign.com/help/mail/chat): SingleSign Chat is team chat for your organization: channels, direct messages and threads, like Slack, built into SingleSign Mail. - [Chat: channels and direct messages](https://singlesign.com/help/mail/chat-channels-and-dms): Channels and direct messages in Chat: sidebar sections, bookmarks and channel docs, channel managers and announcement channels, and user groups. - [Chat with Mail, Calendar and Meetings](https://singlesign.com/help/mail/chat-meetings-and-mail): Meeting chats that last beyond the call, Discuss in Chat from an email, Share via email, files from Documents, and a status set from your calendar. - [Chat: messages, threads, mentions and reactions](https://singlesign.com/help/mail/chat-messages): Format, schedule, forward and set reminders on Chat messages, reply in threads, @mention, react with custom emoji, and share snippets and files. - [Chat: notifications, status and Do Not Disturb](https://singlesign.com/help/mail/chat-notifications): Unread badges, muting, keyword, desktop and email notifications, your status and calendar status, Do Not Disturb, presence and profile cards in Chat. - [Chat: search and keyboard shortcuts](https://singlesign.com/help/mail/chat-search-and-shortcuts): Search Chat with in:, from:, has:, is:thread and date modifiers, jump anywhere with the quick switcher, and every slash command and keyboard shortcut. - [Claiming Your Address](https://singlesign.com/help/mail/claiming-your-address): How to claim your personal @singlesign.com address, which names are allowed, and how a company address from an organization differs. - [Drawings](https://singlesign.com/help/mail/drawings): Draw diagrams, flowcharts and sketches in Writer and Spreadsheets — shapes, lines, text, word art, images, arranging and downloads. - [SingleSign Mail FAQ](https://singlesign.com/help/mail/faq): Common questions about SingleSign Mail: mail apps, the Screener, your address, company addresses, sending limits, and what is coming next. - [Moving your team from Slack](https://singlesign.com/help/mail/moving-from-slack): For admins: export your Slack history, import it into SingleSign Chat, repoint Slack incoming webhooks, set retention and export your Chat data. - [SingleSign Mail on Your Phone](https://singlesign.com/help/mail/phone-setup): Two ways to get SingleSign Mail on your phone — the home-screen app, or your phone's built-in mail app via an app password and IMAP — and how sync works. - [Storage & Limits](https://singlesign.com/help/mail/privacy-and-limits): Storage quotas, Trash and retention periods, permanent deletion, attachment limits, and what happens when a personal or company mailbox is deleted. - [Privacy & Protections](https://singlesign.com/help/mail/privacy-and-protections): How SingleSign Mail protects you — the Screener, Link Guard, tracking-pixel flags, ask-first remote images, sender authentication, and sending limits. - [Apps Script: automate Writer and Spreadsheets](https://singlesign.com/help/mail/scripts): Automate Writer and Spreadsheets with Apps Script: custom functions, menus, simple triggers, dialogs, supported services, authorization and limits. - [Sending & Receiving](https://singlesign.com/help/mail/sending-receiving): Composing messages, threading, attachments, tags, the All mail view, sent-mail metrics, away auto-replies, and sending limits in SingleSign Mail. - [Sharing, comments and version history](https://singlesign.com/help/mail/sharing-comments-and-versions): Share documents and spreadsheets as viewer, commenter or editor — links, comments, @mentions, suggestions, notification emails, versions and the trash. - [Formulas and functions reference](https://singlesign.com/help/mail/spreadsheet-functions): Every function SingleSign Spreadsheets supports, by category, with syntax, a one-line description and an example. - [Spreadsheets: tables, slicers and timelines](https://singlesign.com/help/mail/spreadsheet-tables-and-views): Tables with typed columns and structured references, slicers, timeline view, named functions, smart chips and cleanup suggestions in Spreadsheets. - [Spreadsheets](https://singlesign.com/help/mail/spreadsheets): Build and share spreadsheets — formulas, formatting, filters, pivot tables, every chart type, web and finance data, import, export and shortcuts. - [The Screener](https://singlesign.com/help/mail/the-screener): How the Screener works — every first-time sender waits for your approval before anything they send can reach your inbox. - [What is SingleSign Mail?](https://singlesign.com/help/mail/what-is-singlesign-mail): SingleSign Mail is a free @singlesign.com mailbox built into your account, with a Screener that holds first-time senders until you approve them. - [Writer: building blocks, variables and citations](https://singlesign.com/help/mail/writer-building-blocks): Writer building blocks — meeting notes, trackers and an email draft you send from Mail — plus variables and citations with an automatic bibliography. - [Writer: documents](https://singlesign.com/help/mail/writer-documents): Write and format documents together in Writer — templates, styles, tables, images, page setup, suggesting, reactions, PDF and other downloads. - [Writer: tabs, sections and page layout](https://singlesign.com/help/mail/writer-page-layout): Organize a Writer document with tabs and subtabs, sections with their own orientation, margins and headers, columns, line numbers and watermarks. - [Writer: e-signatures and locking](https://singlesign.com/help/mail/writer-signatures): Collect typed or drawn signatures in a Writer document, follow the audit trail and lock it once signed — and what these signatures are and aren't. - [Privacy & Consent](https://singlesign.com/help/privacy-consent): Understand what apps can access, how consent works, and how to manage your data with SingleSign. - [Account Security](https://singlesign.com/help/security): An overview of how to protect your SingleSign account with MFA, backup codes, session management, and recovery options. - [Sessions & Devices](https://singlesign.com/help/security/devices): How to review active sessions and manage devices signed in to your SingleSign account. - [Multi-Factor Authentication (MFA)](https://singlesign.com/help/security/mfa): How to enable and use multi-factor authentication to protect your SingleSign account. - [Recovery Options](https://singlesign.com/help/security/recovery): How to set up recovery contacts and backup codes to ensure you can always access your SingleSign account. - [Troubleshooting account problems](https://singlesign.com/help/troubleshooting): Fixes for common SingleSign account problems: sign-in failures, verification emails that do not arrive, and multi-factor authentication trouble. ## Legal - [Acceptable Use Policy](https://singlesign.com/legal/aup): Prohibited activities, security expectations, and enforcement for the SingleSign platform. - [Cookie Policy](https://singlesign.com/legal/cookies): How SingleSign uses cookies and similar storage: what each one is for, which are strictly necessary, and how to control them. - [Privacy Policy](https://singlesign.com/legal/privacy): How SingleSign collects, uses, and protects your personal information. - [Terms of Service](https://singlesign.com/legal/terms): The terms and conditions governing your use of the SingleSign identity platform.