Passport strategy for authenticating with Facebook using the OAuth 2.0 API.
This module lets you authenticate using Facebook in your Node.js applications. By plugging into Passport, Facebook authentication can be easily and unobtrusively integrated into any application or framework that supports Connect-style middleware, including Express.
$ npm install passport-facebook
The Facebook authentication strategy authenticates users using a Facebook
account and OAuth 2.0 tokens. The strategy requires a verify
callback, which
accepts these credentials and calls done
providing a user, as well as
specifying an app ID, app secret, callback URL, and optionally enabling [appsecret_proof
] (
passport.use(new FacebookStrategy({
callbackURL: "http://localhost:3000/auth/facebook/callback",
enableProof: false
function(accessToken, refreshToken, profile, done) {
User.findOrCreate({ facebookId: }, function (err, user) {
return done(err, user);
Use passport.authenticate()
, specifying the 'facebook'
strategy, to
authenticate requests.
For example, as route middleware in an Express application:
passport.authenticate('facebook', { failureRedirect: '/login' }),
function(req, res) {
// Successful authentication, redirect home.
If you need extended permissions from the user, the permissions can be requested
via the scope
option to passport.authenticate()
For example, this authorization requests permission to the user's statuses and checkins:
passport.authenticate('facebook', { scope: ['user_friends', 'user_checkins'] }));
Refer to Facebook's docs
passport.authenticate('facebook', { authType: 'rerequest', scope: ['user_friends', 'user_checkins'] }));
The display mode with which to render the authorization dialog can be set by
specifying the display
option. Refer to Facebook's OAuth Dialog
documentation for more information.
passport.authenticate('facebook', { display: 'touch' }));
Refer to Facebook's Re-authentication
passport.authenticate('facebook', { authType: 'reauthenticate', authNonce: 'foo123' }));
The Facebook profile is very rich, and may contain a lot of information. The
strategy can be configured with a profileFields
parameter which specifies a
list of fields (named by Portable Contacts convention) your application needs.
For example, to fetch only user's facebook ID, name, and picture, configure
strategy like this.
passport.use(new FacebookStrategy({
// clientID, clientSecret and callbackURL
profileFields: ['id', 'displayName', 'photos', 'email']
// verify callback
If profileFields
is not specified, the default fields supplied by Facebook
will be parsed.
Add email
to profileFields if you need user's email.
Developers using the popular Express web framework can refer to an example as a starting point for their own web applications.
Facebook's OAuth 2.0 implementation has a [bug][1] in which the fragment #_=_
is appended to the callback URL. This appears to affect Firefox and Chrome, but
not Safari. This fragment can be removed via client-side JavaScript, and @niftylettuce
provides a suggested [workaround][2]. Developers are encouraged to direct their
complaints to Facebook in an effort to get them to implement a proper fix for
this issue.
[2]: jaredhanson#12 (comment)
The test suite is located in the test/
directory. All new features are
expected to have corresponding test cases. Ensure that the complete test suite
passes by executing:
$ make test
All new feature development is expected to have test coverage. Patches that increse test coverage are happily accepted. Coverage reports can be viewed by executing:
$ make test-cov
$ make view-cov
This software is provided to you as open source, free of charge. The time and effort to develop and maintain this project is dedicated by @jaredhanson. If you (or your employer) benefit from this project, please consider a financial contribution. Your contribution helps continue the efforts that produce this and other open source software.
Funds are accepted via PayPal, Venmo, and other methods. Any amount is appreciated.
Copyright (c) 2011-2016 Jared Hanson <>