Login with Facebook SSO
Updated: Aug 27, 2026
Copy for LLM
Open beta
These Facebook Login features are part of an open beta. If you encounter any issues, please use our feedback form.
Login with Facebook SSO surfaces Facebook Login as a single-tap call to action — typically at app startup — for people who already have the Facebook app installed and are signed in. Instead of typing credentials, they see a Facebook-branded prompt with their account, confirm, and return to your app already logged in.
How it behaves depends on the state of the device:
- Facebook app installed and signed in — the SDK app-switches to the Facebook app, which presents the consent prompt and returns an access token to your app.
- Facebook app installed but signed out — the prompt invites the person to sign in to the Facebook app first, then returns to the login flow.
- No compatible Facebook app installed — the SDK shows a built-in fallback dialog that completes login through a Chrome Custom Tab, instead of failing.
This page covers native Android (Kotlin and Java) and the Facebook SDK for Unity. For the web equivalent, see Facebook Login with FedCM.
Requirements
| Requirement | Native Android | Unity |
|---|---|---|
Facebook SDK | Facebook SDK for Android 18.3.0 or later | Facebook SDK for Unity 18.1.0 or later, which resolves Android 18.3.0 |
Facebook app | Recommended installed and signed in for the app-switch experience; a dialog fallback is used otherwise | Same |
App setup | Standard Facebook Login setup: app ID, client token, and your Android key hash registered | Same |
Platform | Android | Android only — a no-op on iOS and in the Unity Editor |
How it works
- Your app creates the SSO entry point early in its lifecycle and calls it with the permissions you want to request.
- The SDK checks login state first. If the person is already logged in to your app through Facebook Login, nothing is shown.
- Otherwise the SDK launches the consent experience:
- App-switch path — control transfers to the installed Facebook app, which renders the consent prompt. On confirm, the Facebook app performs the OAuth exchange and returns the result.
- Fallback path — if no compatible Facebook app is present, the SDK presents its own bundled dialog, and Continue completes login through a Chrome Custom Tab.
- The result — an access token and granted permissions, or a cancel or error — comes back through the standard Facebook Login result handling you already use. There is no special result parsing.
Because the consent step hands the person to the Facebook app and back, expect a brief transition out of and into your app during login. That is the intended experience.
Set up
- Configure Facebook Login as usual. Set your app ID and client token, initialize the SDK, and confirm a normal Facebook Login works first.
- Register your Android key hash. Your app’s key hash and package name must be registered for your Facebook app ID. The Facebook app validates the calling app’s signing key against the registered hashes, and rejects SSO if it does not match.
- Update the SDK to Android 18.3.0 or later, or Unity 18.1.0 or later.
- Test both paths — on a device or emulator with the Facebook app installed and signed in for the app-switch experience, and without it to verify the fallback dialog.
Native Android
Add the dependency
The SSO entry point ships in the
facebook-login artifact:dependencies {
implementation 'com.facebook.android:facebook-login:[18.3.0,19)'
// facebook-common is pulled in transitively
}
Declare package visibility
On Android 11 (API level 30) and above, package visibility is restricted. So the SDK can detect the Facebook app and app-switch into it, add it to
<queries> in your AndroidManifest.xml:<queries>
<package android:name="com.facebook.katana" />
</queries>
Create the launcher and call it
Create
FBLoginSSOLauncher in onCreate() of your launching activity. The constructor calls registerForActivityResult, so it must run before the activity starts. The activity must be a ComponentActivity — for example FragmentActivity or AppCompatActivity.import androidx.fragment.app.FragmentActivity
import com.facebook.FacebookCallback
import com.facebook.FacebookException
import com.facebook.login.FBLoginSSOLauncher
import com.facebook.login.LoginResult
class MainActivity : FragmentActivity() {
private lateinit var ssoLauncher: FBLoginSSOLauncher
override fun onCreate(savedInstanceState: Bundle?) {
super.onCreate(savedInstanceState)
// Must be created in onCreate() - it registers an activity-result launcher.
ssoLauncher = FBLoginSSOLauncher(
this,
object : FacebookCallback<LoginResult> {
override fun onSuccess(result: LoginResult) {
val token = result.accessToken
}
override fun onCancel() {
// The person dismissed the SSO prompt.
}
override fun onError(error: FacebookException) {
// Login failed.
}
}
)
if (savedInstanceState == null) {
val launched = ssoLauncher.launch(listOf("public_profile", "email"))
if (!launched) {
// No app on the device can handle the SSO intent.
// Fall back to standard Facebook Login.
}
}
}
}
The API
FBLoginSSOLauncher(
activity: ComponentActivity,
callback: FacebookCallback<LoginResult>? = null,
showWithoutFBApp: Boolean = true
)
| Parameter | Meaning |
|---|---|
activity | The activity the SSO flow launches from. Must be a ComponentActivity or a subclass such as FragmentActivity or AppCompatActivity. |
callback | Optional. Receives onSuccess(LoginResult), onCancel(), or onError(FacebookException). If null, you can still observe login state through AccessToken and LoginManager listeners. |
showWithoutFBApp | Whether to show the fallback dialog when the Facebook app is not installed. Defaults to true. Set to false to suppress the prompt entirely in that case. |
fun launch(permissions: Collection<String> = emptyList()): Boolean
permissions are the read permissions to request, such as public_profile and email.launch returns true if the consent activity started, meaning the person will see the consent screen. It returns false if the flow did not start, because no app on the device can handle the SSO intent. Use that signal to decide whether to fall back to another login method.Handle the returned token
You do not parse the SSO result yourself. The launcher routes it through the standard SDK login pipeline, so your
FacebookCallback<LoginResult> receives onSuccess, onCancel, or onError exactly as it would with LoginManager.logInWithReadPermissions(...). After success the token is available from AccessToken.getCurrentAccessToken(), and existing LoginManager and AccessToken listeners fire as normal.The fallback dialog
When the Facebook app is not installed,
launch() shows a fallback dialog bundled in the SDK, and Continue completes login through a Chrome Custom Tab. This keeps the call useful without the Facebook app. To show nothing in that case, construct the launcher with showWithoutFBApp = false.The contents of this dialog are built into the SDK, so they change only with a new SDK release — unlike the app-switch consent screen, which is served by the Facebook app.
The consent experience
In the common case — Facebook app installed and signed in — confirming hands the person to the Facebook app for consent and returns them to your app logged in. Design for that brief app-to-app transition; it is what makes the experience one tap.

If someone is signed in to the Facebook app but has not previously connected your app, or you request new permissions, they see the full Facebook Login consent dialog before returning. If they are signed out of the Facebook app, the prompt invites them to sign in first.
Unity
The Facebook SDK for Unity exposes SSO as
FB.Mobile.LoginWithSSO, bridging to the same native Android flow. It is Android-only — a no-op on iOS and in the Unity Editor, so it is safe to compile cross-platform. On iOS, use FB.LogInWithReadPermissions instead.The Unity package does not bundle native binaries; the External Dependency Manager for Unity resolves Facebook SDK for Android 18.3.0 at your build time.
FB.Mobile.LoginWithSSO(
IEnumerable<string> permissions = null,
FacebookDelegate<ILoginResult> callback = null);
The result is delivered through
FacebookDelegate<ILoginResult> — handle it exactly as you would FB.LogInWithReadPermissions.using System.Collections.Generic;
using Facebook.Unity;
public void SignIn()
{
#if UNITY_ANDROID
FB.Mobile.LoginWithSSO(new List<string> { "public_profile", "email" }, OnLogin);
#else
FB.LogInWithReadPermissions(new List<string> { "public_profile", "email" }, OnLogin);
#endif
}
void OnLogin(ILoginResult result)
{
if (!string.IsNullOrEmpty(result.Error)) { Debug.LogError(result.Error); return; }
if (result.Cancelled) { return; }
if (FB.IsLoggedIn)
{
var token = AccessToken.CurrentAccessToken;
}
}
Import Facebook SDK for Unity 18.1.0 or later and run the Android Resolver, configure your app ID and client token in Facebook Settings, call
FB.Init(), and register your Android key hash — then test on a device with the Facebook app installed.Troubleshooting
- The flow doesn’t switch to the Facebook app. The Facebook app probably isn’t installed, so you get the fallback dialog instead. On native Android, a
falsereturn fromlaunch()means the flow did not start at all. - Login is rejected immediately. Confirm your app’s Android key hash and package are registered for your Facebook app ID — the Facebook app validates the calling app’s signature.
- No prompt appears. The person may already be logged in through Facebook Login, in which case nothing is shown by design. The Facebook app on the device may also be too old to support SSO.
- Android 11 and above can’t find the Facebook app. Make sure
<package android:name="com.facebook.katana" />is in your manifest<queries>block. - Inspect logs. Filter Android logcat to
com.facebookto see the SDK’s diagnostics.