Instruction
Configuration -> System -> Oauth providers

Online documentation

Enable email delivery

Sign in to https://developer.apple.com/account/resources

Click on “More …” and add domains and email addresses (requires SPF and DKIM, probably also an Apple ID in .well-known)

Keys & IDs

Sign in to https://developer.apple.com/account/resources

Identifiers

App ID

Create the primary ID for “Sign in” service.

Service ID

Create a service ID of the type Sign in with Apple and assign it to the app ID, then fill in your domains.

The Apple Service ID is your OAuth2 Client ID.

Key ID and private key

Create a new key for your Sign-In Service. This gets you a key ID (under details) and the private key (download)

Hints:

  • Don’t forget to fill in the key name (there will be no error message if you forget).
  • Downloading the privacy key is only possible once.

Team ID

This is your Account ID at the top right of the account information (2nd line)