> For the complete documentation index, see [llms.txt](https://fusionauth.io/docs/llms.txt)

# Apple Reconcile Lambda | FusionAuth Docs

An overview of the Apple Reconcile lambda.

# Apple Reconcile Lambda

[Edit on GitHub](https://github.com/FusionAuth/fusionauth-site/blob/main/astro/src/content/docs/extend/code/lambdas/reconcile/apple-reconcile.mdx)

[View Markdown](https://fusionauth.io/docs/extend/code/lambdas/reconcile/apple-reconcile.md)

When an Apple identity provider is used to complete a federated login request, FusionAuth will use the [configured linking strategy](https://fusionauth.io/docs/lifecycle/authenticate-users/identity-providers.md#linking-strategies) to reconcile the user. FusionAuth will attempt to match the user information returned from the Apple identity provider to an existing user account or create a new one.

You may optionally utilize a lambda to customize the user and user registration during the authentication event.

When you create a new lambda using the FusionAuth administrative user interface, you will be provided an empty function to implement.

Starting in version 1.65.0, you can use [attribute mappings](https://fusionauth.io/docs/lifecycle/authenticate-users/identity-providers.md#attribute-mappings) to map IdP claims directly to FusionAuth user and registration fields without writing a lambda. Reconcile lambdas and attribute mappings are mutually exclusive. Attempting to configure both on a given IdP results in a validation error.

## Lambda Structure[#](#lambda-structure)

If you are using the API to create the lambda you will need to ensure your function has the following signature:

```javascript
function reconcile(user, registration, idToken, context) {
  // Lambda code goes here
}
```

This lambda must contain a function named `reconcile` that accepts the following parameters:

*   `user` - the FusionAuth User object. You can modify this object. However, the **email** and **username** attributes may not be modified after the user has been linked.
*   `registration` - the FusionAuth UserRegistration object. You can modify this object.

*   `idToken` - the JSON payload of the validated and decoded Id Token returned from Apple. This object is read-only.
*   `context` - Available since 1.64.0 - an object containing the context of the request, including access to [secrets](https://fusionauth.io/docs/extend/code/lambdas.md#secrets). This object is read-only.

The two FusionAuth objects are well documented in the [User API](https://fusionauth.io/docs/apis/users.md) and [Registration API](https://fusionauth.io/docs/apis/registrations.md) documentation. The Id Token object that contains the payload returned by Apple and may contain well known OpenID Connect registered claims as well as any custom claims defined by Apple.

## Assigning The Lambda[#](#assigning-the-lambda)

Once a lambda is created, you may assign it to the Apple identity provider in the IdP configuration.

Navigate to Settings -> Identity Providers and select your existing Apple configuration or click Add provider and select Apple if it has not yet been configured.

## Default Lambda[#](#default-lambda)

A default Apple reconcile lambda is available in FusionAuth that may be used or modified. The default Apple lambda function is documented below.

```javascript
// This is the default Apple reconcile, modify this to your liking.
function reconcile(user, registration, idToken) {
  // Un-comment this line to see the idToken object printed to the event log
  // console.info(JSON.stringify(idToken, null, 2));

  // During the first login attempt, the user object will be available which may contain first and last name.
  if (idToken.user && idToken.user.name) {
    user.firstName = idToken.user.name.firstName || user.firstName;
    user.lastName = idToken.user.name.lastName || user.lastName;
  }
}
```