Skip to content
Insights

NQ Solution

Kakao Login and Naver Login Integration Guide

Add Kakao and Naver login: OAuth and OIDC flows, consent items, business app and D-U-N-S rules, Naver's app review, and Supabase or Auth.js setup.

Kakao Login and Naver Login are both standard OAuth 2.0 authorization-code flows with OpenID Connect options: you register an app, send the user to the provider's authorize URL, exchange the returned code for tokens on your server and call a profile API. The harder part is the approvals, because Kakao gates email and most personal data behind a business app and a permission review, and Naver only lets registered test accounts log in until your app passes its review.

This guide walks through both flows, the review and consent rules that catch foreign teams out, and how to use the two providers with libraries such as Supabase Auth and Auth.js. It follows the official developer documentation (linked at the end, checked October 2026).

How do Kakao Login and Naver Login compare?

Kakao LoginNaver Login
Developer consoledevelopers.kakao.comdevelopers.naver.com
Client IDREST API keyClient ID issued at registration
Authorize URLhttps://kauth.kakao.com/oauth/authorizehttps://nid.naver.com/oauth2.0/authorize
Token URLhttps://kauth.kakao.com/oauth/tokenhttps://nid.naver.com/oauth2.0/token
Profile APIhttps://kapi.kakao.com/v2/user/mehttps://openapi.naver.com/v1/nid/me
Client secretOn by default for the REST API keyAlways sent in the token request
state parameterOptional (recommended for CSRF protection)Required
OpenID ConnectTurn it on in the app settings to receive an ID tokenSeparate OIDC endpoints with scope=openid, PKCE supported
Before real users can log inTurn Kakao Login on and register redirect URIs. Some consent items need a business app and a reviewApp review ("검수"). Until then, only the registrant and registered members can log in
Docs languageKorean and EnglishKorean

How does Kakao Login work?

Start in the Kakao Developers console:

  1. Create an app. The REST API key becomes your client_id.
  2. Turn Kakao Login on. If it is off, users see error KOE004.
  3. Register at least one redirect URI. A mismatch returns KOE006.
  4. Note the client secret. It is enabled by default for the REST API key, and you send it with the token request.
  5. Configure consent items, the pieces of user data you ask for, each set as required or optional.
  6. Optionally turn on OpenID Connect so the token response also includes an id_token.

The flow itself:

  • Redirect the user to https://kauth.kakao.com/oauth/authorize with client_id, redirect_uri, response_type=code, and optionally scope, state and nonce (for the ID token).
  • Kakao redirects back with a code. On your server, POST to https://kauth.kakao.com/oauth/token with grant_type=authorization_code, client_id, redirect_uri, code and client_secret.
  • The response includes an access_token, a refresh_token, expires_in and, with OIDC on, an id_token.
  • Call https://kapi.kakao.com/v2/user/me with the access token to get the user's ID and whatever data they agreed to share.

Kakao also has endpoints to log a user out (POST /v1/user/logout) and to unlink the app from their account (POST /v1/user/unlink). Build unlink into account deletion, so a user who leaves your service is also disconnected on Kakao's side.

Which Kakao consent items need a business app or a review?

This is where most foreign teams lose time. According to Kakao's consent item documentation:

  • Nickname and profile image are available to every app.
  • Email (account_email) can only have a consent level set in a business app (or a test app).
  • Name, gender, age range, birthday, birth year and phone number need permission, which you request through a review.

A business app is an app with registered business information. Domestic companies register a Korean business registration number. Overseas businesses can register a D-U-N-S number. Individuals without a business can switch to a "business app for individual developers" after verifying their identity, adding an app icon and agreeing to Kakao Business terms. That kind of business app cannot be connected to a business KakaoTalk Channel, because it has no business information. In Kakao's developer forum, overseas residents have reported that the identity verification step assumes Korean identity details, so a foreign company should plan on the D-U-N-S route.

To request extra permissions you switch to a business app, complete business information review and submit an application with your sign-up page URL, your privacy policy and the reason you need each item. Kakao says review typically takes three to five business days. Your privacy policy has to state that the data from Kakao is used for sign-up and list every item you request, so publish it before you apply.

The practical lesson is to ask for less. If you only need a stable user ID and a display name, Kakao Login works with no review at all. Ask for email only if you will actually use it. Remember that some users will decline optional items, so the sign-up flow still has to work when they do.

How does Naver Login work?

Register an application in the Naver Developers console. Choose Naver Login as the API, then add the service environment: the homepage URL for web, the package name and URL scheme for apps, and the callback URL. You also choose which profile fields you want access to.

  • Redirect the user to https://nid.naver.com/oauth2.0/authorize with response_type=code, client_id, redirect_uri and state. Naver requires state and uses it to protect against cross-site request forgery.
  • Naver redirects back with code and state. Check that the state matches, then request https://nid.naver.com/oauth2.0/token with grant_type=authorization_code, client_id, client_secret, code and state. A code works only once.
  • Call https://openapi.naver.com/v1/nid/me with Authorization: Bearer <access token>. The response/id field is a unique identifier issued for each Naver ID. Use it as the login key.
  • Store the refresh token server-side. The access token expires after the number of seconds given in expires_in.
  • To disconnect a user, revoke their tokens at https://nid.naver.com/oauth2.0/revoke (RFC 7009 token revocation). The service also disappears from the user's list of connected services on Naver.

Naver documents OpenID Connect separately. It uses different paths, discovery at https://nid.naver.com/.well-known/openid-configuration, keys at https://nid.naver.com/oauth2/jwks, scope=openid required on the authorize request, and PKCE with S256 supported. If your auth library speaks standard OIDC, the discovery document is the easiest way in.

What does Naver's app review involve?

A new Naver Login app is in development status. In that state, only the account that registered the app and the IDs you add as admins or testers in the member management tab can log in. To open it to everyone you request a review, submitting screenshots of the login button and the full login and sign-up flow, taken while logged in with one of those accounts.

Reviewers check that every profile field you request is actually used in your service. Asking for a name and never showing or using it gets you rejected. If you request phone numbers, the review also checks that you are a properly registered business. Your app name and logo appear on the consent screen, so they must represent your service and must not imitate Naver. An app called "Naver Login" is rejected. Results arrive by email within two to three business days, and you can fix the issues and request a re-review.

Plan the review into your launch schedule. The login works in development, but real customers cannot use it until the review passes.

Can you use Supabase or Auth.js instead of writing the flow yourself?

Yes, for the most part.

  • Supabase Auth has a built-in Kakao provider. You use the REST API key as the client ID, the Kakao Login client secret, and https://<project-ref>.supabase.co/auth/v1/callback as the redirect URI. Supabase's guide notes that account_email requires a business app, and that you can allow users without an email in the provider settings.
  • Auth.js (NextAuth) has built-in Kakao and Naver providers, with callback URLs of the form /api/auth/callback/kakao and /api/auth/callback/naver.

A library handles the redirects and token exchange, but not the decisions: which consent items to request, what to do when a user has no email, and how to link a Kakao or Naver account to an existing customer record.

What should you decide before you build?

  • The identity key. Store the provider plus its user ID as the login identity. Do not use email, which may be missing or may change.
  • Account linking. If a customer signed up with email and later logs in with Kakao, decide whether you link the accounts automatically (only with a verified match) or ask them to confirm.
  • The minimum data set. Every extra item adds review work, privacy policy text and a sign-up step that has to handle refusal.
  • Unlinking and deletion. Call Kakao's unlink API or Naver's token revocation when a user deletes their account.
  • Which provider first. You can offer both. If you can only ship one, look at who your users are and where they already log in.

How much does it cost to add Kakao or Naver login?

The main costs are development and review time. Our public estimator lists social login as a module at 300,000 to 800,000 KRW, excluding 10% VAT (pricing catalogue v1.1, 23 September 2026). The higher end applies when you need account linking with existing members, several providers, or a consent review.

Frequently asked questions

Does Supabase support Kakao login?

Yes. Supabase Auth has a Kakao provider. You enter the Kakao REST API key and the Kakao Login client secret in Supabase and register Supabase's callback URL as a redirect URI in Kakao Developers.

Do I need a Korean business to register a Kakao app?

No. Anyone can create an app and use Kakao Login with nickname and profile image. Email and personal data such as phone number need a business app. Overseas businesses can register a D-U-N-S number instead of a Korean business registration number.

Should I use Kakao Login or Naver Login?

You can offer both. Kakao Login gets you running with basic profile data quickly. Naver Login needs an app review before the public can use it. Choose based on your users, and plan the review time for whichever you pick.

How long do the reviews take?

Kakao says permission reviews typically take three to five business days. Naver says review results arrive by email within two to three business days of the request. Rejections need a fix and a new review, so allow extra time.

Can I get a user's phone number through Kakao or Naver login?

Only with approval. Kakao treats phone number as a consent item that needs permission through review, and Naver's review checks that you are a registered business when you request phone numbers.

Adding Korean sign-in to your product?

If you are adding Kakao or Naver login to a site or app and want the consent items, reviews and account linking sorted out before launch, send us your requirements. See our web development page for the kinds of services we build. Related reading: PASS identity verification in Korea if you also need real-name checks, Korean address search for sign-up forms, and the Korea integrations page.

Sources

All checked October 2026.

Planning a similar project?

Send us your goals, scope and timeline. The two of us who would build it reply directly.

Prefer email? Write to dwkim@nqsolution.kr — the founder replies directly.