# Sign in with Google — one tap, no passwords

*How Trackmint login works now, why it is safer, and what is coming next (Apple Sign-In). Written simply.*

## 1. What changed

The web app login screen now has a **"Continue with Google"** button above the email boxes. Tap it, pick the Google account you are already logged into in your browser, and you are in — **no password to invent, type, or forget**. Google proves who you are; Trackmint never sees or stores a password for these users. Email + password still works as a fallback for anyone who prefers it.

## 2. Why this is the right idea (Barry's instinct, confirmed)

1. **Less friction = more signups.** The #1 drop-off point in every SaaS funnel is the "create a password" box. One tap removes it.
2. **Better security, zero effort.** Google brings its own 2-factor, phishing protection, and breach monitoring. We inherit all of it for free.
3. **Less for us to manage.** No "forgot password" tickets from Google users, no password database to defend.
4. **Same workspace either way.** Account linking is ON: if someone made an email account first and later taps Google with the *same* email address, Firebase links them into the **same** account — nobody loses data.

## 3. How it works (30-second version)

Trackmint asks Google "who is this?" → a Google popup appears (the familiar account-chooser) → the user picks an account → Google hands Trackmint a signed proof of identity → Firebase Auth accepts it and issues the same kind of session as an email login. Everything downstream (workspace, packs, billing, rules) is unchanged, because the user still gets one Firebase `uid`.

## 4. What's enabled where

| Platform | Google button | Notes |
|---|---|---|
| **Web app** (apex.socialtokens.site) | ✅ live now | Popup account-chooser; domain safelisted in Firebase |
| **iPhone (TestFlight)** | 🔜 next build cycle | Needs a native Google config + **Apple Sign-In must ship at the same time** — App Store rule: any app offering Google login must also offer Apple login |
| **Android APK** | 🔜 with the iPhone work | Needs the SHA-1 fingerprint of our signing key added in Firebase |

## 5. The enhancement plan (what ships next)

**Phase 2 — native buttons.** Add Google *and* Apple Sign-In to the iOS/Android apps together (Apple's rule makes them a pair). This uses Expo's authentication modules and one extra config screen in Firebase; no data-model changes.

**Phase 3 — passwordless polish.** Once Google/Apple cover most users, we can demote the email form to a "more options" link, and optionally add email magic-links so even fallback users never need a password.

## 6. For the record (technical facts)

- Provider: Firebase Auth Google provider, enabled with public-facing name **"Trackmint"** and support email barry.auyeung@gmail.com.
- Authorized domains: localhost, trackmint-a8604.firebaseapp.com/web.app, **apex.socialtokens.site**.
- Account linking: "Link accounts that use the same email" (Firebase default) — one email = one account, always.
- Code: `signInWithPopup(GoogleAuthProvider)` in `AppContext.signInGoogle()`, button in `LoginScreen` shown only when Firebase is on and the platform is web.
