2
1 Comment

The best dev auth setup is the one you delete by changing three variables.

A common MVP mistake: one OAuth integration for local dev, a different shape for staging, another for production.

Better pattern:
-> Same authorization code flow in code
-> Same env variable names (OAUTH_ISSUER, OAUTH_CLIENT_ID, OAUTH_CLIENT_SECRET, plus GOOGLE, GITHUB, etc. for multi-IdP)
-> Different values per environment

In dev, point at a dummyoauth issuer under /p/your-project or /p/your-project/emulate/google.

In prod, point at Google (or GitHub, etc.) with real credentials.
Your redirect handler, session logic, and token exchange stay put.

That is the whole “prototype then swap credentials” story. Mock IdP for dev and tests.

posted toAvatar for product DummyOAuth
DummyOAuth
  1. 1

    This looks great, I had a look at the website too. This would definetely help me test out my OAuth workflow for the services I build.