> ## Documentation Index
> Fetch the complete documentation index at: https://docs.capedigital.co.ke/llms.txt
> Use this file to discover all available pages before exploring further.

# Sign in with Apple (direct identity-token verification)

> Verify an Apple identity token directly and issue session tokens.

Not brokered through Keycloak — see
authentication/services/apple_identity_token.py for why (Keycloak's
generic OIDC broker can't accept Apple's mandatory form_post callback).
Shared by the web BFF and, later, the iOS app: both just need to hand us
the identity token Apple already gave them.



## OpenAPI

````yaml /openapi/user.yaml post /api/v1/auth/social/apple
openapi: 3.0.3
info:
  title: CapeMedia User Service API
  version: 1.0.0
  description: |2-

        **CapeMedia User Service API** - Comprehensive user service and management system.

        ## Authentication
        This API uses **JWT Bearer tokens** for authentication.

        1. Login via `/api/v1/auth/login` to obtain tokens
        2. Include the access token in the `Authorization` header: `Bearer <access_token>`
        3. Refresh expired tokens via `/api/v1/auth/refresh-token`

        ## Versioning
        The API uses URL path versioning (e.g., `/api/v1/`, `/api/v2/`).
        Current version: **v1**
        
  contact:
    name: API Support
    email: support@capemedia.co.ke
  license:
    name: Cape Media
servers:
  - url: https://api.diginacape.co.ke/acl
    description: Production
  - url: http://sapi.diginacape.co.ke/acl
    description: Local development
security: []
paths:
  /api/v1/auth/social/apple:
    post:
      tags:
        - Authentication
      summary: Sign in with Apple (direct identity-token verification)
      description: |-
        Verify an Apple identity token directly and issue session tokens.

        Not brokered through Keycloak — see
        authentication/services/apple_identity_token.py for why (Keycloak's
        generic OIDC broker can't accept Apple's mandatory form_post callback).
        Shared by the web BFF and, later, the iOS app: both just need to hand us
        the identity token Apple already gave them.
      operationId: auth_social_apple
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/AppleSignInRequest'
          application/x-www-form-urlencoded:
            schema:
              $ref: '#/components/schemas/AppleSignInRequest'
          multipart/form-data:
            schema:
              $ref: '#/components/schemas/AppleSignInRequest'
        required: true
      responses:
        '200':
          description: No response body
      security:
        - bearerAuth: []
        - {}
components:
  schemas:
    AppleSignInRequest:
      type: object
      properties:
        identity_token:
          type: string
          minLength: 1
          description: >-
            Apple's signed identity token (id_token) — from the web form_post
            callback or the iOS AuthenticationServices SDK.
        realm:
          type: string
          minLength: 1
          default: capedigi
          description: Keycloak realm name. Defaults to the consumer realm.
      required:
        - identity_token
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: 'Enter your JWT token in the format: Bearer <token>'

````