Implementing User Authentication with Sign in with Apple
At a glance
| Item | Summary |
|---|---|
| Purpose | Provide a way for users of your app to set up an account and start using your services. |
| App architecture | A Swift sample with the source-visible chain AppDelegate → LoginViewController → AuthenticationServices APIs. |
| Main patterns | View-controller organization, Delegate or data-source callbacks |
| Project style | 4 scanned source file(s) across Swift, organized around ranked entry, type, and file boundaries. |
| Execution model | Source-visible boundaries: DispatchQueue.main.async; none alone proves a background thread. |
| State/event model | No structured observation or publisher-scheduling marker indexed. |
| Key frameworks/packages | AuthenticationServices, UIKit, Foundation; these are source dependencies, not architecture labels. |
Project structure
Source bundle/
├── Juice/
│ ├── AppDelegate.swift
│ ├── LoginViewController.swift
│ ├── ResultViewController.swift
│ ├── Supporting Files/
│ │ ├── KeychainItem.swift
│ │ ├── Base.lproj/
│ │ │ └── LaunchScreen.storyboard
│ │ └── Info.plist
│ ├── Base.lproj/
│ │ └── Main.storyboard
│ └── Juice.entitlements
├── Configuration/
│ └── SampleCode.xcconfig
└── Juice.xcodeproj/
├── .xcodesamplecode.plist
└── project.pbxproj
Structure observations
- Architecturally prominent files are ranked from entry points and role-named declarations; resource-only paths are omitted.
- Primary languages: Swift.
- The verified tree contains 7 project/configuration file(s) and 5 source declaration(s).
Overall architecture
flowchart LR
N1["AppDelegate"]
N2["LoginViewController"]
N3["AuthenticationServices APIs"]
N1 --> N2
N2 --> N3
Reference code
Juice/AppDelegate.swift:11 — architecture anchor
@UIApplicationMain
class AppDelegate: UIResponder, UIApplicationDelegate {
var window: UIWindow?
/// - Tag: did_finish_launching
func application(_ application: UIApplication, didFinishLaunchingWithOptions launchOptions: [UIApplication.LaunchOptionsKey: Any]?) -> Bool {
let appleIDProvider = ASAuthorizationAppleIDProvider()
appleIDProvider.getCredentialState(forUserID: KeychainItem.currentUserIdentifier) { (credentialState, error) in
switch credentialState {
case .authorized:
break // The Apple ID credential is valid.
case .revoked, .notFound:
// The Apple ID credential is either revoked or was not found, so show the sign-in UI.
DispatchQueue.main.async {
self.window?.rootViewController?.showLoginViewController()
}
default:
break
}
}
return true
}
}Interpretation
The arrows summarize the source-visible entry, role-named types or folders, and framework direction; when nodes come from structural folders, the sequence is a high-level interpretation rather than proof that every adjacent node calls the next. Ownership is claimed only where the next section cites a stored property or assignment. The diagram is intentionally limited to the dominant path into Authentication Services.
Ownership and state
classDiagram
AppDelegate o-- UIWindow : window
LoginViewController o-- UIStackView : loginProviderStackView
ResultViewController o-- UILabel : userIdentifierLabel
ResultViewController o-- UILabel : givenNameLabel
Ownership evidence
Juice/AppDelegate.swift:14 — stored dependency or nearest verified ownership anchor
@UIApplicationMain
class AppDelegate: UIResponder, UIApplicationDelegate {
// ...
var window: UIWindow?
// ...
}| Owner | Object or state | Relationship | Mutation authority |
|---|---|---|---|
AppDelegate |
UIWindow (window) |
stores or receives | App/module collaborators |
LoginViewController |
UIStackView (loginProviderStackView) |
holds a non-owning reference | The referenced object’s lifecycle is owned elsewhere |
ResultViewController |
UILabel (userIdentifierLabel) |
holds a non-owning reference | The referenced object’s lifecycle is owned elsewhere |
ResultViewController |
UILabel (givenNameLabel) |
holds a non-owning reference | The referenced object’s lifecycle is owned elsewhere |
Composition arrows indicate a source-visible construction expression or locally owned value state; aggregation means the owner stores or receives a dependency without proving exclusive lifetime ownership.
Concurrency, scheduling, and thread safety
Evidence limit: actor isolation, async/await, or Task creation does not by itself prove background-thread execution; Sendable conformance alone does not prove thread-safe mutation.
| Concern | Source mechanism | Verified placement or handoff | Evidence |
|---|---|---|---|
| Queue scheduling | DispatchQueue.main.async |
The source addresses the main dispatch queue. | Juice/AppDelegate.swift:25 |
@MainActor/MainActor.run, DispatchQueue.main, and RunLoop.main are reported as distinct isolation, queue, and event-loop mechanisms. A plain Task is kept separate from Task.detached; neither is labeled as a background thread.
Reference code
Juice/AppDelegate.swift:25 — representative execution boundary
DispatchQueue.main.async {
self.window?.rootViewController?.showLoginViewController()
}State propagation, frameworks, and dependencies
Evidence limit: an import proves a source-level compilation dependency at the cited line; it does not prove runtime use, architectural adoption, or whether a Swift package is a direct application dependency.
| Category | Mechanism or module | Verified role | Evidence |
|---|---|---|---|
| Source import | AuthenticationServices |
The cited file imports this module; runtime use and architectural role are not inferred. | Juice/AppDelegate.swift:9 |
| Source import | UIKit |
The cited file imports this module; runtime use and architectural role are not inferred. | Juice/AppDelegate.swift:8 |
| Source import | Foundation |
The cited file imports this module; runtime use and architectural role are not inferred. | Juice/Supporting Files/KeychainItem.swift:8 |
receive(on:) describes downstream delivery scheduling, while subscribe(on:) describes upstream subscription/request/cancel scheduling. An import Combine alone establishes neither behavior nor a Store, reducer, Redux, or other application architecture.
Class and protocol design
Juice/AppDelegate.swift:12 — representative type boundary
@UIApplicationMain
class AppDelegate: UIResponder, UIApplicationDelegate {
// ...
var window: UIWindow?
// ...
}| Type | Responsibility | Depends on or conforms to |
|---|---|---|
AppDelegate |
Receives callback-driven events | UIResponder, UIApplicationDelegate |
LoginViewController |
View lifecycle, callbacks, and feature coordination | UIViewController |
ResultViewController |
View lifecycle, callbacks, and feature coordination | UIViewController |
KeychainItem |
Represents feature data | Concrete collaborators/imported frameworks |
KeychainError |
Represents feature failure conditions | Error |
No local protocol conformance is claimed as protocol-oriented design; external framework conformances are listed only as dependencies.
Access control
| Symbol | Access | Verified effect | Likely rationale |
|---|---|---|---|
saveUserInKeychain (Juice/LoginViewController.swift:93) |
private |
Use is restricted to the lexical declaration and same-file extensions allowed by Swift. | Inference: hide an implementation step that is not part of the collaboration surface. |
showResultViewController (Juice/LoginViewController.swift:101) |
private |
Use is restricted to the lexical declaration and same-file extensions allowed by Swift. | Inference: hide an implementation step that is not part of the collaboration surface. |
showPasswordCredentialAlert (Juice/LoginViewController.swift:120) |
private |
Use is restricted to the lexical declaration and same-file extensions allowed by Swift. | Inference: hide an implementation step that is not part of the collaboration surface. |
account (Juice/Supporting Files/KeychainItem.swift:24) |
private(set) |
Read access follows the declaration; writes remain in the private scope. | Inference: allow observation while reserving invariant-changing writes for the owner. |
Reference code
Juice/LoginViewController.swift:93 — representative boundary
private func saveUserInKeychain(_ userIdentifier: String) {
// ...
try KeychainItem(service: "com.example.apple-samplecode.juice", account: "userIdentifier").saveItem(userIdentifier)
// ...
}Swift declarations without a modifier are internal; explicit private, fileprivate, private(set), public, or open entries above are interpreted by language semantics. Objective-C/C samples instead rely on header and implementation boundaries, which are not equivalent to Swift lexical privacy.
Logic ownership and placement
| Logic | Owning type or file | Placement rationale |
|---|---|---|
| View lifecycle, callbacks, and feature coordination | LoginViewController, ResultViewController |
The source’s Controller suffix makes this role explicit. |
| Receives callback-driven events | AppDelegate |
The source’s Delegate suffix makes this role explicit. |
Design patterns
| Pattern | Source evidence | Purpose or tradeoff |
|---|---|---|
| View-controller organization | Juice/LoginViewController.swift:11 |
A controller is the verified coordination boundary; this is MVC-style only where a separate model is present. |
| Delegate or data-source callbacks | Juice/AppDelegate.swift:12 |
Callback protocols invert event delivery back into the sample’s owner. |
Naming conventions
- Types: Controller: LoginViewController, ResultViewController; Delegate: AppDelegate.
- Protocols: no local protocol declaration in the scanned source.
- Methods:
application,viewDidLoad,viewDidAppear,setupProviderLoginView,performExistingAccountSetupFlows,handleAuthorizationAppleIDButtonPress,authorizationController,saveUserInKeychain. - Files:
Juice/AppDelegate.swift,Juice/LoginViewController.swift,Juice/ResultViewController.swift,Juice/Supporting Files/KeychainItem.swift.
Architecture takeaways
AppDelegateis the main source-visible entry or composition anchor for this sample.- Framework work reaches AuthenticationServices, UIKit through a deliberately small high-level chain; the detailed API graph remains inside the cited implementation files.
- Stored-property evidence identifies lifecycle collaboration; it does not by itself prove exclusive object ownership.
- Access-control conclusions separate verified language visibility from the likely design rationale.
- The source does not justify labeling the design protocol-oriented.
Source map
| Source file | Relevant symbols |
|---|---|
Juice/AppDelegate.swift |
Cited implementation, AppDelegate, DispatchQueue.main.async, AuthenticationServices, UIKit |
Juice/LoginViewController.swift |
Cited implementation, LoginViewController |
Juice/Supporting Files/KeychainItem.swift |
Cited implementation, Foundation, KeychainItem, KeychainError |
Juice/ResultViewController.swift |
ResultViewController |