GitHub Login is not yet compatible with Blesta 6 - we're working on it.

GitHub Login

The GitHub Login plugin allows clients to authenticate using their GitHub accounts, streamlining the login process and improving convenience.

From £4.99 - View Pricing

Features

What GitHub Login gives you

Per-Company Configuration

Configure it independently for each brand on a multi-company install, so every company runs with its own settings.

Fully Translatable

Every staff and client label ships in editable language files, ready to translate into any language or reword to match your brand.

Built-In Demo Mode

A built-in demo mode runs the whole extension from bundled sample data, so you can trial every screen and action before you have an account or API key.

Sign In With an Account They Already Have

Clients reach your client area with an account they already use elsewhere instead of another password to remember, on your existing login page with no template edits.

Single-Use Sign-In Links

Each GitHub sign-in is tied to the browser that started it and works only once, so a link copied out of someone's address bar, history or logs cannot be replayed to get into their account.

Only Their Email Is Requested

The GitHub authorization screen asks your client for nothing but their email addresses, with no access to their repositories or their code and no permission to change anything, so signing in is an easy yes.

Straightforward GitHub App Setup

Enter your GitHub application's client ID and client secret, and the exact authorization callback URL to paste back into GitHub is shown for you on the settings page, so the two sides cannot drift out of sync.

Never Locks Anyone Out

If no client account matches, or GitHub cannot complete the sign-in, the visitor is returned to the normal login page with a plain-language explanation and can log in with their email address and password as usual.

Two-Factor Accounts Stay Protected

A client who has two-factor authentication switched on is never waved past it by the GitHub button. They are asked to sign in with their email address and password instead, so their second factor is still required every time.

Verified Email Addresses Only

Only email addresses GitHub itself has verified are used to identify the client, and the verified primary address is tried first, so an unverified address added to someone's GitHub account can never be used to reach another person's client account.

Signs In the Matching Client Account

The verified GitHub address is matched to the client account that already uses it and that client is logged straight in, with the sign-in recorded in Blesta exactly like a normal login. Only client accounts are signed in this way, so a staff login can never be created from the client area.

Blesta Club Logo

GitHub Login

Let clients into your client area with the GitHub account they already use, matched only to email addresses GitHub has verified.

What it does

Another password is one more thing standing between a client and paying their bill. GitHub Login adds a "Login with GitHub" button to your existing client login page, so a client can sign straight in with the GitHub account they already have. Blesta matches the GitHub account to a client by email address - using only addresses GitHub itself has verified - logs the matching client in, and records it exactly like a normal login. Nothing is asked of GitHub beyond the client's email addresses: no repository access, no code access, nothing that can be changed on their behalf.

Key features

  • Sign In With an Account They Already Have: Clients reach your client area with an account they already use elsewhere, on your existing login page with no template edits.
  • Verified Email Addresses Only: Only email addresses GitHub itself has verified are used to identify the client, so an unverified address someone added to their own GitHub account can never be used to reach another person's client account.
  • Signs In the Matching Client Account: The verified GitHub address is matched to the client account that already uses it and that client is logged straight in. Only client accounts are signed in this way - a staff login can never be created from the client area.
  • Two-Factor Accounts Stay Protected: A client with two-factor authentication switched on is never waved past it by the GitHub button - they're asked to sign in with their email address and password instead.
  • Single-Use Sign-In Links: Each GitHub sign-in is tied to the browser that started it and works only once, so a link copied out of an address bar, browser history or a log file can't be replayed to get into someone's account.
  • Never Locks Anyone Out: If no client account matches, or GitHub can't complete the sign-in, the visitor is returned to the normal login page with a plain-language explanation and can still log in with their email address and password.
  • Straightforward GitHub App Setup: Enter your GitHub application's client ID and client secret, and the exact authorization callback URL to paste back into GitHub is shown for you on the settings page.
  • Try It Without a GitHub Application: A Mock API mode runs the whole sign-in flow from bundled sample data, so you can see exactly how it behaves before setting up a real GitHub application.

Enhance your client login experience with GitHub Login by Blesta.Club.

Installing and updating extensions can now be done automatically through the Blesta Club Subscription Manager - this is the recommended way going forward.

Blesta Club Logo

Installing GitHub Login

Before you start

  • If you are on the leased (subscription) licence, the Blesta Club Subscription Manager must be installed and your subscription active. The owned and owned-source licences have no such requirement.
  • You'll want a GitHub OAuth application (for its Client ID and Client Secret) from the GitHub Developer Portal. You can install and try the plugin first with its Mock API mode if you'd rather set the GitHub application up afterward.

1. Upload the files

Upload the extension folder into your Blesta installation so it lands under your Blesta directory at:

plugins/github_login/

For example, on a typical install: /var/www/html/blesta/plugins/github_login/

2. Install it in Blesta

  1. Log in to your Blesta admin area with a staff account that has access to Settings > Company > Plugins.
  2. Go to Settings > Company > Plugins and click the Available tab.
  3. Find GitHub Login in the list and click Install.

3. Configure it

  1. Click Manage next to GitHub Login on the Plugins page.
  2. Copy the Authorization Callback URL shown on the settings page into your GitHub OAuth application's own "Authorization callback URL" field - the two must match exactly.
  3. Enter that GitHub application's Client ID and Client Secret, then save. Or tick Mock API to try the whole sign-in flow from bundled sample data with no GitHub application at all.

You're ready to go - see the usage guide for a walkthrough of day-to-day use.

Installing and updating extensions can now be done automatically through the Blesta Club Subscription Manager - this is the recommended way going forward.

Blesta Club Logo

Updating GitHub Login

Upgrading works just like installing: upload the new files over the old ones, then run the upgrade from the same page you installed it on.

  1. Back up your current extension files first - good practice before any upgrade.
  2. Upload the new version over the existing folder, replacing the old files.
  3. Log in to your Blesta admin area and go to Settings > Company > Plugins.
  4. Find GitHub Login and click Update to run the upgrade.

Version-specific notes

  • v2.0.0: Adds a Mock API mode for testing without a real GitHub application, refuses to sign in a client who has two-factor authentication enabled (they're asked for their email address and password instead), and makes each sign-in link single-use and tied to the browser that started it. This version also fixes several issues: the "Login with GitHub" button failing on every attempt including a first click in a fresh browser, an email GitHub had not verified being accepted as proof of identity, a failed sign-in dropping the visitor back on the client area with no explanation, the button appearing before a GitHub application had been configured, a staff member's GitHub email producing a session the client area couldn't display, blank error messages on the settings page, and a blank settings page when the license check failed. Your existing Client ID and Client Secret carry over unchanged - no reconfiguration is needed.

Blesta Club Logo

Using GitHub Login

For your staff

The settings screen (Settings > Company > Plugins > Manage)

  • Client ID / Client Secret: The credentials from your GitHub OAuth application.
  • Authorization Callback URL: A read-only field showing the exact URL to paste into your GitHub application's own settings - keep the two in sync if you ever recreate the GitHub application.
  • Mock API: Runs the whole sign-in flow from bundled sample data instead of a real GitHub application - useful for seeing exactly how it behaves before you've set one up.

There is nothing else to manage day to day - once saved, the "Login with GitHub" button appears on your client login page automatically.

For your clients

Signing in with GitHub

On the normal client-area login page, clients see a Login with GitHub button alongside the usual email and password fields. Clicking it sends them to GitHub to approve access to their email addresses only - nothing about their repositories or code is requested. Once they approve, they're brought back to Blesta and, if their verified GitHub email address matches an existing client account, logged straight in.

If GitHub can't complete the sign-in, or no client account matches, they're returned to the login page with a plain-language explanation and can sign in with their email address and password as usual instead.

Good to know

  • Only a GitHub-verified email address is used to find the matching client - an address GitHub has not verified is never used to identify anyone, even if it's the one listed as primary.
  • A client with two-factor authentication enabled is never signed in through GitHub - they're asked for their email address and password instead, so the second factor is never bypassed.
  • Each sign-in link works once, and only in the browser that started it - a copied or reused link can't sign anyone in a second time or from a different browser.
  • Connecting this plugin doesn't change any account, contact or password data - it only checks an existing verified email address against an existing client account each time someone signs in.

v2.0.0 - 2026-09-11

PHP 7.2 - 7.4, 8.1 - 8.4 · Blesta 5.x

The "Login with GitHub" button is now a proper button with the GitHub icon and "Sign in with GitHub" text, instead of a single wordmark image; the "or login with" divider no longer repeats when another social login plugin is also installed
Fixed a cURL connection handle leaking when a request to GitHub failed before a response arrived
Fixed the Mock API checkbox rendering with its label before the checkbox instead of after
Fixed a settings save that failed the license check discarding the Client ID and Secret the admin had just typed
Added missing alt text to the "Login with GitHub" button image
Two-factor accounts are no longer signed in automatically; they are now asked to sign in with their email address and password instead, so the second factor is never skipped
Sign-in links are now single-use and tied to the browser that started them, closing a window where a captured link could be replayed
Added a Mock API mode for testing and demonstrations, which runs sign-in from bundled sample data without a real GitHub application
Uninstalling from one company no longer leaves that company's settings behind
Fixed sign-in accepting a GitHub email address that GitHub had not verified, which could let someone sign in as a client whose email address they did not control
Fixed a failed or expired GitHub sign-in dropping the visitor back on the client area with no explanation; they are now returned to the login page with a message saying what went wrong
Fixed the "Login with GitHub" button appearing before a GitHub application had been set up, where it led to a GitHub error page instead of a sign-in
Fixed a GitHub email address belonging to a staff member rather than a client producing a signed-in session the client area could not display; those accounts are now passed over
Fixed the settings page showing blank error messages when settings failed to save
Fixed the browser tab title being blank on the page that completes a GitHub sign-in
Fixed the settings page coming up completely empty, with no form and no explanation, when the license check did not pass

v1.0.0 - 2024-09-22

PHP 7.2 - 7.3, 8.1 - 8.4 · Blesta 5.x

Blesta Club release

Pricing Options

Get exactly what you need and want.

Requires PHP 7.2 - 7.4, 8.1 - 8.4 · Blesta 5.x

Included In

Value: £42.3

£14.99
per month
  • +51 Other Extensions
  • Additional Discounts
  • Included Support & Updates
Leased
£4.99
per year
  • Partially Encoded
  • Full Functionality
  • Included Support & Updates
Owned
£20
one time
  • Partially Encoded
  • Buy Once Use Forever
  • 1 Year Support & Updates
Owned - Source
£40
one time
  • Source Available
  • Buy Once Use Forever
  • 1 Year Support & Updates

Not sure whether to lease or own? Our FAQ explains how the licence types differ.

Reviews

What our customers say

(0 customer reviews)

Seems like this extension doesn't have reviews yet...
Be one of the firsts to leave a review!

It is possible to leave a review only if you have purchased this extension or a Club tier which contains it.
We reserve the right to alter wording or formatting for presentation.
We will discuss any changes made and offer the option to withdraw review text if the changes can't be agreed on.
It may take up to 1 hour for a review to appear or update due to caching.

You might also like

More extensions to explore

Blesta 6

Plugin

Announcements

(1)

Integrate the Announcements plugin to provide updates and news to your clients.

PHP 8.2 - 8.4 · Blesta 6.x

Blesta 6

Plugin

Bulk Download Invoices

Download multiple invoices simultaneously.

PHP 8.2 - 8.4 · Blesta 6.x

Blesta 5

Plugin

Convoy Automatic Stock

Automate Convoy stock management.

PHP 7.2 - 7.4, 8.1 - 8.4 · Blesta 5.x

Blesta 5

Plugin

Cookie Cuttr

Implement cookie compliance easily.

PHP 7.2 - 7.4, 8.1 - 8.4 · Blesta 5.x

Blesta 5

Plugin

Credit Awards

Give your clients rewards based upon service purchases.

PHP 7.2 - 7.4, 8.1 - 8.4 · Blesta 5.x

Blesta 5

Plugin

Crisp Live Chat

Integrate Crisp live chat into your client area.

PHP 7.2 - 7.4, 8.1 - 8.4 · Blesta 5.x