Social Login for Magento 2

Let shoppers sign in and register with the accounts they already use — on your sign-in page and at checkout.

  • Google · Facebook · X
  • Magento 2.4.7 – 2.4.9
  • PHP 8.2 – 8.5
  • Hyvä and Luma
  • Version 1.3.0

Free

No payment needed, with 12 months of updates.

Add it to your cart and complete the free checkout. Your ZIP downloads and Composer access will be in your account.

What is included

  • 12 months of new versions and fixes; the versions released in that time stay yours
  • Install with Composer, or download a zip from your account
  • Licence for one production domain, staging and development copies included

No subscription or automatic renewal. Keep using the versions included in your update period. Update and licence details

Key features

  • Google, Facebook and X (Twitter) sign-in
  • Buttons on sign-in, registration and checkout
  • Popup or full-page sign-in
See all features

Composer package softaware/module-social-login

Social Login for Magento 2 Free

Sign in with the account they already have

Every extra form field costs you customers. Social Login lets shoppers sign in and create an account with Google, Facebook or X in one click: on the sign-in page, the registration page, the checkout and anywhere else you place the buttons.

It is built for production stores: no third-party SDKs, every ID token fully validated, PKCE where the provider supports it, and careful rules for linking an existing account so a social sign-in can never be used to take over someone else's account. It works on Luma and Hyvä, per website and store view, and stores nothing but the link between the customer and the provider.

  • Sign up in one click

    Shoppers use the account they already have. No form to fill in and no new password to remember.

  • Sign in at checkout

    The buttons sit in the checkout sign-in popup and above the email field, right where shoppers decide.

  • Safe by design

    Every ID token is validated and accounts are only linked when the email address can be trusted.

All features

What is included

Providers

  • Google (OpenID Connect with PKCE)
  • Facebook (Graph API with appsecret_proof)
  • X / Twitter (OAuth 2.0 with PKCE, optional email)
  • Your own button labels and order
  • More providers with Social Login Pro

Where the buttons appear

  • Sign-in page
  • Create-account page
  • Authentication popup and checkout sign-in
  • Checkout email step (guests)
  • CMS widget and layout block

Accounts

  • New accounts in the customer group you choose
  • Optional welcome email
  • Link existing customers automatically or after their password
  • Existing customers only mode for B2B and trade shops
  • Works with Softaware Customer Approval

Customer experience

  • Popup or full-page sign-in
  • Icon and text or icon only, light or dark
  • Stay on the page, go to My Account or a custom URL
  • Connected Accounts in My Account
  • Short form when a provider gives no email or name

Security and privacy

  • Single-use state bound to the browser
  • ID tokens validated: signature, issuer, audience, expiry, nonce
  • Email addresses trusted only when verified
  • Confirmation email for unverified addresses
  • No access tokens stored; links deleted with the customer

Admin and developers

  • Linked Accounts grid and customer tab
  • Separate ACL permissions
  • CLI: list, unlink and self-test
  • Per website and store view settings
  • Extension point for more providers

Feature tour

Everything your shoppers and your team see

01 / 07

One click instead of a form

Buttons above the sign-in and registration forms. Icon and text or icon only, light or dark, in the order you choose.

02 / 07

Sign in without leaving the checkout

The "Sign In" popup on the checkout page and the authentication popup show the same buttons, so returning customers check out faster.

03 / 07

Native Hyvä templates

Alpine.js and Tailwind templates for Hyvä 1.3+, picked automatically. Luma, Blank and their child themes work out of the box.

04 / 07

Made for small screens

Buttons stack into full-width rows on phones, where typing an email address and a password is hardest.

05 / 07

Customers manage their connections

My Account › Connected Accounts lists the linked providers. Customers connect another one or disconnect one — never the last way to sign in.

06 / 07

One settings page, per store view

Choose where the buttons appear, how they look, what happens after sign-in and which customer group new accounts join.

07 / 07

The exact callback URL, ready to copy

Each provider shows the callback URL to register for the current store view, with short setup steps. Secrets are stored encrypted.

Live demo

Try it before you install it

A full Magento store with the module installed, on Luma and on Hyvä. The admin demo signs you in with one click.

Compatibility

Requirements and compatibility

Compatibility of Social Login for Magento 2
Magento2.4.7 – 2.4.9
Storefront themes Luma Blank Hyvä
PHP8.2 – 8.5
Latest version 1.3.0 · 7 Oct 2026
composer.json requires php ~8.2.0||~8.3.0||~8.4.0||~8.5.0 ext-json * ext-openssl * magento/framework ~103.0.7 softaware/module-core ^1.0 magento/module-backend * magento/module-checkout * magento/module-config * magento/module-customer * magento/module-store * magento/module-ui * magento/module-widget *

Installation

Up and running in minutes

Get it free, create a Composer key in your account, then in the root of your Magento project:

  1. 01Add the repository and your key (once per project)

    composer config repositories.softaware composer https://repo.softawarecommerce.com
    composer config --auth http-basic.repo.softawarecommerce.com PUBLIC_KEY PRIVATE_KEY
  2. 02Install the module

    composer require softaware/module-social-login
  3. 03Enable it

    bin/magento setup:upgrade
    bin/magento setup:di:compile
    bin/magento setup:static-content:deploy
    bin/magento cache:flush

    The last three are only needed in production mode.

Prefer a zip? Every version you are entitled to can be downloaded from My modules. More about Composer access

User guide

How to set up and use Social Login

For version 1.3.0. The same guide comes with the module, in docs/user-guide.md.

Let customers sign in and register with Google, Facebook and X (Twitter) in one click. This guide covers installation, configuration, provider setup and day-to-day use.

Sign-in page with social login buttons
Sign-in page with social login buttons

1. Requirements

MagentoOpen Source or Adobe Commerce 2.4.7 – 2.4.9
PHP8.2 – 8.5 with ext-openssl and ext-json
ThemesLuma, Blank and themes based on them; Hyvä 1.3+
Othersoftaware/module-core (installed automatically)

No provider SDKs or JWT libraries are installed: the module talks to the providers through Magento's own HTTP client and PHP's OpenSSL extension.

2. Installation

With Composer (recommended). Use the access keys from your account on shop.softawarecommerce.com:

composer config repositories.softaware composer https://repo.softawarecommerce.com
composer config --auth http-basic.repo.softawarecommerce.com PUBLIC_KEY PRIVATE_KEY
composer require softaware/module-social-login
bin/magento setup:upgrade
bin/magento setup:di:compile            # production mode only
bin/magento setup:static-content:deploy # production mode only
bin/magento cache:flush

On Hyvä, the module's templates are picked automatically. If you build Tailwind CSS from your theme, run your usual Hyvä build after installing so the button styles are included.

To update later: composer update softaware/module-social-login, then the same bin/magento commands.

3. Quick start (10 minutes)

  1. Stores > Configuration > Softaware > Social Login (also under Softaware > Social Login > Configuration).
  2. General > Enabled = Yes.
  3. Open a provider group, e.g. Google, set Enabled = Yes. Below the field you now see the callback URL for the current store view, for example https://www.example.com/sociallogin/auth/callback/provider/google/.
  4. Create an OAuth app at the provider (see section 5), register that callback URL exactly as shown, and copy the client ID and secret back into Magento.
  5. Save Config and flush the cache. The buttons appear on the sign-in and create-account pages.
Google provider settings with the callback URL
Google provider settings with the callback URL

4. Settings

General, display and account settings
General, display and account settings

All settings can be set per website and store view, so each domain can use its own provider apps.

General

SettingWhat it does
EnabledSwitches the whole module on or off. When off, no buttons are shown and the sign-in URLs return 404; existing links between customers and providers are kept.
Sign-in WindowFull-page redirect or Popup. A popup keeps the shopper on the current page; browsers that block it fall back to a redirect.
Button StyleIcon and text, or icon only.
Button ColourLight or dark.

Where to Show the Buttons

SettingWhat it does
Sign-in PageButtons above the sign-in form.
Create Account PageButtons above the registration form.
Authentication Popup and Checkout Sign-inLuma: the "Checkout using your account" popup and the "Sign In" link on the checkout page. Hyvä: the authentication popup.
Checkout Email StepButtons above the email field in the shipping step (guests only).

The buttons are also available as a CMS widget and a layout block (section 7).

Accounts

SettingWhat it does
Create New AccountsYes: shoppers without an account get one on their first social sign-in. No: only existing customers can sign in with a provider (useful for trade-only shops).
Existing Account with the Same EmailLink automatically when the provider has verified the address and is responsible for it, or Ask for the password every time. Other addresses always ask for the account password once.
Send Welcome Email to New CustomersSends the "Welcome Email (without password)" template.
Customer Group for Social Sign-upsThe store's default group or a fixed group.
After Sign-inStay on the current page, go to My Account, or a custom URL.

Providers

Each provider has Enabled, its credentials (stored encrypted), an optional Button Label (empty = "Continue with …") and a Sort Order for the button position.

5. Setting up the providers

Register the callback URL shown under the provider's Enabled field. With several store views or domains, register one callback URL per store view URL.

ProviderWhere to create the appWhat to enter in Magento
GoogleGoogle Cloud Console > APIs & Services > Credentials > Create OAuth client ID (Web application); add the callback under "Authorised redirect URIs".Client ID, Client Secret
FacebookMeta for Developers: add the Facebook Login product, enter the callback under "Valid OAuth Redirect URIs", request the email permission.App ID, App Secret, Graph API version
XX Developer Portal > User authentication settings: OAuth 2.0, type "Web App", callback URL.Client ID, Client Secret; "Request Email Address" only if the app has the email permission

6. What your customers see

Signing in or registering. The customer clicks a button, approves at the provider and is signed in. A new customer gets an account with the name and email from the provider. If the provider gives no email (X without the email permission) or no name, the customer fills in a short form once.

Existing customers. If a customer with the same email already exists, the identity is linked to that account (automatically or after the password, see Accounts). From then on the provider signs them in directly.

Unverified addresses. A new account made from an address the provider has not verified must be confirmed with Magento's confirmation email before it can be used, even if your store does not normally require confirmation.

Connected Accounts. Under My Account > Connected Accounts customers see their linked providers, connect another one or disconnect one. Disconnecting is refused when it would leave the account without any way to sign in (no password and no other provider).

Connected Accounts in My Account
Connected Accounts in My Account

Hyvä and mobile. The Hyvä templates are included and the buttons stack on small screens.

HyväMobile
Hyvä sign-in pageMobile sign-in page

7. Widget and layout block

CMS widget: Content > Widgets > Add Widget > "Softaware Social Login Buttons" (heading, style, colour), or Insert Widget in a page or block.

Layout XML:

<block class="Softaware\SocialLogin\Block\Buttons" name="my.social.buttons">
    <arguments>
        <argument name="place" xsi:type="string">widget</argument>
        <argument name="title" xsi:type="string">Sign in with</argument>
    </arguments>
</block>

The block picks the Luma or Hyvä template automatically and hides itself for signed-in customers in the browser, so it is safe on full-page-cached pages.

8. Admin tools

  • Softaware > Social Login > Linked Accounts: every link between a customer and a provider, with filters, last sign-in and number of sign-ins; remove links singly or in bulk.
  • Customers > edit customer > Social Login tab: the customer's links.
  • ACL: separate permissions for viewing links, removing links and the configuration.

Links of a provider that is not installed (for example after removing an add-on) stay visible with their provider code and can be removed; customers can remove them under Connected Accounts too.

9. Command line

bin/magento softaware:social-login:links [--customer=<id|email>] [--provider=google] [--limit=50]
bin/magento softaware:social-login:unlink <link_id>
bin/magento softaware:social-login:self-test [--accounts]

self-test lists the registered providers and checks the security pieces (PKCE, ID token validation including tampered, expired and wrong-audience tokens, return URL handling, email trust rules) without calling any provider. Installed add-ons such as Social Login Pro add their own checks. With --accounts it also checks the account-matching rules using temporary test customers that are deleted afterwards.

10. Privacy (GDPR)

  • The module stores only the link between a customer and a provider account (provider, provider user ID, email and display name at the provider, link date, last sign-in and number of sign-ins). No access tokens are kept.
  • Links are deleted together with the customer.
  • Pending sign-in data is deleted after 15 minutes by cron.
  • Mention the sign-in providers you use in your privacy policy.

11. Troubleshooting

ProblemSolution
The buttons do not appearCheck General > Enabled, the provider's Enabled, client ID and secret for the store view you are looking at, then flush the cache.
"redirect_uri_mismatch" or similar at the providerThe callback URL registered at the provider differs from the one shown in Magento (http vs https, www, store code, trailing slash). Copy it again exactly.
The popup does not openThe browser blocked it; the module falls back to a full-page redirect. Choose Full-page redirect if you prefer.
Customer is asked for the passwordExpected when the provider has not verified the address or is not responsible for it (see Accounts). It happens once; afterwards the provider signs them in directly.
Sign-in failsSee var/log/softaware_sociallogin.log for the technical reason (no secrets or tokens are logged).

12. More providers: Social Login Pro

The add-on Social Login Pro (softaware/module-social-login-pro) adds Sign in with Apple, Microsoft (Entra ID), LinkedIn, Amazon and GitHub. After installing it (composer require softaware/module-social-login-pro, then the bin/magento commands from section 2), the new providers appear as groups in the same configuration section and use all the settings in this guide. Its own user guide describes the provider setup.

13. Uninstall

bin/magento module:disable Softaware_SocialLogin
composer remove softaware/module-social-login
bin/magento setup:upgrade

If Social Login Pro is installed, remove it first (composer remove softaware/module-social-login-pro).

Customers created through social sign-in keep their accounts; they can set a password with "Forgot Your Password?".

Changelog

Release notes

1.3.0

Latest
  • Works with Social Login Pro (Apple, Microsoft, LinkedIn, Amazon and GitHub): the add-on's providers appear in the same configuration section, button rows, Connected Accounts page, admin grid and self-test.
  • Extension points for modules that add providers: button icons per provider code (icons argument of ViewModel\ProviderIcons), self-test checks (Model\SelfTest\CheckInterface, checks argument of the self-test command), and the callback URL comment for the admin (documented in the README together with the provider pool and the settings).
  • Links of providers that are not installed are handled safely: the Linked Accounts grid (column and filter), the customer tab and Connected Accounts show them with their provider code, customers and admins can remove them, and they do not count as a way to sign in when the customer disconnects another provider.
  • Self-test: lists the registered providers; ES256 ID token checks (valid token, tampered payload, algorithm whitelist); a rejected issuer for issuer patterns; the handling of links whose provider is not installed.
  • README, user guide and FAQ: provider extension points for developers, Social Login Pro; new screenshots.

1.2.1

Documentation

  • User guide (docs/user-guide.md): installation, every setting, provider setup, admin tools, CLI, privacy, troubleshooting.
  • FAQ (docs/faq.md) and screenshots (docs/images/).
  • README: demo links; compatibility corrected to Magento 2.4.7-2.4.9 and softaware/module-core ^1.0.

1.2.0

  • Requires softaware/module-core instead of softaware/module-base. The admin menu and ACL now sit under Softaware_Core::core ("Softaware"); roles that had access keep it (migrated by module-core). After updating all SoftAware modules, softaware/module-base can be removed.

1.1.0

  • Open redirect after sign-in fixed: return URLs such as https:///evil.example/ or https://evil.example\@your-shop/ passed the "own host" check (PHP and browsers read them differently) and sent the customer to another site after signing in. Return URLs are now parsed strictly (no backslashes, control characters, user info or empty hosts) before the host check.
  • Pre-account hijacking: an account created from an email address the provider has not verified (typed in by the shopper, Amazon, the test provider) now always needs Magento's email confirmation before it can be used, whether or not the store requires confirmation. Before, anybody could create an account in someone else's name through a provider without email (e.g. X) and keep access through the linked provider after the real owner had reset the password.
  • Linking to an existing account by email is limited to providers that are responsible for the address: Google only for Gmail and Google Workspace addresses (Google's own guidance), Facebook no longer (the Graph API has no verification flag). Everything else asks for the account password once, as before for unverified addresses. The same rule applies when an unconfirmed account is confirmed through a provider.
  • Accounts > Create New Accounts (default Yes). Set to No to let only existing customers sign in with a provider; shoppers without an account are asked to register first.
  • Hint on the "Connect your account" password step for customers who signed up with another provider and have no password.
  • Self-test: return URL (open redirect) checks and email trust rules per provider.
  • With "Require Emails Confirmation" switched on, a new social customer with an unverified address got the "welcome (no password)" email without a confirmation link and could never activate the account. The confirmation email is now sent.
  • With "Require Emails Confirmation" switched on, accounts created from a verified address stayed unconfirmed in the database (password sign-in later said "not confirmed"). They are now confirmed.
  • When another module refused the sign-in (e.g. Softaware Customer Approval: account waiting for approval), the customer saw two messages; now only the other module's explanation is shown. A refused sign-in is also detected when the session ends up with a different customer.

1.0.0

First release.

  • Sign-in and registration with Google, Sign in with Apple, Facebook, Microsoft (Entra ID), GitHub, LinkedIn, Amazon and X (Twitter), implemented directly on OAuth 2.0 / OpenID Connect (no provider SDKs).
  • State, nonce and PKCE (S256) where supported; ID token signature validation via JWKS (RS256/ES256) for Google, Microsoft, Apple and LinkedIn; browser-bound, single-use state stored server-side.
  • Apple: ES256 client secret from the .p8 key, form_post callback with session restore.
  • Buttons on the sign-in and create-account pages, the Luma authentication popup, the checkout sign-in and (optional) checkout email step, the Hyvä authentication popup, a CMS widget and a layout block. Icon+text or icon-only, light or dark, popup or full-page redirect.
  • Account matching: verified email links automatically (or asks for the password, configurable); missing email or name is asked for on a short form; new customers get a configurable group and optional welcome email.
  • My Account > Connected Accounts (connect, disconnect with lock-out protection).
  • Admin grid Softaware > Social Login > Linked Accounts, "Social Login" tab on the customer edit page.
  • CLI: softaware:social-login:links, softaware:social-login:unlink, softaware:social-login:self-test.
  • Luma and Hyvä templates; en_US and de_DE translations.
  • Test provider for development (developer mode only, disabled by default).

FAQ

Questions, answered

Something else on your mind? The developers who wrote the module answer before and after you buy.

Ask a question →

Already installed it? Open a support ticket

Which providers are supported?

Google, Facebook and X (Twitter). Each one can be switched on separately, per website or store view.

Can I offer Apple, Microsoft, LinkedIn, Amazon or GitHub as well?

Yes, with the add-on Social Login Pro. It adds these five providers to the same configuration section, buttons, Connected Accounts page and admin tools; everything described here applies to them too.

Does it work with Hyvä?

Yes. Hyvä templates are included (Hyvä 1.3+, tested with 1.5). On the Hyvä checkout the Luma checkout fallback is used, so the checkout buttons are the Luma ones.

Does it install third-party SDKs?

No. OAuth 2.0 and OpenID Connect are implemented on Magento's HTTP client and PHP's OpenSSL extension, so there are no extra libraries to keep up to date or to conflict with other extensions.

Where can the buttons appear?

On the sign-in page, the create-account page, the authentication popup and the checkout sign-in, above the email field in checkout (guests), anywhere as a CMS widget, and anywhere in your layout as a block.

What happens if a customer already has an account with the same email?

The provider is linked to that account. If the provider has verified the address and is responsible for it (for example Gmail addresses at Google), this happens automatically; otherwise, or if you choose so, the customer enters their account password once. After that the provider signs them in directly.

Can I allow only existing customers to sign in with a provider?

Yes: set Create New Accounts to No. Shoppers without an account are asked to register first. This is useful for B2B and trade-only shops.

Does it work with customer approval?

Yes, with Softaware Customer Approval: social sign-ups get an approval status like any other registration, and pending or rejected customers are not signed in.

What if the provider does not give an email address?

X never returns one unless your app has the email permission. The customer then enters an email address once; an account created from a typed-in address must be confirmed by email before it can be used.

Can customers remove a connection?

Yes, under My Account > Connected Accounts. The module refuses to remove the last way to sign in (no password and no other provider). Admins can remove links under Softaware > Social Login > Linked Accounts.

Is it GDPR friendly?

Only the link between the customer and the provider account is stored, no access tokens. Links are deleted with the customer, and pending sign-in data is deleted after 15 minutes.

How is it protected against account takeover?

Every sign-in uses a single-use state bound to the browser, PKCE where the provider supports it, and full ID token validation (signature, issuer, audience, expiry, nonce). Email addresses are only trusted when the provider has verified them, and accounts from unverified addresses must be confirmed by email first. Return URLs are restricted to your own store.

Can I use different provider apps for each domain?

Yes. All settings, including the credentials, can be set per website and store view. Register one callback URL per store view URL at the provider.

Can I add another provider?

Yes, developers can implement ProviderInterface (or extend AbstractOidcProvider) and register it in di.xml; icons, settings and self-test checks have extension points too. See the README.

What happens to links of a provider that is not installed (for example after removing an add-on)?

They are kept and shown with their provider code in the admin and under Connected Accounts, where they can be removed. They are not counted as a way to sign in, so customers are never left without one.

Which Magento and PHP versions are supported?

Magento Open Source and Adobe Commerce 2.4.7 – 2.4.9, PHP 8.2 – 8.5.

Support

Help from the developers who wrote it

Social Login Pro

Need Apple, Microsoft, LinkedIn, Amazon or GitHub?

Social Login Pro adds five more providers to the same buttons, settings and account rules.

See Social Login Pro →
FeatureFreePro
Google, Facebook and X
Apple (Sign in with Apple)
Microsoft personal and work accounts
LinkedIn, Amazon and GitHub
All placements, popup, widget and layout block
Account linking rules and Connected Accounts
Hyvä and Luma

From the blog

Guides and articles

  • How to check (and fix) Hyvä compatibility for a Magento extension

    Why Luma extensions break on a Hyvä storefront, how to check an extension before you buy or migrate, and the four ways to fix it: vendor support, a compatibility module, the Luma theme fallback or your own compat module.

  • How do you install a Magento 2 extension with Composer?

    A practical walkthrough of installing, updating and removing Magento 2 extensions with Composer, including private repositories, auth.json and the errors you are most likely to meet.

  • Magento 2 extension or custom module: how to decide

    Buy when the requirement is common and a well-built extension fits your processes. Build when the logic is unique to your business or ties into your own systems. Here is how to tell the difference.

  • How to get social login credentials for Magento 2

    Where to create each sign-in app, which callback URL and scopes to use, what each provider charges or reviews, and where the keys go in the Magento admin.