logoalt Hacker News

impulser_yesterday at 9:10 PM2 repliesview on HN

Majority of apps are B2C apps, they don't need any of this.

All you need is Apple and Google Oauth.


Replies

sandeepkdyesterday at 11:28 PM

If you are just starting out its probably a good idea. Think about the use case when google bans either your app or bans your app user?

show 1 reply
mooredsyesterday at 10:13 PM

It depends on your use case.

If you are a B2C app, you are probably more concerned about:

- social providers (Apple and Google being the big ones, but others could play a role--FB or Tiktok for example)

- easy registration (but not too easy, you want to avoid bot spam)

- self-service account management (updating profile fields, consents [CCPA, GDPR, others], resetting passwords

- single sign-on between your apps (if you have multiple)

- language support (for your backend, and mobile/web front end)

- cost

- possibly MFA, possibly passkeys