# oauth Google and Microsoft sign-in exchange provider identity tokens for a normal Jobjakt local session. Verified provider email addresses may link to the matching local account; provider subject identifiers are then retained for stable future sign-in. Gmail and Microsoft Graph mailbox connections use separate OAuth flows and state validation because they grant mailbox permissions, not application login. Provider client IDs and secrets belong in environment configuration, never the repository. See `docs/architecture/authentication.md` and the connected-account settings UI.