Skip to main content
Drupal is a registered trademark of Dries Buytaert
Release: Configuration Language Lock 1.0.2 Minor update available for module config_language_lock (1.0.2). Release: Canvas Override 1.0.1 Minor update available for module canvas_override (1.0.1). Release: Media Remote Image 8.x-1.2 Minor update available for module media_entity_remote_image (8.x-1.2). Release: IDNA Convert Service (punycode) 2.0.4 Minor update available for module idna (2.0.4). Release: Bootstrap Cloud 7.1.3 Minor update available for theme bootstrap_cloud (7.1.3). Release: Token Browser 1.0.2 Minor update available for module token_browser (1.0.2). Release: Varbase Project 11.0.8 Minor update available for module varbase_project (11.0.8). Release: Media Remote Image 2.0.0-beta1 First beta version released for module media_entity_remote_image (2.0.0-beta1). Usage Milestone: Term CSV Export Import Module term_csv_export_import crossed 1,000 active installs. Security Coverage: Module Scout Module module_scout now has official Drupal security advisory coverage.

SSO Connector Social

Security covered Drupal 11 · not 10
View on drupal.org

This module allows users to log in to your Drupal site using social accounts like Google, Microsoft, or Facebook, while still maintaining control of their Drupal accounts and integration with SSO Connector. It supports pre-configured providers as well as custom OAuth2/OIDC identity platforms, and offers features for linking social identities to existing Drupal users and synchronizing profile data.

Lets anonymous visitors log in or register with social and identity providers over OAuth 2.0 and OpenID Connect. It ships provider plugins for Google, Microsoft (Entra ID), Okta, GitHub, LinkedIn, GitLab, Facebook, Discord, Twitter/X and a configurable generic OAuth2/OIDC provider, plus account linking/unlinking, an optional login block, optional auto-registration, and optional avatar and display-name synchronisation.

Features

  • Ten provider plugins plus a configurable generic OAuth2/OIDC provider.
  • OIDC id_token verification (JWKS signature plus iss/aud/exp/nonce) for Google, Microsoft (Entra ID), Okta, and the generic provider when an issuer is configured.
  • Providers that do not issue an OpenID Connect id_token (GitHub, LinkedIn, GitLab, Facebook, Discord, Twitter/X) fall back to the provider's userinfo endpoint over TLS.
  • PKCE for every provider that supports it.
  • Account linking with a password-confirmation step and a short-lived, server-side pending link.
  • email_verified is never assumed — for example GitHub is treated as verified only when the primary email is confirmed via the API.
  • Optional avatar sync with an SSRF-guarded, size-capped, HTTPS-only fetch, and optional display-name sync.
  • Themeable social login block for anonymous users.

Requirements

  • Drupal core ^11.2 || ^12
  • PHP >= 8.1
  • SSO Connector ^1.0
  • firebase/php-jwt (pulled in automatically by Composer)

Installation

composer require drupal/sso_connector_social
drush en sso_connector_social

Part of the SSO Connector bundle

Requires SSO Connector (core). See the core project for the full suite.

Depends on

Dependencies of the latest stable release

  • SSO Connector
  • block Drupal core
  • file Drupal core
  • help Drupal core
  • image Drupal core
  • user Drupal core

Required by

Tracked projects that depend on this one

No tracked projects depend on this one yet.

Activity

Tracked releases
4
Tracked since
Apr 2026
Latest release
1 month ago
Releases (12 mo)
4 ▲ from 0
Maintenance
Active

Release Timeline

Releases

Version Type Core Release date
1.0.1 Stable 11 Jul 21, 2026
1.0.0 Stable 11 Jul 18, 2026
1.0.0-beta1 Pre-release 10–11 Apr 26, 2026
1.0.x-dev Dev 11 Apr 26, 2026