Reference library · App Review

Guideline 4.8 Login Services: when you need Sign in with Apple, and when you don't

If your app offers Google or Facebook sign-in, you need one more option. It doesn't have to be Apple's — but in practice it usually is.

Guideline 4.84. Design · Login ServicesApple text last updated June 8, 2026
Updated 6 min read

Checked against Apple's App Review Guidelines (last updated June 8, 2026), the Sign in with Apple Human Interface Guidelines and Apple's account deletion guidance, on Oct 5, 2026.

The short answer

Guideline 4.8 says that if your app uses a third-party or social login such as Google or Facebook for the user's primary account, it must also offer an equivalent login that limits data to name and email, lets users hide their email, and doesn't track them for ads without consent. Sign in with Apple meets all three. Apps using only their own email login are exempt.

Triggered by
Third-party login
Google, Facebook, X, LinkedIn, Amazon, WeChat
Equivalent login must
3 features
Name and email only, hidden email, no ad tracking
Exemptions
5
Including own-account-only apps
Apple-only rule removed
Jan 25, 2024
Any login with the three features qualifies

01What Guideline 4.8 requires

Apps that use a third-party or social login service (such as Facebook Login, Google Sign-In, Log in with X, Sign In with LinkedIn, Login with Amazon, or WeChat Login) to set up or authenticate the user’s primary account with the app must also offer as an equivalent option another login service with the following features:
— App Store Review Guidelines, 4.8
  1. It "limits data collection to the user’s name and email address".
  2. It "allows users to keep their email address private as part of setting up their account".
  3. It "does not collect interactions with your app for advertising purposes without consent".

Until January 2024 the rule named Sign in with Apple specifically. On January 25, 2024 Apple edited it to "require an additional login service with certain privacy features" instead. In principle any provider with all three features qualifies. In practice Sign in with Apple is the option reviewers recognize instantly, and its Hide My Email relay is the most obvious way to satisfy the second point.

The app uses a third-party login service like Google or Facebook, but does not appear to offer an equivalent login option with Sign in with Apple.
— App Review rejection under 4.8, posted on Apple Developer Forums, October 2024
The finding, in one line
According to ASOitis, the cheapest way to never see a Guideline 4.8 rejection is to launch with email and Sign in with Apple only: the rule is triggered by adding Google or Facebook sign-in, not by having accounts at all.

02Do you need it? A quick decision table

When Guideline 4.8 applies to your sign-in screen
Your sign-in options4.8 applies?What to do
Email and password (your own system) onlyNoNothing — the guideline exempts apps that only use your own account system
No accounts at allNoNothing
Email + GoogleYesAdd Sign in with Apple, or another login with all three privacy features
Google onlyYesAdd Sign in with Apple; consider adding email too
Email + Sign in with AppleNoAlready compliant; the rule is about third-party logins
Google used only to connect Google Drive, not to sign inNoThe rule covers the user's primary account, not integrations
Apple defines the primary account as the one users "establish with your app for the purposes of identifying themselves, signing in, and accessing your features and associated services."

03The five exemptions

Another login service "is not required" in these cases, paraphrased from the guideline:

  • Your own accounts only. The app "exclusively uses your company’s own account setup and sign-in systems."
  • Alternative marketplaces. An alternative app marketplace, or an app distributed from one, using a marketplace-specific login.
  • Education, enterprise and business apps that require signing in with an existing school or company account.
  • Government or industry-backed electronic ID used to authenticate users.
  • Clients for a specific third-party service, where users must sign in to their mail, social media or other account directly to get their content — a Mastodon or Gmail client, for example.

The last one is narrower than it looks. A habit tracker that offers "Continue with Google" for convenience is not a client for Google's service; it just uses Google as a login. It needs the equivalent option.

04The design mistakes that get rejected anyway

Adding the button isn't the end of it. Apps that offer Sign in with Apple are also checked against its design requirements, and the most common failure is asking again for what Apple already provided:

Your app requires users to provide their name and/or email address after using Sign in with Apple. This information is already provided by the Authentication Services framework.
— App Review rejection, posted on Apple Developer Forums, March 2025

Gets rejected

  • A "complete your profile" screen asking for email right after Sign in with Apple
  • Refusing relay addresses: "please choose Share My Email to continue"
  • An Apple button smaller than the Google button, or below the fold
  • Asking for a password after Sign in with Apple

Passes

  • Accepting the private relay email as the account email
  • Asking only for things Apple doesn't provide, such as a username, and making it optional where you can
  • Equal-size buttons, all visible without scrolling
  • Storing the name on first sign-in — Apple only sends it once

Apple's Human Interface Guidelines put the size rule plainly: "Make a Sign in with Apple button no smaller than other sign-in buttons, and avoid making people scroll to see the button." They also say to avoid asking for a personal email address when people supply a private relay address.

05Sign in with Apple and account deletion

Every app that lets people create an account must also let them delete it, under Guideline 5.1.1. Sign in with Apple adds one step. Apple's account deletion guidance says: "Apps that support Sign in with Apple should use the Sign in with Apple REST API to revoke user tokens."

That call happens on your server, so plan for it before launch. If you use a backend such as Firebase or Supabase, check whether its delete-user function revokes the Apple token or whether you have to call Apple's endpoint yourself.

06Fixing a 4.8 rejection and replying

  1. Add Sign in with Apple

    Enable the capability in Xcode and the identifier in your developer account, and use the system button from AuthenticationServices.

  2. Give it equal weight

    Same size as the other sign-in buttons, visible without scrolling, on every screen where the others appear — including sign-up.

  3. Handle relay emails

    Treat @privaterelay.appleid.com addresses as normal emails. If you send email, register your sending domain for Apple's relay service.

  4. Remove the follow-up form

    Don't ask for the name or email again after sign-in.

  5. Wire up token revocation

    Make account deletion revoke the Apple token on your server.

Reply in App Store Connect — Guideline 4.8text
Hello App Review team,

Thank you for the feedback on Guideline 4.8.

Build [number] adds Sign in with Apple as an equivalent option to
Google Sign-In:
- It appears on the welcome and sign-up screens, the same size as the
  Google button and visible without scrolling.
- The app accepts private relay email addresses and does not ask for
  name or email after sign-in.
- Deleting the account (Settings > Account > Delete) revokes the
  Sign in with Apple token.

Thank you,
[Name]

Frequently asked questions

Is Sign in with Apple mandatory?

Only if your app uses a third-party or social login such as Google or Facebook for the user's primary account, and even then any login with the same three privacy features qualifies. Apps that use only their own email and password are exempt.

Can I offer email login instead of Sign in with Apple next to Google?

Not usually. The equivalent option must let users keep their email address private, which a standard email and password login doesn't do. Sign in with Apple's Hide My Email covers it, which is why it's the usual fix.

Can I ask for the user's email after they use Sign in with Apple?

No. Apple rejects apps that require users to provide their name or email after Sign in with Apple, because the framework already supplies them. Accept the private relay address if the user chose to hide their email.

Does 4.8 apply if Google is only used to connect Google Drive?

No. The guideline covers logins used to set up or authenticate the user's primary account. Connecting a third-party service for its data, after the user has signed in another way, is not a login service in this sense.

What happens to Sign in with Apple when a user deletes their account?

Apple's account deletion guidance says apps that support Sign in with Apple should use the Sign in with Apple REST API to revoke user tokens. Do it on your server as part of the deletion flow.

Where to go next

Sources

  1. App Store Review Guidelines — 4.8 Login Services — Apple Developer
  2. Updated App Store Review Guidelines (Jan 25, 2024) — Apple Developer News
  3. Human Interface Guidelines — Sign in with Apple — Apple Developer
  4. Offering account deletion in your app — Apple Developer
  5. Forum: no equivalent login option (4.8) — Apple Developer Forums
  6. Forum: asking for name or email after Sign in with Apple — Apple Developer Forums

Published Oct 5, 2026 · last checked Oct 5, 2026. Found something out of date? Tell us and we'll fix it within a day. Machine-readable version: /app-review/guideline-4-8-login-services.md