AddThisFeature

Account Linking

Let one account sign in several ways without spawning duplicates.

involved User Accounts

What it adds

Attach and detach sign-in methods — password, OAuth providers, SSO — on a single existing account.

What your agent is told to do

6
  1. 1

    Model sign-in methods as separate identity records attached to one account, rather than columns on the user.

  2. 2

    Require a fresh re-authentication before any link or unlink. A stale session is enough to read the app; it is not enough to change how the account is entered.

  3. 3

    Refuse to link an identity that is already attached to another account. Explain the conflict and point the user at recovery — do not silently steal the identity or silently create a second account.

  4. 4

    Before unlinking, prove at least one usable method remains. Unlinking the last one locks the user out of their own data.

  5. 5

    Do NOT treat a matching email address as proof of ownership. Providers vary in whether they verify email, and an unverified match is a takeover route.

  6. 6

    Combining two accounts that both already exist is owned by Account Merge; extend that rather than building a second merge path here.

Edge cases it handles

6
  • A provider that returns no email, or a changed email, must still link to the right account by stable provider ID.
  • An email that the provider has not verified must not satisfy any ownership check.
  • Linking a provider whose email differs from the account email must not overwrite the account email.
  • Unlinking a method used by an active session should not sign that session out mid-action, but the session must lose the ability to re-authenticate with it.
  • Both link and unlink must be written to the audit trail and emailed to the account owner, including when the actor is an admin.
  • A provider that later revokes the app's access leaves a dead identity record — detect it and prompt, rather than failing at the next sign-in.

Definition of done

8
  • One account can hold multiple sign-in methods and all of them reach the same data.
  • Linking and unlinking both require recent re-authentication.
  • An identity already bound to another account is refused with a clear explanation.
  • The last usable sign-in method cannot be removed.
  • Every link and unlink is audited and notified to the owner.
  • Unverified provider emails are never used to match an account.
  • The feature matches the existing design system.
  • No existing functionality is broken.

Related features

How it works

  1. 1

    Copy the link

    Grab the Markdown instruction URL for this feature.

  2. 2

    Give it to your AI

    Paste it into Claude Code, Cursor, v0, Lovable — whatever you build with.

  3. 3

    It inspects, then implements

    Your agent reads your existing app first, then adds the feature to fit it.

Works with your stack

These instructions are written to adapt. They tell the agent to detect your framework, match your existing design system, and reuse what you already have — rather than assuming a particular stack.

Need it tighter than that? Customize the feature and tell it exactly what you're running.