The GitHub Login plugin allows clients to authenticate using their GitHub accounts, streamlining the login process and improving convenience.
From £4.99 - View Pricing
What GitHub Login gives you
Configure it independently for each brand on a multi-company install, so every company runs with its own settings.
Every staff and client label ships in editable language files, ready to translate into any language or reword to match your brand.
A built-in demo mode runs the whole extension from bundled sample data, so you can trial every screen and action before you have an account or API key.
Clients reach your client area with an account they already use elsewhere instead of another password to remember, on your existing login page with no template edits.
Each GitHub sign-in is tied to the browser that started it and works only once, so a link copied out of someone's address bar, history or logs cannot be replayed to get into their account.
The GitHub authorization screen asks your client for nothing but their email addresses, with no access to their repositories or their code and no permission to change anything, so signing in is an easy yes.
Enter your GitHub application's client ID and client secret, and the exact authorization callback URL to paste back into GitHub is shown for you on the settings page, so the two sides cannot drift out of sync.
If no client account matches, or GitHub cannot complete the sign-in, the visitor is returned to the normal login page with a plain-language explanation and can log in with their email address and password as usual.
A client who has two-factor authentication switched on is never waved past it by the GitHub button. They are asked to sign in with their email address and password instead, so their second factor is still required every time.
Only email addresses GitHub itself has verified are used to identify the client, and the verified primary address is tried first, so an unverified address added to someone's GitHub account can never be used to reach another person's client account.
The verified GitHub address is matched to the client account that already uses it and that client is logged straight in, with the sign-in recorded in Blesta exactly like a normal login. Only client accounts are signed in this way, so a staff login can never be created from the client area.
v2.0.0 - 2026-09-11
PHP 7.2 - 7.4, 8.1 - 8.4 · Blesta 5.x
The "Login with GitHub" button is now a proper button with the GitHub icon and "Sign in with GitHub" text, instead of a single wordmark image; the "or login with" divider no longer repeats when another social login plugin is also installed
Fixed a cURL connection handle leaking when a request to GitHub failed before a response arrived
Fixed the Mock API checkbox rendering with its label before the checkbox instead of after
Fixed a settings save that failed the license check discarding the Client ID and Secret the admin had just typed
Added missing alt text to the "Login with GitHub" button image
Two-factor accounts are no longer signed in automatically; they are now asked to sign in with their email address and password instead, so the second factor is never skipped
Sign-in links are now single-use and tied to the browser that started them, closing a window where a captured link could be replayed
Added a Mock API mode for testing and demonstrations, which runs sign-in from bundled sample data without a real GitHub application
Uninstalling from one company no longer leaves that company's settings behind
Fixed sign-in accepting a GitHub email address that GitHub had not verified, which could let someone sign in as a client whose email address they did not control
Fixed a failed or expired GitHub sign-in dropping the visitor back on the client area with no explanation; they are now returned to the login page with a message saying what went wrong
Fixed the "Login with GitHub" button appearing before a GitHub application had been set up, where it led to a GitHub error page instead of a sign-in
Fixed a GitHub email address belonging to a staff member rather than a client producing a signed-in session the client area could not display; those accounts are now passed over
Fixed the settings page showing blank error messages when settings failed to save
Fixed the browser tab title being blank on the page that completes a GitHub sign-in
Fixed the settings page coming up completely empty, with no form and no explanation, when the license check did not pass
v1.0.0 - 2024-09-22
PHP 7.2 - 7.3, 8.1 - 8.4 · Blesta 5.x
Blesta Club release
Get exactly what you need and want.
Requires PHP 7.2 - 7.4, 8.1 - 8.4 · Blesta 5.x
Value: £42.3
Not sure whether to lease or own? Our FAQ explains how the licence types differ.
What our customers say
(0 customer reviews)
It is possible to leave a review only if you have purchased this extension or a Club tier which contains it.
We reserve the right to alter wording or formatting for presentation.
We will discuss any changes made and offer the option to withdraw review text if the changes can't be agreed on.
It may take up to 1 hour for a review to appear or update due to caching.
More extensions to explore
Plugin
Integrate the Announcements plugin to provide updates and news to your clients.
PHP 8.2 - 8.4 · Blesta 6.x
Plugin
Download multiple invoices simultaneously.
PHP 7.2 - 7.4, 8.1 - 8.4 · Blesta 5.x
Plugin
Automate Convoy stock management.
PHP 7.2 - 7.4, 8.1 - 8.4 · Blesta 5.x
Plugin
Give your clients rewards based upon service purchases.
PHP 7.2 - 7.4, 8.1 - 8.4 · Blesta 5.x
Plugin
Integrate Crisp live chat into your client area.
PHP 7.2 - 7.4, 8.1 - 8.4 · Blesta 5.x