LINKED IDENTITIES

More ways to sign in.
One Hybrid-ID.

Apple and Google can become sign-in methods for your Hybrid identity. They do not create a second application profile or change its permissions.

Rollout status: provider registration and real-account acceptance are still required. These methods are hidden from sign-in until configured and enabled.

Existing account or new account?

For integrating applications

Continue using Hybrid-ID’s OIDC integration. Your application does not need Apple or Google credentials and should key users by the validated Hybrid issuer and subject, not email. Hybrid manages the upstream sign-in method.

Linked sign-in methods grant no extra profile, agent, wallet or spending authority. Existing application consent and scopes remain in force.

Optional explorer receipts

Management and verification routes

The first-party browser uses GET/POST /api/identity/federation with its secure Hybrid-ID session. Actions are begin, unlink, publish and withdraw. Writes require a fresh authenticator code; publication also requires publish_consent: true.

These are owner-portal operations, not third-party OIDC token APIs. Server-only Identity routes validate the management client, owner and purpose-bound authorization. Provider callbacks are browser-bound and single-use.

Public signed receipts: https://hybrid-chain.com/api/explorer/external-identities/RECEIPT_ID. Fetch trusted issuer metadata separately at https://hybrid-chain.com/api/explorer/identities/issuer; never trust a key supplied by a receipt presenter.

Disconnecting requires another usable sign-in method and revokes existing Identity sessions. External applications remain responsible for ending their own local sessions and rechecking credentials.