App Store 4.8 rejection: Login services

By The Draftbit team · Updated
Sources checked

This guide is for iPhone and iPad apps using third-party or social login for the user's primary app account.

You’ve added Google login, and Apple asks for another sign-in option. Guideline 4.8 doesn’t apply to every app with an account. Start with how the user creates or authenticates their primary account in your app.

Apple’s current rule requires an equivalent login option in covered cases. That option must limit collection to name and email, support keeping email private, and avoid collecting app interactions for advertising without consent. Sign in with Apple is a way to provide those capabilities; an ordinary email form doesn’t automatically meet them all.

Check whether the rule covers your login

If social login creates the account people use to access your app’s features, assess 4.8. If someone connects another service after signing in, determine whether that connection is authentication for your app or access to that service’s content. Explain the distinction in your review notes.

The documented exceptions include exclusively using your own account system, required existing education or enterprise accounts, certain citizen-ID systems, clients for a specific third-party service, and qualifying alternative-marketplace login. Read the exact exception before relying on it. A “business app” that lets anyone create a consumer account isn’t automatically an enterprise-login exception.

We’d map the actual screens before changing anything:

  1. How does a new user create their primary account?
  2. Which login choices are available afterward?
  3. Does each choice reach the same app features?
  4. Which specific exception, if any, describes this flow?

If you add another login option

Test account creation, returning sign-in, cancellation, and the email-private choice. Check how your backend identifies users and links accounts. A hidden email address shouldn’t prevent someone from reaching the feature they signed up to use.

Use separate test identities to check whether two login methods accidentally create duplicate app accounts. Have your developer design account linking with proof of account ownership; matching an unverified email isn’t enough to establish that the accounts belong to the same person.

Also test account deletion, including Apple’s token-revocation requirement when you use Sign in with Apple.

Reply with the flow the reviewer can inspect

If you’re relying on an exception, identify it and give steps showing why it applies. If you added an option, name the new build and explain where it appears. Provide working review access for every protected feature.

Before resubmitting, start signed out and follow the same instructions yourself. An extra button on the screen is only the start; the resulting account needs to work.

Messages this guide can help with

4.8 login services; Google login rejected; Sign in with Apple required; own email login; equivalent login option; App Store 4.8 rejection; app store 4.8 denial; Guideline 4.8; Login services

Official sources

We checked these instructions against the sources below. The console layout may change, and your review decision may call for different steps.

Your next stepSubmit your iPhone or iPad app for review