diff --git a/main/config/navigation/get-started.json b/main/config/navigation/get-started.json index c17c75662b..3c7fdbf065 100644 --- a/main/config/navigation/get-started.json +++ b/main/config/navigation/get-started.json @@ -1,238 +1,27 @@ { + "directory": "accordion", "pages": [ "docs/get-started", - { - "group": "Auth0 Onboarding", - "pages": [ - "docs/get-started/onboarding", - "docs/get-started/onboarding/self-service-m2m" - ] - }, { "group": "Quickstarts", + "directory": "none", "$ref": "./quickstarts.json" }, { "group": "Learn the Basics", "pages": [ - { - "group": "Identity Fundamentals", - "pages": [ - "docs/get-started/identity-fundamentals", - "docs/get-started/identity-fundamentals/identity-and-access-management", - "docs/get-started/identity-fundamentals/introduction-to-auth0", - "docs/get-started/identity-fundamentals/authentication-and-authorization" - ] - }, - { - "group": "Auth0 Overview", - "pages": [ - "docs/get-started/auth0-overview", - { - "group": "Auth0 Dashboard", - "pages": [ - "docs/get-started/auth0-overview/dashboard", - "docs/get-started/auth0-overview/dashboard/activity" - ] - }, - { - "group": "Create Tenants", - "pages": [ - "docs/get-started/auth0-overview/create-tenants", - "docs/get-started/auth0-overview/create-tenants/create-multiple-tenants", - "docs/get-started/auth0-overview/create-tenants/child-tenants", - "docs/get-started/auth0-overview/create-tenants/set-up-multiple-environments", - "docs/get-started/auth0-overview/create-tenants/multi-tenant-apps-best-practices" - ] - }, - { - "group": "Create Applications", - "pages": [ - "docs/get-started/auth0-overview/create-applications", - "docs/get-started/auth0-overview/create-applications/register-applications-with-cimd", - "docs/get-started/auth0-overview/create-applications/native-apps", - "docs/get-started/auth0-overview/create-applications/single-page-web-apps", - "docs/get-started/auth0-overview/create-applications/regular-web-apps", - "docs/get-started/auth0-overview/create-applications/machine-to-machine-apps", - "docs/get-started/auth0-overview/create-applications/configure-an-identity-provider-in-access-gateway" - ] - }, - "docs/get-started/auth0-overview/set-up-apis" - ] - } - ] - }, - { - "group": "Configure Auth0", - "pages": [ - { - "group": "Auth0 Teams", - "pages": [ - "docs/get-started/auth0-teams", - "docs/get-started/auth0-teams/tenant-management", - "docs/get-started/auth0-teams/team-member-management", - "docs/get-started/auth0-teams/tenant-member-management", - "docs/get-started/auth0-teams/configure-security-policies", - "docs/get-started/auth0-teams/troubleshoot-teams", - "docs/get-started/auth0-teams/team-activity", - "docs/get-started/auth0-teams/quarterly-snapshot" - ] - }, - { - "group": "Dashboard Profile", - "pages": [ - "docs/get-started/dashboard-profile", - "docs/get-started/dashboard-profile/auth0-dashboard-login-session-management", - "docs/get-started/dashboard-profile/light-and-dark-themes" - ] - }, - { - "group": "Tenant Settings", - "pages": [ - "docs/get-started/tenant-settings", - { - "group": "Signing Keys", - "pages": [ - "docs/get-started/tenant-settings/signing-keys", - "docs/get-started/tenant-settings/signing-keys/rotate-signing-keys", - "docs/get-started/tenant-settings/signing-keys/revoke-signing-keys", - "docs/get-started/tenant-settings/signing-keys/view-signing-certificates", - "docs/get-started/tenant-settings/signing-keys/customer-signing-keys" - ] - }, - "docs/get-started/tenant-settings/configure-device-user-code-settings", - "docs/get-started/tenant-settings/enable-sso-for-legacy-tenants", - "docs/get-started/tenant-settings/find-your-tenant-name-or-tenant-id" - ] - }, - { - "group": "Applications in Auth0", - "pages": [ - "docs/get-started/applications", - "docs/get-started/applications/application-settings", - "docs/get-started/applications/credentials", - "docs/get-started/applications/wildcards-for-subdomains", - { - "group": "Confidential and Public Applications", - "pages": [ - "docs/get-started/applications/confidential-and-public-applications", - "docs/get-started/applications/confidential-and-public-applications/view-application-type" - ] - }, - "docs/get-started/applications/first-party-and-third-party-applications", - { - "group": "Third-Party Applications", - "pages": [ - "docs/get-started/applications/third-party-applications", - "docs/get-started/applications/third-party-applications/security-controls", - "docs/get-started/applications/third-party-applications/user-consent-and-third-party-applications", - "docs/get-started/applications/third-party-applications/configure-third-party-applications", - "docs/get-started/applications/third-party-applications/troubleshooting", - "docs/get-started/applications/third-party-applications/permissive-mode" - ] - }, - "docs/get-started/applications/dynamic-client-registration", - "docs/get-started/applications/set-up-database-connections", - "docs/get-started/applications/test-database-connections", - "docs/get-started/applications/application-access-to-apis-client-grants", - "docs/get-started/applications/application-grant-types", - "docs/get-started/applications/update-grant-types", - "docs/get-started/applications/revoke-api-access", - "docs/get-started/applications/signing-algorithms", - "docs/get-started/applications/change-application-signing-algorithms", - "docs/get-started/applications/configure-application-metadata", - "docs/get-started/applications/update-application-connections", - "docs/get-started/applications/rotate-credentials", - "docs/get-started/applications/rotate-client-secret", - "docs/get-started/applications/enable-android-app-links-support", - "docs/get-started/applications/enable-universal-links-support-in-apple-xcode", - "docs/get-started/applications/set-up-cors", - "docs/get-started/applications/configure-applications-with-oidc-discovery", - "docs/get-started/applications/configure-ws-fed-applications", - { - "group": "Configure FAPI Compliance", - "pages": [ - "docs/get-started/applications/configure-fapi-compliance", - "docs/get-started/applications/configure-fapi-compliance/configure-auth0-to-pass-openid-fapi-certification-tests" - ] - }, - "docs/get-started/applications/configure-par", - "docs/get-started/applications/configure-jar", - { - "group": "Configure mTLS Authentication", - "pages": [ - "docs/get-started/applications/configure-mtls", - "docs/get-started/applications/configure-mtls/set-up-the-customer-edge", - "docs/get-started/applications/configure-mtls/configure-mtls-for-a-tenant", - "docs/get-started/applications/configure-mtls/configure-mtls-for-a-client" - ] - }, - "docs/get-started/applications/configure-private-key-jwt", - "docs/get-started/applications/remove-applications", - "docs/get-started/applications/work-with-auth0-locally", - "docs/get-started/applications/enable-sso-for-applications", - "docs/get-started/applications/configure-client-initiated-backchannel-authentication" - ] - }, - { - "group": "APIs", - "pages": [ - "docs/get-started/apis", - "docs/get-started/apis/api-settings", - "docs/get-started/apis/api-access-policies-for-applications", - "docs/get-started/apis/add-api-permissions", - "docs/get-started/apis/delete-api-permissions", - { - "group": "Scopes", - "pages": [ - "docs/get-started/apis/scopes", - "docs/get-started/apis/scopes/api-scopes", - "docs/get-started/apis/scopes/openid-connect-scopes", - "docs/get-started/apis/scopes/sample-use-cases-scopes-and-claims" - ] - }, - "docs/get-started/apis/configure-access-token-profile", - "docs/get-started/apis/configure-json-web-encryption", - "docs/get-started/apis/set-logical-api", - "docs/get-started/apis/configure-rich-authorization-requests", - "docs/get-started/apis/create-m2m-app-test", - "docs/get-started/apis/enable-role-based-access-control-for-apis" - ] - }, - { - "group": "Manage Dashboard Access", - "pages": [ - "docs/get-started/manage-dashboard-access", - "docs/get-started/manage-dashboard-access/feature-access-by-role", - "docs/get-started/manage-dashboard-access/add-dashboard-users", - "docs/get-started/manage-dashboard-access/edit-dashboard-users", - "docs/get-started/manage-dashboard-access/remove-dashboard-users", - "docs/get-started/manage-dashboard-access/update-dashboard-user-email", - { - "group": "Multi-factor authentication for Dashboard users", - "pages": [ - "docs/get-started/manage-dashboard-access/add-change-remove-mfa", - "docs/get-started/manage-dashboard-access/add-change-remove-mfa/add-mfa", - "docs/get-started/manage-dashboard-access/add-change-remove-mfa/remove-or-change-dashboard-multi-factor-authentication" - ] - }, - "docs/get-started/manage-dashboard-access/configure-single-sign-on-for-auth0-dashboard" - ] - } - ] - }, - { - "group": "Plan and Design", - "pages": [ + "docs/get-started/identity-fundamentals/introduction-to-auth0", + "docs/get-started/identity-fundamentals/identity-and-access-management", + "docs/get-started/identity-fundamentals/authentication-and-authorization", { "group": "Authentication and Authorization Flows", + "root": "docs/get-started/authentication-and-authorization-flow", "pages": [ - "docs/get-started/authentication-and-authorization-flow", "docs/get-started/authentication-and-authorization-flow/which-oauth-2-0-flow-should-i-use", { "group": "Authorization Code Flow", + "root": "docs/get-started/authentication-and-authorization-flow/authorization-code-flow", "pages": [ - "docs/get-started/authentication-and-authorization-flow/authorization-code-flow", "docs/get-started/authentication-and-authorization-flow/authorization-code-flow/add-login-auth-code-flow", "docs/get-started/authentication-and-authorization-flow/authorization-code-flow/call-your-api-using-the-authorization-code-flow", "docs/get-started/authentication-and-authorization-flow/authorization-code-flow/authorization-code-flow-with-rar", @@ -242,24 +31,24 @@ }, { "group": "Authorization Code Flow with Proof Key for Code Exchange", + "root": "docs/get-started/authentication-and-authorization-flow/authorization-code-flow-with-pkce", "pages": [ - "docs/get-started/authentication-and-authorization-flow/authorization-code-flow-with-pkce", "docs/get-started/authentication-and-authorization-flow/authorization-code-flow-with-pkce/add-login-using-the-authorization-code-flow-with-pkce", "docs/get-started/authentication-and-authorization-flow/authorization-code-flow-with-pkce/call-your-api-using-the-authorization-code-flow-with-pkce" ] }, { "group": "Client Credentials Flow", + "root": "docs/get-started/authentication-and-authorization-flow/client-credentials-flow", "pages": [ - "docs/get-started/authentication-and-authorization-flow/client-credentials-flow", "docs/get-started/authentication-and-authorization-flow/client-credentials-flow/call-your-api-using-the-client-credentials-flow", "docs/get-started/authentication-and-authorization-flow/client-credentials-flow/customize-tokens-using-hooks-with-client-credentials-flow" ] }, { "group": "Client-Initiated Backchannel Authentication Flow", + "root": "docs/get-started/authentication-and-authorization-flow/client-initiated-backchannel-authentication-flow", "pages": [ - "docs/get-started/authentication-and-authorization-flow/client-initiated-backchannel-authentication-flow", "docs/get-started/authentication-and-authorization-flow/client-initiated-backchannel-authentication-flow/mobile-push-notifications-with-ciba", "docs/get-started/authentication-and-authorization-flow/client-initiated-backchannel-authentication-flow/email-notifications-with-ciba", "docs/get-started/authentication-and-authorization-flow/client-initiated-backchannel-authentication-flow/user-authorization-with-ciba" @@ -267,37 +56,37 @@ }, { "group": "Custom Token Exchange Flow", + "root": "docs/get-started/authentication-and-authorization-flow/token-exchange-flow", "pages": [ - "docs/get-started/authentication-and-authorization-flow/token-exchange-flow", "docs/get-started/authentication-and-authorization-flow/token-exchange-flow/call-your-api-using-the-custom-token-exchange-flow" ] }, { "group": "Device Authorization Flow", + "root": "docs/get-started/authentication-and-authorization-flow/device-authorization-flow", "pages": [ - "docs/get-started/authentication-and-authorization-flow/device-authorization-flow", "docs/get-started/authentication-and-authorization-flow/device-authorization-flow/call-your-api-using-the-device-authorization-flow" ] }, { "group": "Implicit Flow with Form Post", + "root": "docs/get-started/authentication-and-authorization-flow/implicit-flow-with-form-post", "pages": [ - "docs/get-started/authentication-and-authorization-flow/implicit-flow-with-form-post", "docs/get-started/authentication-and-authorization-flow/implicit-flow-with-form-post/mitigate-replay-attacks-when-using-the-implicit-flow", "docs/get-started/authentication-and-authorization-flow/implicit-flow-with-form-post/add-login-using-the-implicit-flow-with-form-post" ] }, { "group": "Hybrid Flow", + "root": "docs/get-started/authentication-and-authorization-flow/hybrid-flow", "pages": [ - "docs/get-started/authentication-and-authorization-flow/hybrid-flow", "docs/get-started/authentication-and-authorization-flow/hybrid-flow/call-api-hybrid-flow" ] }, { "group": "Resource Owner Password Flow", + "root": "docs/get-started/authentication-and-authorization-flow/resource-owner-password-flow", "pages": [ - "docs/get-started/authentication-and-authorization-flow/resource-owner-password-flow", "docs/get-started/authentication-and-authorization-flow/resource-owner-password-flow/call-your-api-using-resource-owner-password-flow", "docs/get-started/authentication-and-authorization-flow/resource-owner-password-flow/avoid-common-issues-with-resource-owner-password-flow-and-attack-protection" ] @@ -309,12 +98,12 @@ }, { "group": "Architecture Scenarios", + "root": "docs/get-started/architecture-scenarios", "pages": [ - "docs/get-started/architecture-scenarios", { "group": "Business to Consumer", + "root": "docs/get-started/architecture-scenarios/business-to-consumer", "pages": [ - "docs/get-started/architecture-scenarios/business-to-consumer", "docs/get-started/architecture-scenarios/business-to-consumer/architecture", "docs/get-started/architecture-scenarios/business-to-consumer/provisioning", "docs/get-started/architecture-scenarios/business-to-consumer/authentication", @@ -327,8 +116,8 @@ "docs/get-started/architecture-scenarios/business-to-consumer/operations", { "group": "Launch Preparation", + "root": "docs/get-started/architecture-scenarios/business-to-consumer/launch", "pages": [ - "docs/get-started/architecture-scenarios/business-to-consumer/launch", "docs/get-started/architecture-scenarios/business-to-consumer/launch/tenant-check", "docs/get-started/architecture-scenarios/business-to-consumer/launch/testing", "docs/get-started/architecture-scenarios/business-to-consumer/launch/operations-readiness", @@ -341,8 +130,8 @@ }, { "group": "Business to Business", + "root": "docs/get-started/architecture-scenarios/business-to-business", "pages": [ - "docs/get-started/architecture-scenarios/business-to-business", "docs/get-started/architecture-scenarios/business-to-business/architecture", "docs/get-started/architecture-scenarios/business-to-business/provisioning", "docs/get-started/architecture-scenarios/business-to-business/authentication", @@ -355,8 +144,8 @@ "docs/get-started/architecture-scenarios/business-to-business/operations", { "group": "Launch Preparation (B2B)", + "root": "docs/get-started/architecture-scenarios/business-to-business/launch", "pages": [ - "docs/get-started/architecture-scenarios/business-to-business/launch", "docs/get-started/architecture-scenarios/business-to-business/launch/tenant-check", "docs/get-started/architecture-scenarios/business-to-business/launch/testing", "docs/get-started/architecture-scenarios/business-to-business/launch/operations-readiness", @@ -370,12 +159,12 @@ "docs/get-started/architecture-scenarios/b2e", { "group": "Multiple Organization Architecture", + "root": "docs/get-started/architecture-scenarios/multiple-organization-architecture", "pages": [ - "docs/get-started/architecture-scenarios/multiple-organization-architecture", { "group": "Single Identity Provider Organizations", + "root": "docs/get-started/architecture-scenarios/multiple-organization-architecture/single-identity-provider-organizations", "pages": [ - "docs/get-started/architecture-scenarios/multiple-organization-architecture/single-identity-provider-organizations", "docs/get-started/architecture-scenarios/multiple-organization-architecture/single-identity-provider-organizations/provisioning", "docs/get-started/architecture-scenarios/multiple-organization-architecture/single-identity-provider-organizations/authentication", "docs/get-started/architecture-scenarios/multiple-organization-architecture/single-identity-provider-organizations/branding", @@ -389,8 +178,8 @@ }, { "group": "SSO for Regular Web Apps", + "root": "docs/get-started/architecture-scenarios/sso-for-regular-web-apps", "pages": [ - "docs/get-started/architecture-scenarios/sso-for-regular-web-apps", "docs/get-started/architecture-scenarios/sso-for-regular-web-apps/part-1", "docs/get-started/architecture-scenarios/sso-for-regular-web-apps/part-2", "docs/get-started/architecture-scenarios/sso-for-regular-web-apps/part-3", @@ -400,8 +189,8 @@ }, { "group": "Server Application + API", + "root": "docs/get-started/architecture-scenarios/server-application-api", "pages": [ - "docs/get-started/architecture-scenarios/server-application-api", "docs/get-started/architecture-scenarios/server-application-api/part-1", "docs/get-started/architecture-scenarios/server-application-api/part-2", "docs/get-started/architecture-scenarios/server-application-api/part-3", @@ -412,8 +201,8 @@ }, { "group": "SPA + API", + "root": "docs/get-started/architecture-scenarios/spa-api", "pages": [ - "docs/get-started/architecture-scenarios/spa-api", "docs/get-started/architecture-scenarios/spa-api/part-1", "docs/get-started/architecture-scenarios/spa-api/part-2", "docs/get-started/architecture-scenarios/spa-api/part-3", @@ -424,8 +213,8 @@ }, { "group": "Mobile + API", + "root": "docs/get-started/architecture-scenarios/mobile-api", "pages": [ - "docs/get-started/architecture-scenarios/mobile-api", "docs/get-started/architecture-scenarios/mobile-api/part-1", "docs/get-started/architecture-scenarios/mobile-api/part-2", "docs/get-started/architecture-scenarios/mobile-api/part-3", @@ -439,6 +228,210 @@ ] } ] + }, + { + "group": "Auth0 Tenants", + "pages": [ + "docs/get-started/auth0-overview/tenants", + { + "group": "Create Tenants", + "root": "docs/get-started/auth0-overview/create-tenants", + "pages": [ + "docs/get-started/auth0-overview/create-tenants/set-up-multiple-environments", + "docs/get-started/auth0-overview/create-tenants/multi-tenant-apps-best-practices" + ] + }, + { + "group": "Configure Tenant Settings", + "root": "docs/get-started/tenant-settings", + "pages": [ + "docs/get-started/auth0-overview/dashboard/activity", + { + "group": "Signing Keys", + "root": "docs/get-started/tenant-settings/signing-keys", + "pages": [ + "docs/get-started/tenant-settings/signing-keys/rotate-signing-keys", + "docs/get-started/tenant-settings/signing-keys/revoke-signing-keys", + "docs/get-started/tenant-settings/signing-keys/view-signing-certificates", + "docs/get-started/tenant-settings/signing-keys/customer-signing-keys" + ] + }, + "docs/get-started/tenant-settings/enable-sso-for-legacy-tenants", + "docs/get-started/tenant-settings/find-your-tenant-name-or-tenant-id" + ] + }, + { + "group": "Tenant Membership", + "root": "docs/get-started/manage-dashboard-access", + "pages": [ + "docs/get-started/manage-dashboard-access/feature-access-by-role", + "docs/get-started/manage-dashboard-access/add-dashboard-users", + "docs/get-started/manage-dashboard-access/edit-dashboard-users", + "docs/get-started/manage-dashboard-access/remove-dashboard-users", + "docs/get-started/manage-dashboard-access/update-dashboard-user-email" + ] + }, + { + "group": "Team Membership", + "root": "docs/get-started/auth0-teams", + "pages": [ + "docs/get-started/auth0-teams/tenant-management", + "docs/get-started/auth0-teams/team-member-management", + "docs/get-started/auth0-teams/tenant-member-management", + "docs/get-started/auth0-teams/configure-security-policies", + "docs/get-started/auth0-teams/troubleshoot-teams", + "docs/get-started/auth0-teams/team-activity", + "docs/get-started/auth0-teams/quarterly-snapshot" + ] + } + ] + }, + { + "group": "Accessing Auth0", + "pages": [ + { + "group": "The Auth0 Dashboard", + "root": "docs/get-started/auth0-overview/dashboard", + "pages": [ + "docs/get-started/dashboard-profile/auth0-dashboard-login-session-management", + { + "group": "Multi-Factor Authentication", + "root": "docs/get-started/manage-dashboard-access/add-change-remove-mfa", + "pages": [ + "docs/get-started/manage-dashboard-access/add-change-remove-mfa/add-mfa", + "docs/get-started/manage-dashboard-access/add-change-remove-mfa/remove-or-change-dashboard-multi-factor-authentication" + ] + }, + "docs/get-started/manage-dashboard-access/configure-single-sign-on-for-auth0-dashboard" + ] + }, + { + "group": "APIs", + "root": "docs/get-started/apis", + "pages": [ + "docs/get-started/auth0-overview/set-up-apis", + "docs/get-started/apis/api-settings", + "docs/get-started/apis/api-access-policies-for-applications", + "docs/get-started/apis/add-api-permissions", + "docs/get-started/apis/delete-api-permissions", + { + "group": "Scopes", + "root": "docs/get-started/apis/scopes", + "pages": [ + "docs/get-started/apis/scopes/api-scopes", + "docs/get-started/apis/scopes/openid-connect-scopes", + "docs/get-started/apis/scopes/sample-use-cases-scopes-and-claims" + ] + }, + "docs/get-started/apis/configure-access-token-profile", + "docs/get-started/apis/configure-json-web-encryption", + "docs/get-started/apis/set-logical-api", + "docs/get-started/apis/configure-rich-authorization-requests", + "docs/get-started/apis/create-m2m-app-test", + "docs/get-started/apis/enable-role-based-access-control-for-apis" + ] + } + ] + }, + { + "group": "Applications", + "pages": [ + { + "group": "Application Types", + "root": "docs/get-started/applications", + "pages": [ + "docs/get-started/applications/first-party-and-third-party-applications", + "docs/get-started/applications/confidential-and-public-applications", + "docs/get-started/applications/confidential-and-public-applications/view-application-type" + ] + }, + { + "group": "Register Applications", + "pages": [ + "docs/get-started/auth0-overview/create-applications/", + "docs/get-started/auth0-overview/create-applications/native-apps", + "docs/get-started/auth0-overview/create-applications/single-page-web-apps", + "docs/get-started/auth0-overview/create-applications/regular-web-apps", + "docs/get-started/auth0-overview/create-applications/machine-to-machine-apps", + "docs/get-started/auth0-overview/create-applications/configure-an-identity-provider-in-access-gateway", + "docs/get-started/applications/dynamic-client-registration", + "docs/get-started/applications/remove-applications" + ] + }, + { + "group": "Configure Applications", + "pages": [ + "docs/get-started/applications/application-settings", + "docs/get-started/applications/credentials", + "docs/get-started/applications/wildcards-for-subdomains", + "docs/get-started/applications/configure-application-metadata", + { + "group": "Third-Party Applications", + "root": "docs/get-started/applications/third-party-applications", + "pages": [ + "docs/get-started/applications/third-party-applications/security-controls", + "docs/get-started/applications/third-party-applications/user-consent-and-third-party-applications", + "docs/get-started/applications/third-party-applications/configure-third-party-applications", + "docs/get-started/applications/third-party-applications/troubleshooting", + "docs/get-started/applications/third-party-applications/permissive-mode" + ] + } + ] + }, + { + "group": "Connections and Grant Types", + "pages": [ + "docs/get-started/applications/set-up-database-connections", + "docs/get-started/applications/test-database-connections", + "docs/get-started/applications/update-application-connections", + "docs/get-started/applications/application-grant-types", + "docs/get-started/applications/update-grant-types", + "docs/get-started/applications/application-access-to-apis-client-grants", + "docs/get-started/applications/revoke-api-access", + "docs/get-started/applications/enable-sso-for-applications" + ] + }, + { + "group": "Security and Compliance", + "pages": [ + "docs/get-started/applications/signing-algorithms", + "docs/get-started/applications/change-application-signing-algorithms", + "docs/get-started/applications/rotate-credentials", + "docs/get-started/applications/rotate-client-secret", + { + "group": "Configure FAPI Compliance", + "root": "docs/get-started/applications/configure-fapi-compliance", + "pages": [ + "docs/get-started/applications/configure-fapi-compliance/configure-auth0-to-pass-openid-fapi-certification-tests" + ] + }, + "docs/get-started/applications/configure-par", + "docs/get-started/applications/configure-jar", + { + "group": "Configure mTLS Authentication", + "root": "docs/get-started/applications/configure-mtls", + "pages": [ + "docs/get-started/applications/configure-mtls/set-up-the-customer-edge", + "docs/get-started/applications/configure-mtls/configure-mtls-for-a-tenant", + "docs/get-started/applications/configure-mtls/configure-mtls-for-a-client" + ] + }, + "docs/get-started/applications/configure-private-key-jwt", + "docs/get-started/applications/configure-client-initiated-backchannel-authentication" + ] + }, + { + "group": "Platform and Deployment", + "pages": [ + "docs/get-started/applications/enable-android-app-links-support", + "docs/get-started/applications/enable-universal-links-support-in-apple-xcode", + "docs/get-started/applications/set-up-cors", + "docs/get-started/applications/configure-applications-with-oidc-discovery", + "docs/get-started/applications/configure-ws-fed-applications", + "docs/get-started/applications/work-with-auth0-locally" + ] + } + ] } ] } diff --git a/main/config/navigation/quickstarts.json b/main/config/navigation/quickstarts.json index 461ccc25af..8ad842bba4 100644 --- a/main/config/navigation/quickstarts.json +++ b/main/config/navigation/quickstarts.json @@ -1,6 +1,6 @@ { + "root": "docs/quickstarts", "pages": [ - "docs/quickstarts", "docs/quickstart/agent-skills", { "group": "Single Page App", diff --git a/main/config/redirects.json b/main/config/redirects.json index c1bdebb447..aac09d274c 100644 --- a/main/config/redirects.json +++ b/main/config/redirects.json @@ -1,4 +1,44 @@ [ + { + "source": "docs/get-started/auth0-overview/create-tenants/child-tenants", + "destination": "docs/get-started/auth0-teams/tenant-management#manage-multiple-tenants/" + }, + { + "source": "docs/get-started/auth0-overview/create-tenants/create-multiple-tenants", + "destination": "docs/get-started/auth0-teams/tenant-management#manage-multiple-tenants" + }, + { + "source": "docs/get-started/onboarding/self-service-m2m", + "destination": "docs/get-started/auth0-overview/create-applications/machine-to-machine-apps" + }, + { + "source": "docs/get-started/auth0-overview", + "destination": "docs/get-started/identity-fundamentals/introduction-to-auth0" + }, + { + "source": "docs/get-started/tenant-settings/configure-device-user-code-settings", + "destination": "docs/get-started/tenant-settings#device-flow-user-code-format" + }, + { + "source": "docs/get-started/dashboard-profile/light-and-dark-themes", + "destination": "docs/get-started/auth0-overview/dashboard#manage-account-settings" + }, + { + "source": "docs/get-started/onboarding", + "destination": "docs/get-started/identity-fundamentals/introduction-to-auth0" + }, + { + "source": "docs/get-started/dashboard-profile", + "destination": "docs/get-started/auth0-overview/dashboard" + }, + { + "source": "docs/get-started/identity-fundamentals", + "destination": "docs/get-started/identity-fundamentals/identity-and-access-management" + }, + { + "source": "docs/customize/login-pages/advanced-customizations/configure", + "destination": "docs/customize/login-pages/advanced-customizations/configure/overview" + }, { "source": "docs/troubleshoot/customer-support/support-channels", "destination": "/docs/troubleshoot/customer-support" @@ -22302,5 +22342,13 @@ { "source": "/docs/ja-jp/secure/mdl-verification/*", "destination": "/docs/ja-jp/secure" + }, + { + "source": "/docs/get-started/authentication-and-authorization-flow/token-exchange-flow/call-your-api-using-the-custom-token-exchange-flow", + "destination": "/docs/get-started/authentication-and-authorization-flow/token-exchange-flow" + }, + { + "source": "docs/get-started/applications/confidential-and-public-applications/view-application-type", + "destination": "docs/get-started/applications/confidential-and-public-applications" } ] diff --git a/main/docs/deploy-monitor/deployment-options.mdx b/main/docs/deploy-monitor/deployment-options.mdx index fb1fd833fc..ff1caa02e6 100644 --- a/main/docs/deploy-monitor/deployment-options.mdx +++ b/main/docs/deploy-monitor/deployment-options.mdx @@ -2,6 +2,7 @@ description: Describes Auth0 public and private cloud deployment options. title: Deployment Options --- + Auth0 provides both public cloud and private cloud deployment options and tools to help you with your Enterprise deployment. The Auth0 identity platform can be deployed in the following ways: @@ -12,9 +13,28 @@ The Auth0 identity platform can be deployed in the following ways: | [**Private Cloud on AWS**](/docs/deploy-monitor/deploy-private-cloud/private-cloud-on-aws) | A dedicated, managed cloud service running on AWS providing isolation, higher performance, dev instances, Geo-HA add-ons and more | | [**Private Cloud on Azure**](/docs/deploy-monitor/deploy-private-cloud/private-cloud-on-azure) | A dedicated cloud service running on Azure providing isolation, higher performance, dev instances, Geo-HA add-ons and more | +## Public Cloud + +When you create a tenant in the public cloud environment, you choose a region. The region determines the locality of your tenant, which control where your data is hosted and forms part of your Auth0 domain. + +| Region | Locality | +|---------------------------|-----------| +| Australia | AU | +| Canada | CA | +| Europe | EU | +| Japan | JP | +| United Kingdom | UK | +| United States of America | US | + +Each reach has multiple sub-localities: for example, EU and EU-2, or US, US-3, US-4, and US-5. When you choose a region for your tenant, we automatically assign a sub-locality (meaning you can't choose a specific one). + +You can view your tenant's sub-locality on [Dashboard > Settings> General](https://manage.auth0.com/#/tenant/general) under **Region**. Your tenant's sub-locality may affect things like feature configuration details where noted in the docs. + +## Private Cloud + The **Private Cloud** packages are managed services that you can use if you: * Cannot use a multi-tenant public cloud service in your organization * Require a guaranteed level of requests per second (RPS) -If you have specific support requirements or need more information about the Professional Services we offer, please [contact Auth0 Sales](https://auth0.com/contact-us). \ No newline at end of file +If you have specific support requirements or need more information about the Professional Services we offer, please [contact Auth0 Sales](https://auth0.com/contact-us). diff --git a/main/docs/get-started/apis.mdx b/main/docs/get-started/apis.mdx index 0ece0ca566..76bfaece7d 100644 --- a/main/docs/get-started/apis.mdx +++ b/main/docs/get-started/apis.mdx @@ -1,9 +1,9 @@ --- +title: API Basics description: Explore key topics related to working with APIs. -sidebarTitle: Overview -title: APIs --- -An API is an entity that represents an external resource, capable of accepting and responding to protected resource requests made by applications. In the [OAuth2 specification](https://tools.ietf.org/html/rfc6749), an API maps to the **Resource Server**. + +An API is an entity that represents an external resource, capable of accepting and responding to protected resource requests made by applications. In the [OAuth2 specification](https://tools.ietf.org/html/rfc6749), an API maps to the Resource Server. At some point, your custom APIs will need to allow limited access to their protected resources on behalf of users. Authorization refers to the process of verifying what a user has access to. While often used interchangeably with [authentication](/docs/authenticate), authorization represents a fundamentally different function. To learn more, read [Authentication and Authorization](/docs/get-started/identity-fundamentals/authentication-and-authorization). @@ -22,9 +22,7 @@ Since only the API can know all of the possible actions that it can handle, it s To protect an API, you must register an API using the Auth0 Dashboard. To learn more, see [Register APIs](/docs/get-started/auth0-overview/set-up-apis). - Before you register any APIs in the Auth0 Dashboard, one API will already exist: the **Auth0 Management API**. To learn more about the features of the Management API and its available endpoints, see [Management API](https://auth0.com/docs/api/management/v2). - ## Learn more @@ -33,4 +31,4 @@ Before you register any APIs in the Auth0 Dashboard, one API will already exist: * [Which OAuth 2.0 Flow Should I Use?](/docs/get-started/authentication-and-authorization-flow/which-oauth-2-0-flow-should-i-use) * [Tokens](/docs/secure/tokens) * [Register APIs](/docs/get-started/auth0-overview/set-up-apis) -* [API Settings](/docs/get-started/apis/api-settings) \ No newline at end of file +* [API Settings](/docs/get-started/apis/api-settings) diff --git a/main/docs/get-started/apis/scopes.mdx b/main/docs/get-started/apis/scopes.mdx index 85fbfff3c6..1c59405c4a 100644 --- a/main/docs/get-started/apis/scopes.mdx +++ b/main/docs/get-started/apis/scopes.mdx @@ -1,8 +1,8 @@ --- -description: Understand the principle of scopes and explore general examples of their use. -sidebarTitle: Overview title: Scopes +description: Understand the principle of scopes and explore general examples of their use. --- + Different pieces of user information are often stored across a number of online resources. Users may upload and store photos with a service like Flickr, keep digital files on Dropbox, and store contacts and events in Google Calendar or on Facebook. Often, new applications will want to make use of the information that has already been created in an online resource. To do so, the application must ask for authorization to access this information on a user's behalf. Scopes define the specific actions applications can be allowed to do on a user's behalf. diff --git a/main/docs/get-started/applications.mdx b/main/docs/get-started/applications.mdx index e4ef9f0019..978561de15 100644 --- a/main/docs/get-started/applications.mdx +++ b/main/docs/get-started/applications.mdx @@ -1,24 +1,35 @@ --- -description: Learn the basics of registering and configuring your applications in Auth0. -sidebarTitle: Overview -title: Applications in Auth0 +title: Application Types on Auth0 +description: Learn about application types and the basics of registering and configuring applications on Auth0. --- -The term **application** or **app** in Auth0 does not imply any particular implementation characteristics. For example, it could be a native app that executes on a mobile device, a single-page application that executes on a browser, or a regular web application that executes on a server. -Auth0 categorizes apps based on these characteristics: +Auth0 categorizes applications based on these characteristics: -* **Application type**: To add authentication to your application, you must register it in the Auth0 Dashboard and select from one of the following application types: +* **Application type**, which can be either regular web applications, single-page web applications, native applications, or machine-to-machine applications. - + **Regular web application**: Traditional web apps that perform most of their application logic on the server (such as Express.js or ASP.NET). To learn how to set up a regular web application, read [Register Regular Web Applications](/docs/get-started/auth0-overview/create-applications/regular-web-apps). - + **Single page web application (SPA)**: JavaScript apps that perform most of their user interface logic in a web browser, communicating with a web server primarily using APIs (such as AngularJS + Node.js or React). To learn how to set up a Single-page web application, read [Register Single-Page Web Applications](/docs/get-started/auth0-overview/create-applications/single-page-web-apps). - + **Native application**: Mobile or Desktop applications that run natively on a device (such as iOS or Android). To learn how to set up a native application, read [Register Native Applications](/docs/get-started/auth0-overview/create-applications/native-apps). - + **Machine to machine (M2M) application**: Non-interactive applications, such as command-line tools, daemons, IoT devices, or services running on your backend. Typically, you use this option if you have a service that requires access to an API. To learn how to set up a native application, read [Register Machine-to-Machine Applications](/docs/get-started/auth0-overview/create-applications/machine-to-machine-apps). -* **Credential security**: According to the [OAuth 2.0 spec](https://tools.ietf.org/html/rfc6749#section-2.1), apps can be classified as either public or confidential; confidential apps can hold credentials securely, while public apps cannot. To learn more, read [Confidential and Public Applications](/docs/get-started/applications/confidential-and-public-applications). -* **Ownership**: Whether an app is classified as first- or third-party depends on app ownership and control. First-party apps are controlled by the same organization or person that owns the Auth0 domain. Third-party apps enable external parties or partners to securely access protected resources behind your API. To learn more, read [First-Party and Third-Party Applications](/docs/get-started/applications/first-party-and-third-party-applications). + * [Regular web applications](/docs/get-started/auth0-overview/create-applications/regular-web-apps) are traditional web apps that perform most of their application logic on the server (such as Express.js or ASP.NET). -## Manage applications settings + * [Single-page web applications (SPAs)](/docs/get-started/auth0-overview/create-applications/single-page-web-apps) are JavaScript apps that perform most of their user interface logic in a web browser, communicating with a web server primarily using APIs (such as AngularJS + Node.js or React). -You register applications in [Dashboard > Applications > Applications](https://manage.auth0.com/#/applications/{yourClientId}/settings). In addition to setting up applications in the Dashboard, you can also set up applications programmatically as described in the [OpenID Connect (OIDC) Dynamic Client Registration 1.0](https://openid.net/specs/openid-connect-registration-1_0.html) specification. + * [Native applications](/docs/get-started/auth0-overview/create-applications/native-apps) are mobile or desktop applications that run natively on a device (such as iOS or Android). + + * [Machine-to-machine (M2M) applications](/docs/get-started/auth0-overview/create-applications/machine-to-machine-apps) are non-interactive applications, such as command-line tools, daemons, IoT devices, or services running on your backend. Typically, you use this option if you have a service that requires access to an API. + +* **Credential security** describes the app's ability to store secrets. Apps can be [public or confidential](/docs/get-started/applications/confidential-and-public-applications). + + * Public applications cannot securely store credentials. + + * Confidential applications can securely store credentials. + +* **Ownership** describes the app's trust relationship (who owns and operates the application), which can be either [first-party and third-party](/docs/get-started/applications/first-party-and-third-party-applications). + + * First-party apps are controlled by the same organization or person that owns the Auth0 domain. + + * Third-party apps enable external parties or partners to securely access protected resources behind your API. + +## Manage application settings + +You register applications in [Dashboard > Applications > Applications](https://manage.auth0.com/#/applications/{yourClientId}/settings). In addition to setting up applications in the Dashboard, you can also set up applications programmatically as described in the [OpenID Connect (OIDC) Dynamic Client Registration 1.0](https://openid.net/specs/openid-connect-registration-1_0.html) specification. You can set up a more complex configuration that allows users to log in differently for different apps. To learn more, read [Multi-Tenant Application Best Practices](/docs/get-started/auth0-overview/create-tenants/multi-tenant-apps-best-practices) and [Create Multiple Tenants](/docs/get-started/auth0-overview/create-tenants/create-multiple-tenants). @@ -28,10 +39,6 @@ By default, Auth0 enables all connections associated with your tenant when you c You can [monitor apps](/docs/deploy-monitor/monitor/monitor-applications) and perform end-to-end testing using your own tests. Auth0 stores [log data](/docs/deploy-monitor/logs) including Dashboard administrator actions, successful and failed user authentications, and password change requests. You can use log streaming in [Auth0 Marketplace](https://marketplace.auth0.com/features/log-streaming) to export your log data and use tools like Sumo Logic, Splunk, or Mixpanel to analyze and store your log data. -## Remove applications - -You can [remove an application](/docs/get-started/applications/remove-applications) using the Dashboard or the Management API. - ## Manage client secrets A client secret is a secret known only to your application and the authorization server. It protects your resources by only granting [tokens](/docs/secure/tokens) to authorized requestors. @@ -41,12 +48,3 @@ Protect your client secrets and **never** include them in mobile or browser-base ## Grant types Auth0 provides many different authentication and authorization grant types or flows and allows you to indicate which grant types are appropriate based on the `grant_types` property of your Auth0-registered app. To learn more, read [Application Grant Types](/docs/get-started/applications/application-grant-types). - -## Learn more - -* [Application Settings](/docs/get-started/applications/application-settings) -* [Confidential and Public Applications](/docs/get-started/applications/confidential-and-public-applications) -* [First-Party and Third-Party Applications](/docs/get-started/applications/first-party-and-third-party-applications) -* [Application Grant Types](/docs/get-started/applications/application-grant-types) -* [Subdomain URL Placeholders](/docs/get-started/applications/wildcards-for-subdomains) -* [Dynamic Application Registration](/docs/get-started/applications/dynamic-client-registration) diff --git a/main/docs/get-started/applications/application-settings.mdx b/main/docs/get-started/applications/application-settings.mdx index 47f7ab2a87..604e512548 100644 --- a/main/docs/get-started/applications/application-settings.mdx +++ b/main/docs/get-started/applications/application-settings.mdx @@ -1,7 +1,8 @@ --- -description: Describe the settings related to applications available in the Auth0 Dashboard. title: Application Settings +description: Describe the settings related to applications available in the Auth0 Dashboard. --- + On the [Applications](https://manage.auth0.com/#/applications) page of the Dashboard, locate your application in the list, and click its name to view the available settings. diff --git a/main/docs/get-started/applications/confidential-and-public-applications.mdx b/main/docs/get-started/applications/confidential-and-public-applications.mdx index 5b3803d8b5..00d367be2e 100644 --- a/main/docs/get-started/applications/confidential-and-public-applications.mdx +++ b/main/docs/get-started/applications/confidential-and-public-applications.mdx @@ -1,17 +1,10 @@ --- -description: Describes the difference between confidential and public application types. -sidebarTitle: Overview title: Confidential and Public Applications +sidebarTitle: Confidental and Public +description: Learn the difference between confidential and public applications are and how it relates to your Auth0 application settings. --- -According to the [OAuth 2.0 specification](https://tools.ietf.org/html/rfc6749#section-2.1), applications can be classified as either confidential or public. The main difference relates to whether or not the application is able to hold credentials (such as a client ID and secret) securely. This affects the type of authentication the applications can use. - -Confidential/public and first-party/third-party are independent classifications. Confidential or public describes the application's authentication capability (whether it can hold a secret). First-party or third-party describes the trust relationship (who owns and operates the application). To learn more, read [First-Party and Third-Party Applications](/docs/get-started/applications/first-party-and-third-party-applications). - - -When you create an application using the Auth0 Dashboard, Auth0 will ask you what Auth0 application type you want to assign to the new application and use that information to determine whether the application is confidential or public. - -To learn more, read [Check if Application is Confidential or Public](/docs/get-started/applications/confidential-and-public-applications/view-application-type). +According to the [OAuth 2.0 specification](https://tools.ietf.org/html/rfc6749#section-2.1), an application is classified as either confidential or public depending on its authentication capability (whether it can hold a secret). ## Confidential applications @@ -24,6 +17,7 @@ Confidential applications use a trusted backend server and can use grant types t These are considered confidential applications: * A web application with a secure backend that uses the [Authorization Code Flow](/docs/get-started/authentication-and-authorization-flow/authorization-code-flow), [Resource Owner Password Flow](/docs/get-started/authentication-and-authorization-flow/resource-owner-password-flow), or Resource Owner Password Flow with realm support + * A machine-to-machine (M2M) application that uses the [Client Credentials Flow](/docs/get-started/authentication-and-authorization-flow/client-credentials-flow) ### ID tokens @@ -31,6 +25,7 @@ These are considered confidential applications: Because confidential applications are capable of holding secrets, you can have ID tokens issued to them that have signed in one of two ways: * Symmetrically, using their client secret (`HS256`) + * Asymmetrically, using a private key (`RS256`) ## Public applications @@ -44,6 +39,7 @@ Public applications can only use grant types that do not require the use of thei These are public applications: * A native desktop or mobile application that uses the [Authorization Code Flow with PKCE](/docs/get-started/authentication-and-authorization-flow/authorization-code-flow-with-pkce) + * A JavaScript-based client-side web application (such as a single-page app) that uses the [Implicit Flow](/docs/get-started/authentication-and-authorization-flow/implicit-flow-with-form-post) grant ### ID tokens @@ -53,9 +49,37 @@ Because public applications are unable to hold secrets, [ID tokens](/docs/secure * Signed asymmetrically using a private key (`RS256`) * Verified using the public key corresponding to the private key used to sign the token -## Learn more +## Manage authentication method and credentials + +Auth0 determines if an application is confidential or public based on the application type and, if available, the application's **Authentication Method** setting. + +Single-page apps and native apps are public. Regular web apps and machine-to-machine apps are confidential unless set to have no authentication method. + +The **Authentication Method** setting defines how an application authenticates against the Auth0 Authentication API [Get Token endpoint](https://auth0.com/docs/api/authentication/authorization-code-flow/get-token). + +You can check whether an application is registered with Auth0 as a confidential or public application in the Auth0 Dashboard. From [Applications > Applications](https://manage.auth0.com/#/applications), select the name of the application to view. + +If the **Credentials** tab is not available, the application is a public application. Public applications cannot maintain the confidentiality of the credentials required for Token endpoint authentication methods like **Post** and **Basic**. + +If the **Credentials** tab is available, the application is a confidental application. + +![Configure Private Key JWT Authentication - Auth0 Dashboard instructions](/docs/images/cdy7uua7fh8z/33kfi48tkbMIOQJ8PBxj76/5b79ffda11ad58b27128068057e6e05c/Default_App_-_Creds_-_English.png) + +This section lets you manage the application authentication methods: + +* **None**: Public application without a client secret. +* **Client Secret Post**: Application using POST request body parameters to send a client secret. +* **Client Secret Basic**: Application using the HTTP BASIC authentication scheme to send a client secret. +* **Private Key JWT**: Application using asymmetric authentication. + +## How Auth0 determines credential security + +Auth0 determines if an application is confidential or public based on the application type and, if available, the application's selected authentication method: + +* Regular web apps and machine-to-machine apps are confidential unless you configure them to have no authentication method. + + You can view and [manage the authentication method and credentials](/docs/secure/application-credentials) for these application types from **[Auth0 Dashboard > Applications > Applications](https://manage.auth0.com/#/applications) > [Your Application] > Credentials**. + +* Single-page apps and native apps are public. -* [Check if Application is Confidential or Public](/docs/get-started/applications/confidential-and-public-applications/view-application-type) -* [First-Party and Third-Party Applications](/docs/get-started/applications/first-party-and-third-party-applications) -* [Third-Party Applications](/docs/get-started/applications/third-party-applications) -* [User Consent and Third-Party Applications](/docs/get-started/applications/third-party-applications/user-consent-and-third-party-applications) + These application types cannot maintain the confidentiality of the credentials required for Token endpoint authentication methods, so the Auth0 Dashboard does not include a authentication method or credentials settings for these application types. diff --git a/main/docs/get-started/applications/confidential-and-public-applications/view-application-type.mdx b/main/docs/get-started/applications/confidential-and-public-applications/view-application-type.mdx deleted file mode 100644 index 9762017f22..0000000000 --- a/main/docs/get-started/applications/confidential-and-public-applications/view-application-type.mdx +++ /dev/null @@ -1,29 +0,0 @@ ---- -description: Describes how to check whether an application is registered with Auth0 as a confidential or public app using the Auth0 Management Dashboard. -title: Check if Application is Confidential or Public ---- -You can check whether an application is registered with Auth0 as a confidential or public application. To learn more, read [Confidential and Public Application](/docs/get-started/applications/confidential-and-public-applications). - -Auth0 determines if an application is confidential or public based on the **Authentication Method** setting, which defines how an application authenticates against the Auth0 Authentication API [Get Token](https://auth0.com/docs/api/authentication/authorization-code-flow/get-token) endpoint. - -1. In the Auth0 Dashboard, go to [Applications > Applications](https://manage.auth0.com/#/applications), and then select the name of the application to view. -2. If the **Credentials** view is not available, the application is a public application. -3. If the **Credentials** view is available, then select it and locate the **Authentication Method** field. - - ![Configure Private Key JWT Authentication - Auth0 Dashboard instructions](/docs/images/cdy7uua7fh8z/33kfi48tkbMIOQJ8PBxj76/5b79ffda11ad58b27128068057e6e05c/Default_App_-_Creds_-_English.png) - -Use the applicable method: - -* **None**: Public application without a client secret. -* **Client Secret Post**: Application using POST request body parameters to send a client secret. -* **Client Secret Basic**: Application using the HTTP BASIC authentication scheme to send a client secret. -* **Private Key JWT**: Application using asymmetric authentication. - -These values map to confidential and public applications as follows: - -| Application Type | Example | Token Endpoint Authentication Method | -| --- | --- | --- | -| **Public** | Single-page or native | **None** | -| **Confidential** | Regular web or machine-to-machine | **Basic**, **Post**, **Private Key JWT**, **Unspecified** | - -Public applications cannot maintain the confidentiality of the credentials required for Token endpoint authentication methods like **Post** and **Basic**. diff --git a/main/docs/get-started/applications/configure-fapi-compliance.mdx b/main/docs/get-started/applications/configure-fapi-compliance.mdx index aa03f84d8b..7e1f0a8a44 100644 --- a/main/docs/get-started/applications/configure-fapi-compliance.mdx +++ b/main/docs/get-started/applications/configure-fapi-compliance.mdx @@ -1,12 +1,10 @@ --- -description: Learn how to configure FAPI compliance for an Auth0 tenant. -sidebarTitle: Overview title: Configure FAPI Compliance +description: Learn how to configure FAPI compliance for an Auth0 tenant. --- - + To use Highly Regulated Identity features, you must have an Enterprise Plan with the Highly Regulated Identity add-on. Refer to [Auth0 Pricing](https://auth0.com/pricing/) for details. - To help customers configure their Auth0 tenant to adhere to one of the Financial-grade API (FAPI) profiles, the Application model includes a `compliance_level` property that can be set to one of three values: @@ -28,11 +26,6 @@ For example, both the `fapi1_adv_pkj_par` and `fapi1_adv_mtls_par` compliance le } ``` - - - - - In some cases, setting a compliance level also changes Auth0’s behavior. For example, both the `fapi1_adv_pkj_par` and `fapi1_adv_mtls_par` compliance levels cause Auth0 to include a `s_hash` claim in the returned ID token containing a SHA256 hash of the state value. This allows the ID tokens to act as a detached signature. The following tables summarize the additional validation rules and changes to Auth0’s behavior that each compliance level enables: @@ -65,8 +58,9 @@ The following tables summarize the additional validation rules and changes to Au ## Configure FAPI Compliance for a client - + + To perform this using the Auth0 Dashboard: 1. Navigate to **Auth0 Dashboard > Applications**. @@ -82,9 +76,9 @@ The options to configure FAPI compliance are: * **FAPI 1 Advanced profile using mTLS and PAR**: The customer would like this client to behave in accordance with the FAPI1 Advanced profile using [mTLS](/docs/get-started/applications/configure-mtls) and [PAR](/docs/get-started/applications/configure-par). * **FAPI 2.0 Security Profile with Private Key JWT and certificate binding**: The customer would like this client to behave in accordance with the FAPI2.0 Security Profile using [Private Key JWT Client Authentication](/docs/get-started/applications/configure-private-key-jwt) and [mTLS Token Sender-Constraining](/docs/secure/sender-constraining/mtls-sender-constraining). * **FAPI 2.0 Security Profile with mTLS and certificate binding**: The customer would like this client to behave in accordance with the FAPI2.0 Security Profile using [mTLS Client Authentication](/docs/get-started/applications/configure-mtls) and [mTLS Token Sender-Constraining](/docs/secure/sender-constraining/mtls-sender-constraining). + - - + Use the [Management API](https://auth0.com/docs/api/management/v2) to set the `compliance_level` property with a `POST` or `PATCH` request: ```bash lines @@ -96,11 +90,6 @@ curl --location --request PATCH 'https://{YOUR_DOMAIN}/api/v2/clients/$client_id }' ``` - - - - - To return the `compliance_level` property, use a `GET` request: ```bash lines @@ -109,8 +98,8 @@ curl --location 'https://{YOUR_DOMAIN}/api/v2/clients/{YOUR_CLIENT_ID} \ ``` For FAPI 2.0 compliance, you can configure the expiry on pushed authorization requests to a value that is less than 600 seconds, with a default of 30 seconds. You can set the expiry value using the Management API. - - + + ## Learn more diff --git a/main/docs/get-started/applications/configure-mtls.mdx b/main/docs/get-started/applications/configure-mtls.mdx index 4a3eddd3d4..8f5070ab0b 100644 --- a/main/docs/get-started/applications/configure-mtls.mdx +++ b/main/docs/get-started/applications/configure-mtls.mdx @@ -1,18 +1,10 @@ --- -description: Learn how to configure mTLS authentication. -sidebarTitle: Overview title: Configure mTLS Authentication +description: Learn how to configure mTLS authentication. --- - + To use Highly Regulated Identity features, you must have an Enterprise Plan with the Highly Regulated Identity add-on. Refer to [Auth0 Pricing](https://auth0.com/pricing/) for details. - Use the [Auth0 Management API](https://auth0.com/docs/api/management/v2) or [Auth0 Dashboard](https://manage.auth0.com/) to configure mTLS authentication. To learn more about how mTLS authentication works at Auth0, read [Authenticate with mTLS](/docs/get-started/authentication-and-authorization-flow/authenticate-with-mtls). - -| Read... | To learn... | -| --- | --- | -| [Set up your customer edge](/docs/get-started/applications/configure-mtls/set-up-the-customer-edge) | How to set up your customer edge to validate your client certificate and forward requests to Auth0's edge network. | -| [Configure mTLS for a client](/docs/get-started/applications/configure-mtls/configure-mtls-for-a-client) | How to configure mTLS authentication for your Auth0 application. | -| [Configure mTLS for a tenant](/docs/get-started/applications/configure-mtls/configure-mtls-for-a-tenant) | How to configure mTLS authentication for your Auth0 tenant. | \ No newline at end of file diff --git a/main/docs/get-started/applications/first-party-and-third-party-applications.mdx b/main/docs/get-started/applications/first-party-and-third-party-applications.mdx index 3ad502d781..f9e065a84d 100644 --- a/main/docs/get-started/applications/first-party-and-third-party-applications.mdx +++ b/main/docs/get-started/applications/first-party-and-third-party-applications.mdx @@ -2,21 +2,18 @@ title: First-Party and Third-Party Applications description: "Learn the difference between first-party and third-party applications in Auth0." --- - import {AuthCodeBlock} from "/snippets/AuthCodeBlock.jsx"; import {AuthCodeGroup} from "/snippets/AuthCodeGroup.jsx"; When you register an application in Auth0, you decide whether it is first-party or third-party based on who owns and operates it. -- First-party applications: Owned and operated by your organization. You control their deployment, credentials, and behavior. -- Third-party applications: Owned and operated by an external organization, such as a partner, an independent developer, or an AI agent. You grant them access to your resources, but you cannot directly control what they do with that access. - -"Third-party" refers to operational control, not authorship. Many organizations outsource development of their own applications. For example, a contractor building your application does not make it third-party. The key distinction is: who deploys it, who holds the credentials, and who can stop it. - +* **First-party applications** are owned and operated by your organization. You control their deployment, credentials, and behavior. + +* **Third-party applications** are owned and operated by an external organization, such as a partner, an independent developer, or an AI agent. You grant them access to your resources, but you cannot directly control what they do with that access. -Confidential/public and first-party/third-party are independent classifications. Confidential or public describes the application's authentication capability (whether it can hold a secret). First-party or third-party describes the trust relationship (who owns and operates the application). + "Third-party" refers to operational control, not authorship. Many organizations outsource development of their own applications. For example, a contractor building your application does not make it third-party. The key distinction is: who deploys it, who holds the credentials, and who can stop it. -Both first-party and third-party applications can be confidential (Regular Web App) or public (SPA, Native). A third-party Regular Web App is both confidential and third-party. +Both first-party and third-party applications can be confidential (regular web apps) or public (SPAs, native apps). ## First-party applications diff --git a/main/docs/get-started/applications/third-party-applications.mdx b/main/docs/get-started/applications/third-party-applications.mdx index c2acd27ecd..b7c1e363f9 100644 --- a/main/docs/get-started/applications/third-party-applications.mdx +++ b/main/docs/get-started/applications/third-party-applications.mdx @@ -1,6 +1,5 @@ --- title: Third-Party Applications -sidebarTitle: Overview description: Configure third-party applications to access your APIs with enhanced security controls. --- import {AuthCodeBlock} from "/snippets/AuthCodeBlock.jsx"; @@ -75,12 +74,3 @@ To learn more, read [User Consent and Third-Party Applications](/docs/get-starte ## Dynamic Client Registration [Dynamic Client Registration](/docs/get-started/applications/dynamic-client-registration) creates third-party applications with enhanced security controls by default. Before enabling DCR for third-party applications, you must [configure default API permissions](/docs/get-started/applications/dynamic-client-registration#configure-api-access-for-dcr-clients) so dynamically registered clients can access your APIs. - -## Learn more - -- [First-Party and Third-Party Applications](/docs/get-started/applications/first-party-and-third-party-applications) -- [Security Controls for Third-Party Applications](/docs/get-started/applications/third-party-applications/security-controls) -- [Configure Third-Party Applications](/docs/get-started/applications/third-party-applications/configure-third-party-applications) -- [User Consent and Third-Party Applications](/docs/get-started/applications/third-party-applications/user-consent-and-third-party-applications) -- [Troubleshoot Third-Party Applications](/docs/get-started/applications/third-party-applications/troubleshooting) -- [Application Access to APIs: Client Grants](/docs/get-started/applications/application-access-to-apis-client-grants) diff --git a/main/docs/get-started/architecture-scenarios/b2e.mdx b/main/docs/get-started/architecture-scenarios/b2e.mdx index 28a2c7d8b2..9a166a7756 100644 --- a/main/docs/get-started/architecture-scenarios/b2e.mdx +++ b/main/docs/get-started/architecture-scenarios/b2e.mdx @@ -1,7 +1,8 @@ --- -description: Explains the architecture scenario of B2E with a large organization that wants to extend their existing enterprise directory service. title: Business to Employees +description: Explains the architecture scenario of B2E with a large organization that wants to extend their existing enterprise directory service. --- + The B2E (Business to Employees) scenario involves applications that are used by employee users. These are applications that are targeted toward users who are typically acting on behalf of an organization such as an employer, a university, or a group in which they are a member, as opposed to acting on their own behalf. Such applications that are custom written by the organization may use the OIDC/OAuth protocol to externalize authentication whereas those that have been purchased will often use the SAML protocol. In either case, the enterprise will typically want to use some form of Enterprise connection, such as a SAML Identity Provider, ADFS, Google Workspace, Azure AD or a directory service such as AD or OpenLDAP, and less frequently, a custom DB, for authentication of enterprise users. diff --git a/main/docs/get-started/architecture-scenarios/business-to-business.mdx b/main/docs/get-started/architecture-scenarios/business-to-business.mdx index 516a8669af..4a50b72fd5 100644 --- a/main/docs/get-started/architecture-scenarios/business-to-business.mdx +++ b/main/docs/get-started/architecture-scenarios/business-to-business.mdx @@ -1,8 +1,8 @@ --- -description: Explains the architecture scenario B2B IAM with a SAAS application. -sidebarTitle: Overview title: Business to Business +description: Explains the architecture scenario B2B IAM with a SAAS application. --- + This guidance is relevant to **all** project stakeholders. We recommend reading it in its entirety at least once, even if you've already started your journey with Auth0. We provide a Project Planning Guide in PDF format, details about how to get started with each phase of the implementation process, and checklists to help you manage the tasks in each phase. There are many different ways Auth0 can be integrated into the B2B IAM project architecture. Auth0's flexibility comprehensively supports many different use cases however your project may not require all of the capabilities provided by Auth0. Knowing what, when, and how best to implement something will help you focus on completing the necessary tasks at the right time. @@ -19,30 +19,6 @@ Many B2B platforms implement some form of isolation and/or branding for their cu [Multiple Organization Architecture](/docs/get-started/architecture-scenarios/multiple-organization-architecture) -## Get started - -Customers using Auth0 for Business-to-Business (B2B) projects typically share a common set of goals and objectives, and in the sections that follow we'll focus on our real-world customer implementation experiences to help you deliver your solution efficiently. - - - -Auth0 provides recommendations and best practice suggestions in an ad hoc way throughout this guide in panels like this one. You can also obtain detailed guidance regarding specific functionality by speaking with your account representative or a member of our Auth0 [Professional Services](/docs/get-started/professional-services) team. - - - -| Read | To learn... | -| --- | --- | -| [Architecture](/docs/get-started/architecture-scenarios/business-to-business/architecture) | How to configure your Auth0 tenant architecture affects your B2B IAM implementation. | -| [Provisioning](/docs/get-started/architecture-scenarios/business-to-business/provisioning) | About user provisioning functionality and considerations for your B2B IAM implementation. | -| [Authentication](/docs/get-started/architecture-scenarios/business-to-business/authentication) | How authentication works in your B2B IAM implementation. | -| [Branding](/docs/get-started/architecture-scenarios/business-to-business/branding) | How to configure Auth0 items to reflect your brand and desired user experience. | -| [Deployment Automation](/docs/get-started/architecture-scenarios/business-to-business/deployment) | How Auth0 tooling helps to automate tenant deployment. | -| [Quality Assurance](/docs/get-started/architecture-scenarios/business-to-business/quality-assurance) | About quality assurance considerations for your B2B IAM implementations. | -| [Profile Management](/docs/get-started/architecture-scenarios/business-to-business/profile-management) | About user profile management planning considerations for your B2B IAM implementation. | -| [Authorization](/docs/get-started/architecture-scenarios/business-to-business/authorization) | About user authorization and related planning considerations for your B2B IAM implementation. | -| [Logout](/docs/get-started/architecture-scenarios/business-to-business/logout) | About user logout planning considerations for your B2B IAM implementation. | -| [Operations](/docs/get-started/architecture-scenarios/business-to-business/operations) | How to operationalize your Auth0 tenant environments. | -| [Launch Preparation](/docs/get-started/architecture-scenarios/business-to-business/launch) | About launch preparation considerations for your B2B IAM implementation. | - ## Implementation planning checklists Use the links below to download a spreadsheet that includes tasks for each phase of a Software Development Lifecycle (SDLC) project. @@ -57,4 +33,8 @@ Use the links below to download a spreadsheet that includes tasks for each phase [Deploy Checklist](https://cdn2.auth0.com/docs/media/articles/architecture-scenarios/checklists/Deploy-Checklist.xlsx) -[Monitor Checklist](https://cdn2.auth0.com/docs/media/articles/architecture-scenarios/checklists/Monitor-Checklist.xlsx) \ No newline at end of file +[Monitor Checklist](https://cdn2.auth0.com/docs/media/articles/architecture-scenarios/checklists/Monitor-Checklist.xlsx) + +## Get started + +Customers using Auth0 for Business-to-Business (B2B) projects typically share a common set of goals and objectives, and in the sections that follow we'll focus on our real-world customer implementation experiences to help you deliver your solution efficiently. diff --git a/main/docs/get-started/architecture-scenarios/business-to-business/launch.mdx b/main/docs/get-started/architecture-scenarios/business-to-business/launch.mdx index 677dd9dd01..296a4affee 100644 --- a/main/docs/get-started/architecture-scenarios/business-to-business/launch.mdx +++ b/main/docs/get-started/architecture-scenarios/business-to-business/launch.mdx @@ -1,19 +1,8 @@ --- -description: Launch preparation considerations for your B2B IAM implementation. -sidebarTitle: Overview title: Launch Preparation (B2B) +description: Launch preparation considerations for your B2B IAM implementation. --- -Use this guide as you prepare for the launch of your application. We’ve included reminders about some content you may have viewed earlier during your planning or development phases as well as some new content unique to the launch phase. The sections below are useful to developers and project owners to ensure that you have everything lined up for a smooth launch. There are several things to check so it may help to assign ownership of different sections to different members of your team. -* [Tenant Check](/docs/get-started/architecture-scenarios/business-to-business/launch/tenant-check): Tenant Checks to perform before launch of your B2B IAM implementation. -* [Testing Complete](/docs/get-started/architecture-scenarios/business-to-business/launch/testing): Testing preparation for the launch of your B2B IAM implementation. -* [Operations Readiness](/docs/get-started/architecture-scenarios/business-to-business/launch/operations-readiness): Operations checks to perform before launch of your B2B IAM implementation. -* [Compliance Readiness](/docs/get-started/architecture-scenarios/business-to-business/launch/compliance-readiness): Compliance checks to perform before launch of your B2B IAM implementation. -* [Support Readiness](/docs/get-started/architecture-scenarios/business-to-business/launch/support-readiness): Support readiness for the launch of your B2B IAM implementation. -* [Launch Day Preparation](/docs/get-started/architecture-scenarios/business-to-business/launch/launch-day): Launch preparation considerations for your B2B IAM implementation. - -## Project Planning Guide - -We provide planning guidance in PDF format that you can download and refer to for details about our recommended strategies. +Use this guide as you prepare for the launch of your application. We’ve included reminders about some content you may have viewed earlier during your planning or development phases as well as some new content unique to the launch phase. The sections below are useful to developers and project owners to ensure that you have everything lined up for a smooth launch. There are several things to check so it may help to assign ownership of different sections to different members of your team. -[B2B IAM Project Planning Guide](https://assets.ctfassets.net/cdy7uua7fh8z/63F0WOPJdVzsPMxV1Xvp8x/7a329487c5e890d8e820f6a48983b46a/B2B_Project_Planning.pdf) \ No newline at end of file +We provide planning guidance in PDF format that you can download and refer to for details about our recommended strategies: [B2B IAM Project Planning Guide](https://assets.ctfassets.net/cdy7uua7fh8z/63F0WOPJdVzsPMxV1Xvp8x/7a329487c5e890d8e820f6a48983b46a/B2B_Project_Planning.pdf) diff --git a/main/docs/get-started/architecture-scenarios/business-to-consumer.mdx b/main/docs/get-started/architecture-scenarios/business-to-consumer.mdx index 621c0b3f0a..e26bbbbe30 100644 --- a/main/docs/get-started/architecture-scenarios/business-to-consumer.mdx +++ b/main/docs/get-started/architecture-scenarios/business-to-consumer.mdx @@ -1,8 +1,8 @@ ---- -description: Explains the architecture scenario B2C IAM with an eCommerce or SAAS application. -sidebarTitle: Overview + title: Business to Consumer +description: Explains the architecture scenario B2C IAM with an eCommerce or SAAS application. --- + This guidance is relevant to **all** project stakeholders. We recommend reading it in its entirety at least once, even if you've already started your journey with Auth0. We provide a Project Planning Guide in PDF format, details about how to get started with each phase of the implementation process, and checklists to help you manage the tasks in each phase. There are many different ways Auth0 can be integrated into the CIAM project architecture. Auth0's flexibility comprehensively supports many different use cases however your project may not require all of the capabilities provided by Auth0. Knowing what, when, and how best to implement something will help you focus on completing the necessary tasks at the right time. @@ -13,30 +13,6 @@ We provide planning guidance in PDF format that you can download and refer to fo [B2C IAM Project Planning Guide](https://assets.ctfassets.net/cdy7uua7fh8z/3er1aEQ7Ul0q3c9leJWczR/b1f18b4c16abb7e78b01e4eb2b52bb8e/B2C_Project_Planning.pdf) -## Get started - -Customers using Auth0 for Business-to-Consumer (B2C) projects typically share a common set of goals and objectives, and in the sections that follow we'll focus on our real-world customer implementation experiences to help you deliver your solution efficiently. - - -### Best Practice - -Auth0 provides recommendations and best practice suggestions in an *ad hoc* way throughout this guide in panels like this one. You can also obtain detailed guidance regarding specific functionality by speaking with your account representative or a member of our Auth0 [Professional Services](/docs/get-started/professional-services) team. - - -| Read | To learn... | -| --- | --- | -| [Architecture](/docs/get-started/architecture-scenarios/business-to-consumer/architecture) | How to configure your Auth0 tenant architecture affects your B2C IAM implementation. | -| [Provisioning](/docs/get-started/architecture-scenarios/business-to-consumer/provisioning) | About user provisioning functionality and considerations for your B2C IAM implementation. | -| [Authentication](/docs/get-started/architecture-scenarios/business-to-consumer/authentication) | How authentication works in your B2C IAM implementation. | -| [Branding](/docs/get-started/architecture-scenarios/business-to-consumer/branding) | How to configure Auth0 items to reflect your brand and desired user experience. | -| [Deployment Automation](/docs/get-started/architecture-scenarios/business-to-consumer/deployment) | How Auth0 tooling helps to automate tenant deployment. | -| [Quality Assurance](/docs/get-started/architecture-scenarios/business-to-consumer/quality-assurance) | About quality assurance considerations for your B2C IAM implementations. | -| [Profile Management](/docs/get-started/architecture-scenarios/business-to-consumer/profile-management) | About user profile management planning considerations for your B2C IAM implementation. | -| [Authorization](/docs/get-started/architecture-scenarios/business-to-consumer/authorization) | About user authorization and related planning considerations for your B2C IAM implementation. | -| [Logout](/docs/get-started/architecture-scenarios/business-to-consumer/logout) | About user logout planning considerations for your B2C IAM implementation. | -| [Operations](/docs/get-started/architecture-scenarios/business-to-consumer/operations) | How to operationalize your Auth0 tenant environments. | -| [Launch Preparation](/docs/get-started/architecture-scenarios/business-to-consumer/launch) | About launch preparation considerations for your B2C IAM implementation. | - ## Implementation planning checklists Use the links below to download a spreadsheet that includes tasks for each phase of a Software Development Lifecycle (SDLC) project. @@ -52,3 +28,7 @@ Use the links below to download a spreadsheet that includes tasks for each phase [Deploy Checklist](https://cdn2.auth0.com/docs/media/articles/architecture-scenarios/checklists/Deploy-Checklist.xlsx) [Monitor Checklist](https://cdn2.auth0.com/docs/media/articles/architecture-scenarios/checklists/Monitor-Checklist.xlsx) + +## Get started + +Customers using Auth0 for Business-to-Consumer (B2C) projects typically share a common set of goals and objectives, and in the sections that follow we'll focus on our real-world customer implementation experiences to help you deliver your solution efficiently. diff --git a/main/docs/get-started/architecture-scenarios/business-to-consumer/launch.mdx b/main/docs/get-started/architecture-scenarios/business-to-consumer/launch.mdx index 7d5a8e44c0..3644691ba9 100644 --- a/main/docs/get-started/architecture-scenarios/business-to-consumer/launch.mdx +++ b/main/docs/get-started/architecture-scenarios/business-to-consumer/launch.mdx @@ -1,18 +1,8 @@ --- -description: Launch preparation considerations for your B2C IAM implementation. title: Launch Preparation (B2C) +description: Launch preparation considerations for your B2C IAM implementation. --- -Use this guide as you prepare for the launch of your application. We’ve included reminders about some content you may have viewed earlier during your planning or development phases as well as some new content unique to the launch phase. The sections below are useful to developers and project owners to ensure that you have everything lined up for a smooth launch. There are several things to check so it may help to assign ownership of different sections to different members of your team. -* [Tenant Check](/docs/get-started/architecture-scenarios/business-to-consumer/launch/tenant-check): Tenant Checks to perform before launch of your B2C IAM implementation. -* [Testing Complete](/docs/get-started/architecture-scenarios/business-to-consumer/launch/testing): Testing preparation for the launch of your B2C IAM implementation. -* [Operations Readiness](/docs/get-started/architecture-scenarios/business-to-consumer/launch/operations-readiness): Operations checks to perform before launch of your B2C IAM implementation. -* [Compliance Readiness](/docs/get-started/architecture-scenarios/business-to-consumer/launch/compliance-readiness): Compliance checks to perform before launch of your B2C IAM implementation. -* [Support Readiness](/docs/get-started/architecture-scenarios/business-to-consumer/launch/support-readiness): Support readiness for the launch of your B2C IAM implementation. -* [Launch Day Preparation](/docs/get-started/architecture-scenarios/business-to-consumer/launch/launch-day): Launch preparation considerations for your B2C IAM implementation. - -## Project Planning Guide - -We provide planning guidance in PDF format that you can download and refer to for details about our recommended strategies. +Use this guide as you prepare for the launch of your application. We’ve included reminders about some content you may have viewed earlier during your planning or development phases as well as some new content unique to the launch phase. The sections below are useful to developers and project owners to ensure that you have everything lined up for a smooth launch. There are several things to check so it may help to assign ownership of different sections to different members of your team. -[B2C IAM Project Planning Guide](https://assets.ctfassets.net/cdy7uua7fh8z/3er1aEQ7Ul0q3c9leJWczR/b1f18b4c16abb7e78b01e4eb2b52bb8e/B2C_Project_Planning.pdf) \ No newline at end of file +We provide planning guidance in PDF format that you can download and refer to for details about our recommended strategies: [B2C IAM Project Planning Guide](https://assets.ctfassets.net/cdy7uua7fh8z/3er1aEQ7Ul0q3c9leJWczR/b1f18b4c16abb7e78b01e4eb2b52bb8e/B2C_Project_Planning.pdf) diff --git a/main/docs/get-started/architecture-scenarios/checklists.mdx b/main/docs/get-started/architecture-scenarios/checklists.mdx index 89e663ab93..8a1497847c 100644 --- a/main/docs/get-started/architecture-scenarios/checklists.mdx +++ b/main/docs/get-started/architecture-scenarios/checklists.mdx @@ -1,7 +1,8 @@ --- -description: Links to checklists for your implementation. title: Implementation Planning Checklists +description: Links to checklists for your implementation. --- + Click the links below to download a checklist that corresponds to a phase in the SDLC (Software Development Lifecycle). You can open the checklist in any spreadsheet application and customize them to suit your needs. ## Analyze Checklist @@ -59,4 +60,4 @@ In the Monitor phase, make enhancements, corrections, and changes to ensure the * Monitoring * Maintenance * Changes and adjustments -* Upgrade and adapt to future needs \ No newline at end of file +* Upgrade and adapt to future needs diff --git a/main/docs/get-started/architecture-scenarios/implementation-resources.mdx b/main/docs/get-started/architecture-scenarios/implementation-resources.mdx index 98de8f04b5..690860e0c5 100644 --- a/main/docs/get-started/architecture-scenarios/implementation-resources.mdx +++ b/main/docs/get-started/architecture-scenarios/implementation-resources.mdx @@ -1,7 +1,8 @@ --- -description: Learn about all the resources Auth0 provides to help you with your Auth0 implementation. title: Implementation Resources +description: Learn about all the resources Auth0 provides to help you with your Auth0 implementation. --- + Auth0 provides a wealth of resources to help you effectively engage with our product and community. This list provides links to the resources available, by category. ## Get started @@ -49,7 +50,6 @@ Auth0 resources that help you troubleshoot your implementation include: + [**Troubleshooting tips**](/docs/deploy-monitor/deploy-private-cloud/private-cloud-on-aws#what-to-check-before-logging-an-issue) and [**Information to include in your support case**](/docs/deploy-monitor/deploy-private-cloud/private-cloud-on-aws#information-to-provide-when-logging-an-issue): Get advice to help your development and support teams analyze issues. * [**Supported versions**](/docs/troubleshoot/customer-support/product-support-matrix): Understand which versions of SDKs, browsers, and languages are supported. Architects and developers should review this to ensure your project employs languages, libraries, and SDKs that will allow your implementation to work with Auth0. * [**Feedback Portal**](https://auth0.com/feedback): Make product suggestions. (You can also do this via the Support Center if you want better visibility into what you’ve filed over time.) Architects and developers can use this site to provide feedback on the Auth0 product for consideration as enhancements in the future. -* [**Professional Services**](/docs/get-started/professional-services): Engage our world-wide professional services team to help speed your project to success. Project owners will find this useful for learning how Auth0 identity experts can help accelerate your project or fill in any temporary skill gaps. ## Set up and monitor operations diff --git a/main/docs/get-started/architecture-scenarios/mobile-api.mdx b/main/docs/get-started/architecture-scenarios/mobile-api.mdx index 7f32c692fc..60dbbc26f9 100644 --- a/main/docs/get-started/architecture-scenarios/mobile-api.mdx +++ b/main/docs/get-started/architecture-scenarios/mobile-api.mdx @@ -1,13 +1,14 @@ --- -description: Explains the architecture scenario with a mobile application communicating with an API. title: Mobile Applications with API +description: Explains the architecture scenario with a mobile application communicating with an API. --- + In this scenario we will build a timesheet API for a fictitious company named ExampleCo. The API will allow management of timesheet entries for an employee or a contractor. We will also be building a mobile application which will be used to view and log timesheet entries in the centralized timesheet database using the API. -### TL;DR +Summary: * Auth0 provides API Authentication and Authorization as a means to secure access to API endpoints (see [API Authentication and Authorization](/docs/get-started/architecture-scenarios/mobile-api/part-1#api-authentication-and-authorization)) * For authorizing a mobile app user and granting access to the API, Auth0 supports the [Authorization Code Flow with Proof Key for Code Exchange (PKCE)](/docs/get-started/authentication-and-authorization-flow/authorization-code-flow-with-pkce) (see [Proof Key for Code Exchange](/docs/get-started/architecture-scenarios/mobile-api/part-1#proof-key-for-code-exchange-pkce-)) @@ -34,12 +35,3 @@ ExampleCo wants to build a flexible solution. There are potential multiple emplo Hence the company has decided to develop a single Timesheets API which will be used to log time not only by this mobile app, but by all other apps as well. They want to put in place a security architecture that is flexible enough to accommodate this. ExampleCo wants to ensure that a large part of the code and business logic for the application can be shared across the different applications. It is required that only authorized users and applications are allowed access to the Timesheets API. - -## Learn more - -* [Solution Overview (Mobile Apps + API)](/docs/get-started/architecture-scenarios/mobile-api/part-1) -* [Auth0 Configuration (Mobile Apps + API)](/docs/get-started/architecture-scenarios/mobile-api/part-2) -* [API and Mobile Configuration (Mobile Apps + API)](/docs/get-started/architecture-scenarios/mobile-api/part-3) -* [Node.js API Implementation (Mobile Apps + API)](/docs/get-started/architecture-scenarios/mobile-api/api-implementation-nodejs) -* [Android Mobile Application Implementation (Mobile Apps + API)](/docs/get-started/architecture-scenarios/mobile-api/mobile-implementation-android) -* [Conclusion (Mobile Apps + API)](/docs/get-started/architecture-scenarios/mobile-api/part-4) diff --git a/main/docs/get-started/architecture-scenarios/multiple-organization-architecture.mdx b/main/docs/get-started/architecture-scenarios/multiple-organization-architecture.mdx index f7db8775e5..9cd733d8f3 100644 --- a/main/docs/get-started/architecture-scenarios/multiple-organization-architecture.mdx +++ b/main/docs/get-started/architecture-scenarios/multiple-organization-architecture.mdx @@ -1,8 +1,8 @@ --- -description: An integration guide to multi-tenant architectures that must accommodate application instances for multiple Auth0 Organizations. -sidebarTitle: Overview title: Multiple Organization Architecture +description: An integration guide to multi-tenant architectures that must accommodate application instances for multiple Auth0 Organizations. --- + There are multiple use cases where users belong to third-party organizations that have signed up for the services you provide. These users may be employees of a third-party organization, customers, or a combination of both. Whatever the situation, this guide will provide you with a high-level overview of common use cases for multi-tenant applications. B2B applications strive to create a pleasant user experience for the employees and customers of the businesses they serve. To accomplish this, service providers in B2B environments often allow branding to be added to their service for each of the organizations that use it. For example, let’s say you work for AwesomeSaaS (an SaaS software company), and your company uses Human0, an HR application for managing benefits and other HR functions. You access your HR app, and when you log in, the login experience is customized to display the AwesomeSaaS logo and use AwesomeSaaS colors. @@ -90,18 +90,11 @@ Sumana needs to have the same identity for both organizations because guiding in There are scenarios where you will need to provide administrative access across your organizations. Typically, this will be for administrative tasks outside of user Profile/Account management (as described in [Profile Management](/docs/get-started/architecture-scenarios/multiple-organization-architecture/single-identity-provider-organizations/profile-management)), and you may need to provide access to your employees as well as to third parties. - **Best Practice** Always enable Multi-factor Authentication (MFA) for Auth0 Tenant administrators who are provided access via the Auth0 Dashboard. Note that you must follow a different process to enable MFA for an Auth0 Tenant administrator than you do to enable MFA for the Auth0 Tenant itself. To learn how to enable MFA for an Auth0 Tenant Administrator, see [Manage Dashboard Access with Multi-factor Authentication](/docs/get-started/manage-dashboard-access/add-change-remove-mfa). - The Auth0 Dashboard can be configured via [role-based access control](/docs/get-started/manage-dashboard-access/feature-access-by-role), which will allow you to define specific roles for your employees across your Auth0 Tenant deployment as a whole. You can even leverage your own corporate IdP to provide Auth0 Tenant Administrator authentication for your employees, as well as extended Tenant Administrator access to trusted third-parties. For other administrative access, you will typically want to build your own API and/or application, which you will use in conjunction with the Auth0 Management API. Providing administrative access to your Auth0 Tenant via the Auth0 Dashboard for a wide range of users is not recommended. While building such an application/API is beyond the scope of this document, it’s recommended that you seek help from [Auth0 Professional Services](/docs/get-started/professional-services) before embarking on such an endeavor. - -## Learn more - -* [Single Identity Provider Organizations](/docs/get-started/architecture-scenarios/multiple-organization-architecture/single-identity-provider-organizations) -* [Multiple Identity Provider Organizations](/docs/get-started/architecture-scenarios/multiple-organization-architecture/multiple-idp-orgs) diff --git a/main/docs/get-started/architecture-scenarios/multiple-organization-architecture/single-identity-provider-organizations.mdx b/main/docs/get-started/architecture-scenarios/multiple-organization-architecture/single-identity-provider-organizations.mdx index ca3691bdd4..a4453eb632 100644 --- a/main/docs/get-started/architecture-scenarios/multiple-organization-architecture/single-identity-provider-organizations.mdx +++ b/main/docs/get-started/architecture-scenarios/multiple-organization-architecture/single-identity-provider-organizations.mdx @@ -1,8 +1,8 @@ --- -description: Learn about Single Identity Provider(IdP) Organizations, in which every Auth0 Organization has exactly one Auth0 connection. -sidebarTitle: Overview title: Single Identity Provider Organizations +description: Learn about Single Identity Provider(IdP) Organizations, in which every Auth0 Organization has exactly one Auth0 connection. --- + In the Single Identity Provider (IdP) Organizations scenario, every organization that uses the [Auth0 Organizations](/docs/manage-users/organizations/organizations-overview) feature uses exactly one Auth0 connection. This feature allows each application to select the appropriate organization defined on the Auth0 Tenant, which will either authenticate user credentials directly or forward the authentication request to the appropriate IdP to handle. In this scenario, we’ll continue to use the [Travel0 Corporate Booking](/docs/get-started/architecture-scenarios/multiple-organization-architecture) example. In this example, the corporate booking application equates to your application and Travel0 corresponds to your company. @@ -10,18 +10,7 @@ In this scenario, we’ll continue to use the [Travel0 Corporate Booking](/docs/ ![Architecture Scenarios - Multitenancy - Diagram - Isolated users, Shared Apps, Orgs A&B](/docs/images/cdy7uua7fh8z/1YBaMaMozamiTv8hXmNB2D/21e9270a59021a12209bdcb4345147cb/isolated-users_shared-apps_org-ab.png) - The Auth0 Organizations feature currently supports applications that use the [SAML](/docs/authenticate/protocols/saml/saml-configuration), [Open ID Connect](/docs/authenticate/protocols/openid-connect-protocol) protocols and/or the [OAuth 2](/docs/authenticate/protocols/oauth) framework. Applications that require [WS-Fed](/docs/authenticate/protocols/ws-fed-protocol) are not supported. - Regardless of how credentials are processed--whether user credentials are stored in a database connection (like with Hoekstra & Associates) or are validated via an enterprise connection (like with MetaHexa Bank) or a social connection--your application behaves the same way. Leveraging the [Organizations](/docs/manage-users/organizations/organizations-overview) feature allows you to configure and control the experience. - -## Learn more - -* [Single Identity Provider: Provisioning](/docs/get-started/architecture-scenarios/multiple-organization-architecture/single-identity-provider-organizations/provisioning) -* [Single Identity Provider: Branding](/docs/get-started/architecture-scenarios/multiple-organization-architecture/single-identity-provider-organizations/branding) -* [Single Identity Provider: Authentication](/docs/get-started/architecture-scenarios/multiple-organization-architecture/single-identity-provider-organizations/authentication) -* [Single Identity Provider: Authorization](/docs/get-started/architecture-scenarios/multiple-organization-architecture/single-identity-provider-organizations/authorization) -* [Single Identity Provider: Profile Management](/docs/get-started/architecture-scenarios/multiple-organization-architecture/single-identity-provider-organizations/profile-management) -* [Single Identity Provider: Logout](/docs/get-started/architecture-scenarios/multiple-organization-architecture/single-identity-provider-organizations/logout) diff --git a/main/docs/get-started/architecture-scenarios/server-application-api.mdx b/main/docs/get-started/architecture-scenarios/server-application-api.mdx index 2840989192..2cadc7246e 100644 --- a/main/docs/get-started/architecture-scenarios/server-application-api.mdx +++ b/main/docs/get-started/architecture-scenarios/server-application-api.mdx @@ -1,13 +1,14 @@ --- -description: Explains the architecture scenario with server to server communication with secure calls to an API (resource server) on behalf of the application. title: Server Applications with API +description: Explains the architecture scenario with server to server communication with secure calls to an API (resource server) on behalf of the application. --- + In this scenario we will build a Timesheet API for a fictitious company named ExampleCo. The API will allow additional timesheet entries for an employee or a contractor. We will also be building a cron job which will process timesheet entries from an external system to the centralized timesheet database using the API. -### TL;DR +Summary: * Auth0 provides API authentication and authorization as a means to secure access to API endpoints (read [API Authentication and Authorization](/docs/get-started/architecture-scenarios/server-application-api/part-1#api-authentication-and-authorization)) * For authorizing a Machine-to-Machine Application (a CLI, service or daemon where no user interaction is involved) Auth0 supports the Client Credentials grant (read [Client Credentials Grant](/docs/get-started/architecture-scenarios/server-application-api/part-1#client-credentials-grant)) @@ -29,10 +30,3 @@ ExampleCo wants to build a flexible solution that: * Allows for future application launches, like a mobile application, in the architecture * Allows for the Timesheets API to be secure and accessed by authorized users and applications * Allows for a large part of code and business logic for the application to be shared across other apps - -## Learn more - -* [Solution Overview (Server Apps + API)](/docs/get-started/architecture-scenarios/server-application-api/part-1) -* [Auth0 Configuration (Server Apps + API)](/docs/get-started/architecture-scenarios/server-application-api/part-2) -* [Application Implementation (Server Apps + API)](/docs/get-started/architecture-scenarios/server-application-api/part-3) -* [Conclusion (Server Apps + API)](/docs/get-started/architecture-scenarios/server-application-api/part-4) diff --git a/main/docs/get-started/architecture-scenarios/spa-api.mdx b/main/docs/get-started/architecture-scenarios/spa-api.mdx index 06b8d31af6..47bec298d9 100644 --- a/main/docs/get-started/architecture-scenarios/spa-api.mdx +++ b/main/docs/get-started/architecture-scenarios/spa-api.mdx @@ -1,13 +1,14 @@ --- -description: Explains the architecture scenario where a single-page application (SPA) talks to an API using OpenID Connect (OIDC), and the OAuth 2.0 Implicit Grant Flow, to authenticate users with Auth0. title: Single-Page Applications (SPA) with API +description: Explains the architecture scenario where a single-page application (SPA) talks to an API using OpenID Connect (OIDC), and the OAuth 2.0 Implicit Grant Flow, to authenticate users with Auth0. --- + In this scenario, we will build a timesheet API for a fictitious company named ExampleCo. The API will allow adding timesheet entries for an employee or a contractor. We will also be building a single-page application (SPA) which will be used to log timesheet entries and send them to the centralized timesheet database using the API. -### TL;DR +Summary: * Auth0 provides API Authentication and Authorization as a means to secure access to API endpoints (see [API Authentication and Authorization](/docs/get-started/architecture-scenarios/spa-api/part-1#api-authentication-and-authorization)) * For authorizing a user of a SPA, Auth0 supports the Implicit Grant (see [Implicit Grant](/docs/get-started/architecture-scenarios/spa-api/part-1#implicit-grant)) @@ -32,12 +33,3 @@ ExampleCo wants to build a flexible solution. At the moment only a SPA is requir It is required that only authorized users and applications are allowed access to the Timesheets API. Two kinds of users will use this SPA: employees and managers. The employees should be able to read, create and delete their own timesheet entries, while the managers should be able to approve timesheets as well. - -## Learn more - -* [Solution Overview (SPAs + API)](/docs/get-started/architecture-scenarios/spa-api/part-1) -* [Auth0 Configuration (SPAs + API)](/docs/get-started/architecture-scenarios/spa-api/part-2) -* [API and SPA Configuration (SPAs + API)](/docs/get-started/architecture-scenarios/spa-api/part-3) -* [Node.js API Implementation (SPAs + API)](/docs/get-started/architecture-scenarios/spa-api/api-implementation-nodejs) -* [SPA Angular 2 Implementation (SPAs + API)](/docs/get-started/architecture-scenarios/spa-api/spa-implementation-angular2) -* [Conclusion (SPAs + API)](/docs/get-started/architecture-scenarios/spa-api/part-4) diff --git a/main/docs/get-started/architecture-scenarios/sso-for-regular-web-apps.mdx b/main/docs/get-started/architecture-scenarios/sso-for-regular-web-apps.mdx index d145c613d5..10e0193e13 100644 --- a/main/docs/get-started/architecture-scenarios/sso-for-regular-web-apps.mdx +++ b/main/docs/get-started/architecture-scenarios/sso-for-regular-web-apps.mdx @@ -1,11 +1,12 @@ --- -description: Regular web app scenario which needs to authenticate users using OpenID Connect (OIDC) single sign-on. title: Regular Web Applications with Single Sign-On +description: Regular web app scenario which needs to authenticate users using OpenID Connect (OIDC) single sign-on. --- + In this scenario, we will build a web application for a fictitious company named ExampleCo. The app is meant to be used by ExampleCo's employees and contractors. Employees will use their existing corporate directory (Active Directory), while contractors will be managed in a separate user store. -### TL;DR +Summary: * Auth0 supports open standards such as OAuth 2.0 and OpenID Connect (OIDC) for authentication and authorization (see [Which protocol to use](/docs/get-started/architecture-scenarios/sso-for-regular-web-apps/part-1#which-protocol-to-use)) * OIDC supports several different authorization flows - the most appropriate one for Web Applications being the Authorization Code Flow (see [Authentication Flow](/docs/get-started/architecture-scenarios/sso-for-regular-web-apps/part-1#authentication-flow)) @@ -59,11 +60,3 @@ ExampleCo wants to minimize user login burden, but wants to maintain a level of The solution should be available both to the employees with a physical presence in the company office, as well as to those working remotely, without the overhead of a VPN connection, hence the app should be deployed on a cloud provider like Heroku or Microsoft Azure. ![Diagram of the solution](/docs/images/cdy7uua7fh8z/7hg1vqzNEJ2RG1JYw0pxFp/d5e88b45ef76d06b1e8d35ab49186e1d/solution-diagram.png) - -## Learn more - -* [Solution Overview (Web Apps + SSO)](/docs/get-started/architecture-scenarios/sso-for-regular-web-apps/part-1) -* [Auth0 Configuration (Web Apps + SSO)](/docs/get-started/architecture-scenarios/sso-for-regular-web-apps/part-2) -* [Application Implementation (Web Apps + SSO)](/docs/get-started/architecture-scenarios/sso-for-regular-web-apps/part-3) -* [ASP.NET Core Implementation (Web Apps + SSO)](/docs/get-started/architecture-scenarios/sso-for-regular-web-apps/implementation-aspnetcore) -* [Conclusion (Web Apps + SSO)](/docs/get-started/architecture-scenarios/sso-for-regular-web-apps/part-4) diff --git a/main/docs/get-started/auth0-overview.mdx b/main/docs/get-started/auth0-overview.mdx deleted file mode 100644 index 1b53cc2014..0000000000 --- a/main/docs/get-started/auth0-overview.mdx +++ /dev/null @@ -1,37 +0,0 @@ ---- -description: Describes Auth0 services and helps you get started using them with your applications and APIs. -sidebarTitle: Overview -title: Auth0 Overview ---- -Auth0 is a flexible, drop-in solution to add authentication and authorization services to your applications. Your team and organization can avoid the cost, time, and risk that come with building your own solution to authenticate and authorize users. - -Take a look at just a few of Auth0's use cases: - -* You built an awesome app and you want to add user authentication and authorization. Your users should be able to log in either with an identifier (username, email, or phone number) and password or with their social accounts (such as Facebook or X). You want to retrieve the user's profile after the login so you can customize the UI and apply your authorization policies. -* You built an API and you want to secure it with [OAuth 2.0](/docs/authenticate/protocols/oauth). -* You have more than one app, and you want to implement [Single Sign-on (SSO)](/docs/authenticate/single-sign-on). -* You built a JavaScript front-end app and a mobile app, and you want them both to securely access your API. -* You have a web app that needs to authenticate users using [Security Assertion Markup Language (SAML)](/docs/authenticate/protocols/saml/saml-configuration). -* You believe passwords are broken and you want your users to log in with one-time codes delivered by email or SMS. -* If one of your user's email addresses is compromised in some site's public data breach, you want to be notified, and you want to notify the users and/or block them from logging in to your app until they reset their password. -* You want to act proactively to block suspicious IP addresses if they make consecutive failed login attempts, in order to avoid DDoS attacks. -* You are part of a large organization that wants to federate your existing enterprise directory service to allow employees to log in to the various internal and third-party applications using their existing enterprise credentials. -* You don't want (or you don't know how) to implement your own user management solution. Password resets, creating, provisioning, blocking, and deleting users, and the UI to manage all these. You just want to focus on your app. -* You want to enforce [multi-factor authentication (MFA)](/docs/secure/multi-factor-authentication) when your users want to access sensitive data. -* You are looking for an identity solution that will help you stay on top of the constantly growing compliance requirements of SOC2, GDPR, PCI DSS, HIPAA, and others. -* You want to monitor users on your site or application. You plan on using this data to create funnels, measure user retention, and improve your sign-up flow. -* You want robust authorization policy to allow your users access to resources based on [their relationship](https://docs.fga.dev/authorization-concepts) to the resource or [their role](/docs/manage-users/access-control/rbac) in your organization. - -| Read... | To learn... | -| --- | --- | -| [Auth0 Dashboard](/docs/get-started/auth0-overview/dashboard) | About the Auth0 Dashboard and features you can access to implement authentication and authorization with your applications and APIs. | -| [Create Tenants](/docs/get-started/auth0-overview/create-tenants) | How to create tenants using the Auth0 Dashboard or the Management API, explore creating multiple tenants and child tenants, and learn about setting up multiple environments. | -| [Create Applications](/docs/get-started/auth0-overview/create-applications) | How to set up and configure applications in the Auth0 Dashboard. | -| [Register APIs](/docs/get-started/auth0-overview/set-up-apis) | How to set up and configure APIs in the Auth0 Dashboard. | - -## Learn more - -* [Create Tenants](/docs/get-started/auth0-overview/create-tenants) -* [Auth0 Dashboard](/docs/get-started/auth0-overview/dashboard) -* [Architecture Scenarios](/docs/get-started/architecture-scenarios) -* [Protocols](/docs/authenticate/protocols) diff --git a/main/docs/get-started/auth0-overview/create-applications.mdx b/main/docs/get-started/auth0-overview/create-applications.mdx index 2e3b63f82f..b223092777 100644 --- a/main/docs/get-started/auth0-overview/create-applications.mdx +++ b/main/docs/get-started/auth0-overview/create-applications.mdx @@ -1,7 +1,8 @@ ---- -description: Learn how to set up and configure applications in the Auth0 Dashboard. +-- title: Create Applications +description: Learn how to set up and configure applications in the Auth0 Dashboard. --- + You can create an application manually or import it from a [Client ID Metadata Document (CIMD)](/docs/get-started/auth0-overview/create-applications/register-applications-with-cimd) URL in the Auth0 Dashboard. ## Create manually @@ -42,13 +43,3 @@ To create an application in Auth0: - **Regular Web Applications**: These applications are traditional web applications that perform most of their application logic on the server (e.g., Express.js, ASP.NET). - **Machine-to-Machine Applications**: These applications include non-interactive applications, such as command-line tools, daemons, IoT devices, or services running on your back-end. 4. Select **Create**. - -## Learn more - -* [Register Applications with CIMD](/docs/get-started/auth0-overview/create-applications/register-applications-with-cimd) -* [Register Native Applications](/docs/get-started/auth0-overview/create-applications/native-apps) -* [Register Single-Page Web Applications](/docs/get-started/auth0-overview/create-applications/single-page-web-apps) -* [Register Regular Web Applications](/docs/get-started/auth0-overview/create-applications/regular-web-apps) -* [Register Machine-to-Machine Applications](/docs/get-started/auth0-overview/create-applications/machine-to-machine-apps) -* [Application Settings](/docs/get-started/applications/application-settings) -* [Remove Applications](/docs/get-started/applications/remove-applications) diff --git a/main/docs/get-started/auth0-overview/create-applications/native-apps.mdx b/main/docs/get-started/auth0-overview/create-applications/native-apps.mdx index c7a3421ee2..14f1cb9ef4 100644 --- a/main/docs/get-started/auth0-overview/create-applications/native-apps.mdx +++ b/main/docs/get-started/auth0-overview/create-applications/native-apps.mdx @@ -3,6 +3,7 @@ description: Learn how to register and configure a native application using the title: Register Native Applications validatedOn: 2026-02-25 --- + To integrate Auth0 with a native application, you must first register your app with Auth0 using the Auth0 Dashboard. Native apps should use the Authorization Code flow with PKCE for secure authentication. To learn more, read [Authorization Code Flow with PKCE](/docs/get-started/authentication-and-authorization-flow/authorization-code-flow-with-pkce). These apps may include mobile, desktop, or hybrid apps running natively in a device (for example, iOS, Android). 1. Go to [Dashboard > Applications > Applications](https://manage.auth0.com/#/applications) and click **Create Application**. diff --git a/main/docs/get-started/auth0-overview/create-tenants.mdx b/main/docs/get-started/auth0-overview/create-tenants.mdx index 0a2798b777..7c79a4b58b 100644 --- a/main/docs/get-started/auth0-overview/create-tenants.mdx +++ b/main/docs/get-started/auth0-overview/create-tenants.mdx @@ -1,84 +1,73 @@ --- -description: Describes how to create a tenant and learn the basics of Auth0 and familiarize yourself with the terminology. -sidebarTitle: Overview -title: Create Tenants +title: How to Create a Tenant on Auth0 +sidebarTitle: Create Tenants +description: Get started on Auth0 by creating your first tenant. --- -We will walk through the initial steps of getting started using Auth0 to familiarize you with the key concepts of the Auth0 service. We will use the company **Example-Co** to help describe some of the steps involved. -## Set up an Auth0 account +When you create a tenant, you choose three initial settings: its name, region, and environment tag. -If you haven't already [signed up](https://auth0.com/signup) for an Auth0 **account**, do so (it's free). You can either use username/email/phone and password or log in with a social provider (such as LinkedIn, Microsoft, GitHub, or Google). +| Setting | Description | Editable? | +|---------|-------------|-----------| +| Name | A unique string identifying your tenant. | No | +| Region | Determines the locality where we store your data. | No | +| Environment tag | Differentiates development, staging, and production environments. Influences tenant [rate limits](/docs/troubleshoot/customer-support/operational-policies/rate-limit-policy). | Yes | -## Create a tenant and domain +Together, the name and region you choose for your tenant define your Auth0 domain, which is the base URL for your authentication requests, Management API calls, and Universal Login page. -Once you create your account you will be asked to create a **tenant**. Everything starts with an Auth0 tenant. This is where you configure your use of Auth0, and then where Auth0 assets - such as [applications](/docs/get-started/applications), [connections](/docs/authenticate/identity-providers), and [user profiles](/docs/get-started/architecture-scenarios/business-to-business/profile-management) - are defined, managed and stored. You access an Auth0 tenant via the Auth0 [Dashboard](/docs/get-started/auth0-overview/dashboard), where you can also create additional, associated tenants. You can create more than one Auth0 tenant so that you can structure your tenants in a way that will isolate different domains of users and also support your Software Development Life Cycle (SDLC). +Auth0 domains are in the format `{tenant-name}.{region}.auth0.com`. For example, a tenant named `example-tenant` in the US region would have the domain `example.us.auth0.com`. -**Tenant names cannot be changed or reused once deleted.** So, make sure you're happy with the name(s) before you create your Auth0 tenants. +## Choosing initial tenant settings -Determining the level of isolation you require when it comes to your user domains is an important step, and together with your branding requirements helps you determine the number of Auth0 tenants needed in your environment. The number of Auth0 tenants you need to manage can quickly grow so consider carefully before creating multiple Auth0 tenants for production. +After you [sign up for Auth0](https://auth0.com/signup), you immediately create your first tenant. By default, we choose your tenant name and region, but you can check **I need advanced settings** to customize them. -Tenant characteristics: + +Trying to create multiple tenants? Learn more about [managing multiple tenants with Auth0 teams](/docs/get-started/auth0-teams/tenant-management#manage-mulitple-tenants). + -* The tenant name has to be unique. It will be used to create your personal domain. -* The tenant name can contain only lowercase alphanumeric characters and hyphens ("-"). It cannot begin or end with a hyphen. -* The tenant name must be a minimum of 3 characters and a maximum of 63 characters. -* The tenant name cannot be changed after creation. -* You can create more than one tenant; in fact, you are encouraged to do so for each environment you may have such as development, staging, or production. To learn more, read [Set Up Multiple Environments](/docs/get-started/auth0-overview/create-tenants/set-up-multiple-environments). +### Tenant name -The name of your tenant is part of your Auth0 domain. You can customize this by using a custom domain. This domain is the base URL used to access the Auth0 API and the URL where your users authenticate. +Tenant names have the following requirements: -### Region, locality, and sub-locality +* Tenant names must be unique. -The domain name is also made up of the locality value from a **region**. We support the following locality values for the [public cloud deployment option](/docs/deploy-monitor/deployment-options): +* Tenant names can contain only lowercase alphanumeric characters and hyphens (`-`). Tenant names cannot begin or end with a hyphen. -| Region | Locality | Sub-localities | -| --- | --- | --- | -| Australia | AU | AU | -| Canada | CA | CA | -| Europe | EU | EU, EU-2 | -| Japan | JP | JP | -| United Kingdom | UK | UK | -| United States of America | US | US, US-3, US-4, US-5 | +* Tenant names must be a minimum of 3 characters and a maximum of 63 characters. -Each of these localities is separated into a sub-locality (or **tenant environment**) with a digit after the locality, e.g. `EU-2`. Tenant environments cannot be chosen manually, but localities based on the selected region may be specified, which control the assigned tenant domain and the region where your data will be hosted. + +You cannot change tenant names after creation. You cannot reuse the name of a deleted tenant. + -In our example, **Example-Co** chose the name `example-co` and AU as their region. So their domain is `example-co.au.auth0.com`. +### Tenant region -## Custom domains +Your tenant's region determines the locality where we host your data and forms part of your Auth0 domain. -We recommend the use of custom domains, such as `example-co.com`, in production environments to provide your users with the most secure and seamless experience. +You can view a list of [available public cloud regions](/docs/deploy-monitor/deployment-options). -Custom domain certificates can be managed by Auth0 or self-managed by you. +### Tenant environment tag -To learn more, read [Custom Domains](/docs/customize/custom-domains). +Your tenant's environment tag can be **Development**, **Staging**, or **Production**. You can use the environment tag to differentiate environments in setups with multiple tenants. -## What's next +Your tenant's environment tag and your Auth0 subscription determine the [rate limits](/docs/troubleshoot/customer-support/operational-policies/rate-limit-policy) that apply to your tenant. -* **Create and register applications**: Now that you have an account and a domain, you need to register each application that will use our services in the [Auth0 Dashboard](https://manage.auth0.com/#/applications). To learn more, read [Applications in Auth0](/docs/get-started/applications) and [Create Applications](/docs/get-started/auth0-overview/create-applications). -* **Set up connections**: Next, you need to set up how your users will authenticate during log in. Auth0 sits between your app and the identity provider that authenticates your users (such as Google or Facebook). The relationship between Auth0 and the identity provider is referred to as a **connection**. By using this connection layer, Auth0 keeps your app isolated from any changes that occur with the identity provider's implementation. To learn more, read [Authentication and Authorization](/docs/get-started/identity-fundamentals/authentication-and-authorization) and [Connections](/docs/authenticate/identity-providers). +## Next steps -## Extend Auth0's functionality +Auth0 sits between your application and the identity provider (IdP) that authenticates your users. -Auth0 offers several ways to extend the platform's functionality: +1. Register your [application](/docs/get-started/applications) with Auth0. -* [Actions](/docs/customize/actions): Actions are secure, tenant-specific, versioned functions written in Node.js that execute at certain points within the Auth0 platform. Use Actions to customize and extend Auth0's capabilities with custom login. -* [Rules](/docs/customize/rules): Rules are functions written in JavaScript or C#, that are executed in Auth0 just after successful authentication and before control returns to your app. Rules can be chained together for modular coding and can be turned on and off individually. You can use Rules for: +2. Create a [connection](/docs/authenticate/identity-providers) between Auth0 and your IDP. - + Access control - + Webhooks - + Profile enrichment - + Multi-factor authentication (MFA) -* [Hooks](/docs/customize/hooks): Hooks allow you to customize the behavior of Auth0 using Node.js code that is executed against extensibility points (which are comparable to webhooks that come with a server). They are secure, self-contained functions associated with specific extensibility points of the Auth0 platform. Auth0 invokes the Hooks at runtime to execute your custom logic. -* [Extensions](/docs/customize/extensions): Auth0 Extensions enable you to install applications or run commands/scripts that extend the functionality of the Auth0 base product. You can either use one of the pre-defined extensions, provided by Auth0, or create your own. Some of the actions you can do with extensions include: +From there, there are many options available to you. Here are a few examples: - + Manage the authorizations for users (using groups, roles, and permissions) - + Import/export users - + Export logs to other services - + Deploy scripts from external repositories +* **Customize your domain**: In production environments, you can replace the default Auth0 domain with a [custom domain](/docs/customize/custom-domains) (for example, `login.example.com`) to give your users a branded login experience and avoid third-party cookie issues. -## Learn more +* **Improve your application's security**: Enable [attack protection](/docs/secure/attack-protection) to mitigate threats using bot detection, suspicious IP throttling, brute force protection, and more. -* [Tenant Settings](/docs/get-started/tenant-settings) -* [Create Multiple Tenants](/docs/get-started/auth0-overview/create-tenants/create-multiple-tenants) -* [Link Multiple Tenants to a Single Subscription](/docs/get-started/auth0-overview/create-tenants/child-tenants) -* [Set Up Multiple Environments](/docs/get-started/auth0-overview/create-tenants/set-up-multiple-environments) +* **Separate isolated environments**: [Create multiple tenants](/docs/get-started/auth0-teams/tenant-management#manage-multiple-tenants) for use cases like separate development lifecycle environments. + +* **Extend Auth0's functionality**: Use Actions and Extensions to expand the functionality of the base Auth0 platform. + + * [Actions](/docs/customize/actions) are secure, tenant-specific, versioned functions written in Node.js that execute at certain points within the Auth0 platform. + + * [Extensions](/docs/customize/extensions) let you install applications or run commands and scripts for tasks like managing user authorizations (using groups, roles, and permissions), importing and exporting users, exporting logs to other services, and deploying scripts from external repositories. diff --git a/main/docs/get-started/auth0-overview/create-tenants/child-tenants.mdx b/main/docs/get-started/auth0-overview/create-tenants/child-tenants.mdx deleted file mode 100644 index c60df52e63..0000000000 --- a/main/docs/get-started/auth0-overview/create-tenants/child-tenants.mdx +++ /dev/null @@ -1,35 +0,0 @@ ---- -description: Learn how to request linking of multiple tenants under a single Auth0 subscription. -title: Link Multiple Tenants to a Single Subscription -validatedOn: 2026-03-04 ---- -Auth0 offers the ability for customers with an Enterprise subscription to link multiple tenants under a single Auth0 subscription (these linked tenants can also be referred to as child tenants). - -This feature can be useful under the following situations: - -* Separate development and production tenants while keeping the same feature access on development tenants as available in production tenants -* Own more than one production tenant under a single Enterprise subscription - -## Linking tenants - -An Enterprise subscription automatically allows users to link tenants under an existing Auth0 subscription by selecting the **Custom Agreement** option from the **Create Under** dropdown when creating new tenants. - -![](/docs/images/cdy7uua7fh8z/7ggqdv5yw011z0TsdlaHOO/7707d826dd585e074bd0d8e25b30d9d6/publiccloudtenants.png) - -If you need to link previously created tenants that are not currently part of your Enterprise subscription, contact your account team or open a ticket with [Auth0 Support](https://support.auth0.com). - - - -If you have a self-service subscription (not Enterprise), you can still link tenants. To learn more, read [Tenant Management](/docs/get-started/auth0-teams/tenant-management). - - - -## Usage consolidation - -Usage from all linked tenants counts toward your Enterprise subscription limits. You can view aggregated usage across all linked tenants in your usage and quota reports. - -## Learn more - -* [Create Multiple Tenants](/docs/get-started/auth0-overview/create-tenants/create-multiple-tenants) -* [Delete or Reset Tenants](/docs/troubleshoot/customer-support/manage-subscriptions/delete-or-reset-tenant) -* [Set Up Multiple Environments](/docs/get-started/auth0-overview/create-tenants/set-up-multiple-environments) diff --git a/main/docs/get-started/auth0-overview/create-tenants/create-multiple-tenants.mdx b/main/docs/get-started/auth0-overview/create-tenants/create-multiple-tenants.mdx deleted file mode 100644 index 5746e061f5..0000000000 --- a/main/docs/get-started/auth0-overview/create-tenants/create-multiple-tenants.mdx +++ /dev/null @@ -1,18 +0,0 @@ ---- -description: Describes how to create an additional tenant using the Auth0 Dashboard. -title: Create Multiple Tenants ---- -You can configure multiple tenants to create [different environments](/docs/get-started/auth0-overview/create-tenants/set-up-multiple-environments) in the Auth0 Dashboard to allow for complex configurations. For example, you could have two separate domains (one internal and one public-facing), or you may want users to log in differently for different applications. The way to accomplish this is to create more than one Auth0 tenant to allow you to have separate sets of applications, connections, and users for the applications and groups of users that you need to support. - -1. Go to the [Auth0 Dashboard](https://manage.auth0.com/#/), select your tenant name, and select **Create Tenant**. - - ![Dashboard Tenant Drop-Down Menu Create Tenant](/docs/images/cdy7uua7fh8z/53KetqhNIGDs6N5cqJdQtz/5efad1137eb8b04031b30137c2fc5ac5/2025-02-26_14-51-39.png) -2. Enter your desired **Tenant Domain**, select a **Region**, and select **Create**. - -## Learn more - -* [Multiple Organization Architecture](/docs/get-started/architecture-scenarios/multiple-organization-architecture) -* [Set Up Multiple Environments](/docs/get-started/auth0-overview/create-tenants/set-up-multiple-environments) -* [Delete or Reset Tenants](/docs/troubleshoot/customer-support/manage-subscriptions/delete-or-reset-tenant) -* [Multi-Tenant Applications Best Practices](/docs/get-started/auth0-overview/create-tenants/multi-tenant-apps-best-practices) -* [Tenant Settings](/docs/get-started/tenant-settings) diff --git a/main/docs/get-started/auth0-overview/create-tenants/multi-tenant-apps-best-practices.mdx b/main/docs/get-started/auth0-overview/create-tenants/multi-tenant-apps-best-practices.mdx index 6634d7b32b..c728c77e5b 100644 --- a/main/docs/get-started/auth0-overview/create-tenants/multi-tenant-apps-best-practices.mdx +++ b/main/docs/get-started/auth0-overview/create-tenants/multi-tenant-apps-best-practices.mdx @@ -3,6 +3,7 @@ description: Describes best practices for how to use Auth0 to secure your multi- title: Multi-Tenant Applications Best Practices validatedOn: 2026-03-04 --- + Multi-tenancy is an architectural approach featuring a single instance of software that runs on a server and is accessible by multiple groups of users. With multi-tenancy, you can segment users with shared characteristics into groups and grant them separate permissions and levels of access to your application. This allows you to create and maintain tailored experiences for different customers, business units, or other defined groups of users. In Auth0, the best method for implementing multi-tenancy is [Auth0 Organizations](/docs/manage-users/organizations/organizations-overview). If necessary, other legacy solutions can be used to accommodate distinct business use cases. If you offer a [business-to-business (B2B)](/docs/get-started/architecture-scenarios/business-to-business) product or service, setting up multi-tenancy for your business users may be beneficial for your use case. @@ -10,9 +11,7 @@ In Auth0, the best method for implementing multi-tenancy is [Auth0 Organizations The sections below outline the options available for implementing multi-tenancy in Auth0. - -This article uses the software architecture term "tenant" to refer to a group of users who can access your application. When referring to your Auth0 instance, the term "Auth0 tenant" is used. - +This article uses the software architecture term "tenant" to refer to a group of users who can access your application, and uses the term "Auth0 tenant" when referring to your Auth0 instance. ## Auth0 Organizations @@ -31,9 +30,7 @@ To learn more about using Auth0 Organizations to implement multi-tenancy, review ## Legacy solutions -If Auth0 Organizations does not satisfy the requirements of your use case, you may consider the legacy solutions outlined below. For guidance on selecting the best approach for your specific requirements, please reach out to our [Professional Services](/docs/get-started/professional-services) team. - -Legacy solutions include: +If Auth0 Organizations does not satisfy the requirements of your use case, you may consider the legacy solutions outlined below. Legacy solutions include: * Using an Auth0 connection to represent each tenant. * Using an Auth0 application to represent each tenant. @@ -43,9 +40,7 @@ Legacy solutions include: ### Use Auth0 connections - Entity limits may apply. To learn more, read [Entity Limit Policy](/docs/troubleshoot/customer-support/operational-policies/entity-limit-policy). If you have an Enterprise subscription, you will not be constrained due to entity limits, but you may be constrained by a connection that already has thousands of enabled clients. - You can represent each of your tenants with a separate Auth0 connection. @@ -58,17 +53,13 @@ This approach allows you to support scenarios where: To prompt a user to log in through a specific connection, call the [Auth0 Authentication API Login endpoint](https://auth0.com/docs/api/authentication#login), and include the `connection` parameter. - -If you use [Lock](/docs/libraries#lock) in your application, note that it supports a maximum of 50 database connections per application. Social and enterprise connections are not affected by this limit, but are still subject to the [Entity Limit Policy](/docs/troubleshoot/customer-support/operational-policies/entity-limit-policy). - +If you use [Lock](/docs/libraries#lock) in your application, it supports a maximum of 50 database connections per application. Social and enterprise connections are not affected by this limit, but are still subject to the [Entity Limit Policy](/docs/troubleshoot/customer-support/operational-policies/entity-limit-policy). ### Use Auth0 applications - Entity limits may apply. To learn more, read [Entity Limit Policy](/docs/troubleshoot/customer-support/operational-policies/entity-limit-policy). If you have an Enterprise subscription, you will not be constrained due to entity limits, but you may be constrained by a connection that already has thousands of enabled clients. - You can represent each of your tenants with a separate Auth0 application. diff --git a/main/docs/get-started/auth0-overview/create-tenants/set-up-multiple-environments.mdx b/main/docs/get-started/auth0-overview/create-tenants/set-up-multiple-environments.mdx index 1dc8f66a6d..91e810b3be 100644 --- a/main/docs/get-started/auth0-overview/create-tenants/set-up-multiple-environments.mdx +++ b/main/docs/get-started/auth0-overview/create-tenants/set-up-multiple-environments.mdx @@ -1,83 +1,22 @@ --- -description: Describes how to use multiple Auth0 tenants to manage various environments. -title: Set Up Multiple Environments +title: Considerations for Multiple Environments on Auth0 +description: Use multiple Auth0 tenants to set up isolated development, staging, and production environments. --- -Development, staging, and production environments are easy to set up in Auth0. Simply create a new tenant for each environment to guarantee isolation between them. You can easily switch between tenants using the tenant chooser from the top left menu on the Dashboard. You can also configure different administrators for each. -Production [rate limits](/docs/troubleshoot/customer-support/operational-policies/rate-limit-policy) only apply to tenants tagged as `Production`. Ensure your tenant's environment tag is set to `Production` before going live, and note the differences between rate limits for different tenants, environments, and fee structures. +You can set up isolated development, staging, and production environments in Auth0 by creating a tenant for each environment and using the tenant's environment tag to differentiate between them. -You can name your multiple environments any way you prefer. For production environments, we strongly recommend using [custom domains](/docs/customize/custom-domains). +* Your Auth0 team must have a subscription that supports multiple tenants. For more information, read the [Auth0 pricing page](https://auth0.com/pricing). -If you have an Enterprise subscription plan, you can create child tenants by [linking multiple tenants to a single subscription](/docs/get-started/auth0-overview/create-tenants/child-tenants); child tenants each gain access to the paid or upgraded features associated with the subscription. You can ensure your development, staging, or testing environments have access to the same features as your production environment by linking them all to the same Enterprise subscription. +* For more information about creating multiple tenants, read [Manage multiple tenants with Auth0 teams](/docs/get-started/auth0-teams/tenant-management#manage-multiple-tenants). -## Tag the environment +* Your tenant's environment tag and your team's Auth0 subscription determine your tenant's rate limits. For more information, read our [rate limit policy](/docs/troubleshoot/customer-support/operational-policies/rate-limit-policy). -For each new tenant created, you should specify its environment. You can assign Environment Tags to your tenants to differentiate between development, staging, and production environments. - -If your tenant is mixed use, choose the higher environment. For example, a tenant used for both development and production should be set to **Production**. - -1. To assign an Environment Tag to a tenant, go to the [Dashboard > Settings > General](https://manage.auth0.com/#/tenant/general). - - ![Dashboard Tenant Settings General Settings tab](/docs/images/cdy7uua7fh8z/4okToiwlkNQBxwr8QGE3Rs/7e96db0efab4082ebb9f78cb43ee302c/Basic_Settings_-_EN.png) -2. Under **Assign Environment Tag**, identify your tenant's environment as **Development**, **Staging**, or **Production**. - - ![undefined](/docs/images/cdy7uua7fh8z/27OH1jFXce97CSjk7TPeD7/deafc344f675fb11ff5d3d589ffadee9/2025-02-26_14-27-31.png) -3. After selecting the environment, click **Save**. - -## Migration - -Through the [Management API v2](https://auth0.com/docs/api/management/v2), you can automate the migration of assets ([rules](/docs/customize/rules), database [connections](/docs/authenticate/identity-providers), and so forth) between tenants. - -For easier configuration management, save your configuration values in the [Dashboard](https://manage.auth0.com/#/rules), instead of hardcoding them into your **rules** or **db connections** scripts. - -For example, let's say you want to set a URL for logs. One way to do it is to hardcode it in the rule: - -```javascript lines -function(user, context, callback){ - var log_url = 'https://someurl/log'; - ... - } -``` - - - - - - -This code, however, is not portable since this URL will likely change from development to production. - -The recommended way of working with code that you need to use/move from development to product is via [Rules](https://manage.auth0.com/#/rules) section. If you have not yet created a rule, you'll need to do so. (Otherwise, jump to step 4.) - -1. Click **Create Your First Rule**. -2. Choose the **empty rule** template. -3. Enter a name for your new rule, and click **Save**. -4. Go to [Dashboard > Rules](https://manage.auth0.com/#/rules), and scroll to the bottom of the page to set your configuration values (we will use `log_url` for the key name, and `https://someurl/log` for value), then click **Create**. -5. Now, you can write your rule. Edit the rule you created, enter the following code in the code area, and click **Save**. - - ```javascript lines - function(user, context, callback){ - var log_url = configuration.log_url; - ... - } - ``` - - - - - - -This code is portable, and when you migrate to production, you only need to change this setting instead of searching your scripts. +* To synchronize settings and configuration between tenants, you can use the [Auth0 Deploy CLI](/docs/deploy-monitor/deploy-cli-tool). ## AD/LDAP Connectors -If you use multiple Auth0 tenants with AD/LDAP, you will need to create an AD/LDAP Connection and set up an AD/LDAP Connector for each tenant. This is because each AD/LDAP Connector is tied to a specific Connection within an Auth0 tenant. +If you use multiple Auth0 tenants with AD/LDAP, you need to create an AD/LDAP Connection and set up an AD/LDAP Connector for each tenant. -Multiple AD/LDAP Connectors can point to the same AD or LDAP directory, but each AD/LDAP Connector can only be used by one Connection within one Auth0 tenant. +This is because each AD/LDAP Connector is tied to a specific Connection within an Auth0 tenant. Multiple AD/LDAP Connectors can point to the same AD or LDAP directory, but each AD/LDAP Connector can only be used by one connection within one Auth0 tenant. If you have multiple AD/LDAP directories against which users will authenticate (for example, to support different departments or customers, each with their own directory), you can set up multiple AD/LDAP Connectors within each Auth0 tenant. - -## Learn more - -* [Create Multiple Tenants](/docs/get-started/auth0-overview/create-tenants/create-multiple-tenants) -* [Delete or Reset Tenants](/docs/troubleshoot/customer-support/manage-subscriptions/delete-or-reset-tenant) -* [Link Multiple Tenants to a Single Subscription](/docs/get-started/auth0-overview/create-tenants/child-tenants) diff --git a/main/docs/get-started/auth0-overview/dashboard.mdx b/main/docs/get-started/auth0-overview/dashboard.mdx index 803812675b..19195b86dc 100644 --- a/main/docs/get-started/auth0-overview/dashboard.mdx +++ b/main/docs/get-started/auth0-overview/dashboard.mdx @@ -1,63 +1,235 @@ --- -description: Describes the Auth0 Dashboard and all the features you can access to implement authentication and authorization with your applications and APIs.. -sidebarTitle: Overview -title: Auth0 Dashboard +description: Learn how to use the Auth0 Dashboard to register applications, configure authentication, manage users, and monitor your identity infrastructure. +title: The Auth0 Dashboard --- -The [Auth0 Dashboard](https://manage.auth0.com/#) is where you manage all aspects of your Auth0 subscription and configuration. -![Auth0 Dashboard Activity page](/docs/images/cdy7uua7fh8z/6k0cRLNEPko6vY6Kw7nIQD/4590d1b9d3e79f8d9c9970d733b08d02/2025-01-28_14-34-41.png) +The [Auth0 Dashboard](https://manage.auth0.com/#) is the web-based management console for your Auth0 tenant. When you sign up for Auth0, the Dashboard is where you do the hands-on work of connecting your applications to Auth0's identity platform, including setting up how users log in, defining what they can access, and watching how your integration behaves in production. -It consists of several sections that you can navigate using the sidebar menu on your left. +The Dashboard is a control panel for your identity infrastructure. Every Auth0 resource, including applications, APIs, connections, users, security policies, and logs, lives inside a tenant, and the Dashboard gives you a visual interface to configure and operate all of it from one place. + +If you prefer to work programmatically, every Dashboard operation is also available through the [Management API](/docs/api/management/v2), [Auth0 CLI](https://auth0.github.io/auth0-cli/), and [Terraform provider](/docs/deploy-monitor/auth0-terraform-provider). Most teams use the Dashboard for exploration, debugging, and one-off tasks, then automate repeatable work through code. -For best practices around usage of the Teams Dashboard, [see General Usage and Operations Best Practices](/docs/troubleshoot/general-usage-and-operations-best-practices). +For operational best practices, see [General Usage and Operations Best Practices](/docs/troubleshoot/general-usage-and-operations-best-practices). -## Configure implementation +## First steps after signing up + +If you just created your Auth0 account, these are the tasks you'll complete first: + + + + Tell Auth0 about the app you want to protect. Go to **Applications > Applications** and select **Create Application**. Choose the type that matches your project (Single-Page App, Regular Web App, Native, or Machine to Machine), and Auth0 pre-fills recommended settings. + + To learn more, read [Create Applications](/docs/get-started/auth0-overview/create-applications). + + + + Decide how users will log in. Go to **Authentication** and configure at least one connection — a database for email/password, a social provider like Google, or an enterprise provider like Okta Workforce Identity Cloud or Microsoft Entra ID. + + To learn more, read [Identity Providers](/docs/authenticate/identity-providers). + + + + Auth0 gives you a hosted login page out of the box. Go to **Branding > Universal Login** to preview it, then customize the look and feel to match your brand. + + To learn more, read [Auth0 Universal Login](/docs/authenticate/login/auth0-universal-login). + + + + Back on your application's **Settings** tab, use the **Quickstart** guide or the **Try** button to walk through a full login cycle and confirm tokens are issued correctly. + + + +## What you can manage + +The Dashboard sidebar organizes your tenant configuration into the sections below. Each section maps to a set of tasks you'll perform as you build and operate your integration. + +### Getting Started + +Guided walkthroughs that help you register your first application, connect an identity provider, and test a login flow. If you're new to Auth0, start here. + +### AI Agents + +Configure Auth0 to issue and validate tokens for AI agent workflows. This includes tool-level consent, token exchange, and async authorization patterns. This section is the starting point for integrating Auth0 with generative AI applications. + +To learn more, read [Auth0 for AI Agents](/docs/get-started/auth0-for-ai-agents). + +### Activity + +Your Dashboard home screen. Shows key metrics like login counts, new signups, and failed authentication attempts so you can spot trends and issues at a glance. + +To learn more, read [Activity Page](/docs/get-started/auth0-overview/dashboard/activity). + +### Applications + +Register every app and API that participates in your Auth0 integration. This is the starting point for most configurations. After an application is registered, you can assign connections, set callback URLs, configure grant types, and retrieve client credentials. + +| Area | What you do there | +| --- | --- | +| **Applications** | Register web apps, SPAs, native apps, and M2M clients. Configure allowed URLs, credentials, and grant types. | +| **APIs** | Register resource servers you want to protect with access tokens. Define permissions (scopes) and token settings. | +| **SSO Integrations** | Enable pre-built single sign-on connections to third-party services like Slack, Salesforce, or Zoom. | + +To learn more, read [Create Applications](/docs/get-started/auth0-overview/create-applications) and [Register APIs](/docs/get-started/auth0-overview/set-up-apis). + +### Authentication + +Configure where user credentials come from and how they're verified. You can use multiple connection types simultaneously. For example, offering both Google social login and an enterprise SAML connection for the same application. + +| Area | What you do there | +| --- | --- | +| **Database** | Store credentials in Auth0's built-in datastore or connect to your own database with custom scripts. Supports lazy migration of legacy credentials without requiring a password reset. | +| **Social** | Enable login with Google, Facebook, Apple, GitHub, X, and other OAuth/OIDC providers. | +| **Enterprise** | Federate with SAML, OIDC, Microsoft Entra ID, Active Directory/LDAP, Google Workspace, and other enterprise identity providers. | +| **Passwordless** | Let users log in with a one-time code (email or SMS) or a magic link instead of a password. | +| **Authentication Profile** | Define a [connection profile](/docs/authenticate/enterprise-connections/connection-profile) that groups configuration settings shared across multiple enterprise connections. | + +To learn more, read [Authentication](/docs/authenticate) and [Identity Providers](/docs/authenticate/identity-providers). + +### Organizations + +If your product serves business customers who each need their own identity configuration, Organizations let you model that. Each organization can have its own set of enabled connections, members, and branding. + +To learn more, read [Organizations](/docs/manage-users/organizations). + +### User Management + +View, search, and administer every user profile in your tenant. From here you can manually create users, trigger password resets, block or delete accounts, inspect login history, and assign roles. + +| Area | What you do there | +| --- | --- | +| **Users** | Browse, search, create, and edit user profiles. View raw JSON metadata, linked accounts, and login history for any user. | +| **Roles** | Define roles that bundle permissions together, then assign roles to users. Roles power your [role-based access control (RBAC)](/docs/manage-users/access-control/rbac) policies. | + +To learn more, read [Manage Users](/docs/manage-users). + +### Branding + +Control the look and feel of every Auth0-hosted surface your users see, from the login page to transactional emails and phone messages. + +| Area | What you do there | +| --- | --- | +| **Universal Login** | Customize the hosted login page: colors, logo, layout, text prompts, and which authentication methods appear. | +| **Custom Domains** | Serve the login page from your own domain (e.g., `login.yourcompany.com`) instead of `yourcompany.auth0.com`. | +| **Email Templates** | Edit the templates for verification, welcome, password-reset, and blocked-account emails. | +| **Email Provider** | Connect your own SMTP or email service (SendGrid, Amazon SES, Mandrill, etc.) so transactional emails come from your domain. | +| **Phone Templates** | Customize the content of SMS and voice messages sent for passwordless login and MFA verification. | +| **Phone Provider** | Configure the telephony provider (Twilio, MessageBird, etc.) that delivers SMS and voice messages on your tenant's behalf. | + +To learn more, read [Customize](/docs/customize). + +### Security + +Harden your tenant against credential attacks, bot traffic, and compromised passwords. These features work alongside Universal Login with no custom code required. + +| Area | What you do there | +| --- | --- | +| **Attack Protection** | Enable bot detection (reCAPTCHA Enterprise), brute-force protection, suspicious IP throttling, and breached password detection. | +| **Access Control** | Configure [role-based access control (RBAC)](/docs/manage-users/access-control) policies and manage how permissions are evaluated and enforced. | +| **Multi-factor Authentication** | Require a second factor — push notification, OTP, SMS, email, or WebAuthn — during login. Configure adaptive MFA to challenge only when risk signals are elevated. | +| **Security Center** | Monitor threat intelligence events, view security recommendations, and configure [prioritized log streams](/docs/secure/security-center) for security-critical data. | +| **Monitoring** | View real-time authentication metrics and signals within the Security context. | + +To learn more, read [Security](/docs/secure) and [Attack Protection](/docs/secure/attack-protection). + +### Actions + +Actions are serverless functions that run at specific points in the Auth0 pipeline, including login, registration, password reset, M2M token exchange, and more. Use them to add custom claims to tokens, call external APIs, enforce business rules, or route users through additional steps. + +| Area | What you do there | +| --- | --- | +| **Triggers** | See which pipeline trigger points are available and drag actions into each flow. | +| **Forms** | Build [visual workflows](/docs/customize/forms) that collect additional user input during login or registration with no custom UI required. | +| **Library** | Browse, create, and manage your tenant's Action code. Includes both custom Actions and installed Marketplace integrations. | + +To learn more, read [Auth0 Actions](/docs/customize/actions). + +### Auth Pipeline (Deprecated) + +Rules and Hooks were the predecessors to Actions. If your tenant still uses them, you can view and edit them here. For new work, use Actions instead. + +To learn more, read [Migrate from Rules to Actions](/docs/customize/actions/migrate/migrate-from-rules-to-actions). -The following table contains a brief overview of the different Dashboard sections and what you can do in each. +### Event Streams -| Section | Description | +Stream real-time events from your Auth0 tenant to external destinations. Unlike log streams (which forward historical log data), event streams deliver events as they happen. This is useful for triggering downstream workflows, syncing user data, or driving real-time analytics. + +To learn more, read [Create an Event Stream](/docs/customize/events/create-an-event-stream). + +### Monitoring + +Track what's happening in your tenant in real time: who logged in, what failed, and what configuration changes administrators made. + +| Area | What you do there | | --- | --- | -| **Applications** | Manage your applications, APIs, and single sign-on (SSO) integrations.
**Applications**: For each of your apps for which you want to authenticate users with Auth0, register an application.
**APIs**: For each of your APIs that you want to secure with Auth0, register an API. Create new APIs and manage existing ones.
**SSO Integrations**: View and enable external services for SSO. Create new SSO integrations and configure, review, and manage integration settings. | -| **Authentication** | Manage the identity providers through which you allow users to authenticate to your apps.
**Database**: Securely store and manage identifier/password credentials either in an Auth0 datastore or in your own database. Connect to existing databases using template-based JavaScript scripts that run on Auth0's server during every authentication. Gradually migrate an existing database of legacy credentials to Auth0 as users authenticate (no password reset required).
**Social**: Configure social identity providers (such as Facebook, X, and Github) through which your users can log in.
**Enterprise**: Configure enterprise identity providers (such as Active Directory, SAML, and Office 365) through which your users can log in using their enterprise credentials.
**Passwordless**: Allow your users to sign up and log in using one-time passcodes (delivered by email or SMS) or one-click links, instead of passwords. | -| **Organizations** | Manage the organizations you do business with, and customize the experience their users have when accessing your applications. | -| **User Management** | Manage your users' identities and permissions.
**Users**: View and create user profiles, perform password resets, block and delete users, and more.
**Roles**: Create and manage roles for your apps. Roles contain collections of permissions and can be assigned to users. | -| **Branding** | **Universal Login**: Create and customize a login page to which you can direct users to authenticate.
**Custom Domains**: Create a custom domain to maintain a consistent experience for your users.
**Email Templates**: Use templates to create welcome, password reset, and account verification email-based workflows.
**Email Provider**: Designate and configure your custom email provider information. | -| **Security** | Configure extra layers of security by enabling shields that protect your users against different types of attacks and user access anomalies.
**Attack Protection**: Manage settings for bot, IP throttling, brute-force, and breached password attacks.
**Multi-factor Auth**: Require additional factors during the login process to prevent unauthorized access.
**Monitoring**: Monitor threat intelligence events with one of our data visualization and alerting integrations. | -| **Actions** | Configure flows such as login, machine-to-machine, user registration, and password resets. Create and manage customized actions used in flows. | -| **Auth Pipeline** | **Rules**: Configure custom JavaScript snippets that are executed in Auth0 as part of each user authentication transaction. You can call external APIs, filter which users can log in to your application, use an AllowList, configure geolocated access, and so on.
**Hooks**: Customize the behavior of Auth0 when you use Database Connections by configuring Node.js code that is executed against extensibility points (which are comparable to webhooks that come with a server). | -| **Monitoring** | **Logs**: View log data of actions taken in the dashboard by administrators and user logins.
**Streams**: Create and manage log event streaming to external data analysis services. | -| **Marketplace** | Explore integrations that help your business do more with Auth0. | -| **Extensions** | Extend the Auth0 platform with official and third-party add-ons. | -| **Settings** | Configure your tenants, manage your Auth0 subscription and payment options, control your tenant administrators and other user roles. Manage other tenant settings related to your custom domains, signing keys, and other advanced settings. | -| **Get Support** | Go to our [Support Center](https://support.auth0.com). If your plan does not have access to support services, see the [Auth0 Community](https://community.auth0.com/). | - -## Manage account settings - -On the top left, you can see your tenant's name and icon, and a little arrow. This arrow displays a dropdown menu that you can use to configure different aspects of your account: - -* [**Settings**](/docs/get-started/tenant-settings): Configure several aspects of your tenant. -* [**Invite a member**](/docs/get-started/manage-dashboard-access): Add an additional user as an administrator or other role to your tenant configuration. -* [**Quota Utilization**](https://support.auth0.com/reports/quota): See quota utilization information about your subscription and tenants. -* [**Create tenant**](/docs/get-started/auth0-overview/create-tenants): Use this to create a new tenant. -* **Switch tenant**: If you have [multiple tenants](/docs/get-started/auth0-overview/create-tenants/create-multiple-tenants), use this option to switch between them. If you create an application for one tenant, you will not see it listed for another tenant. - -On the top right, you see several clickable options: - -* **Search**: Look for apps, marketplace entries, users, and other content related to your tenant. -* **Discuss your needs:** Contact an Auth0 expert to help you reach your goals with Auth0. -* **Docs:** A link to the documentation site you’re reading right now. -* **Notifications bell:** Informs you of new communication from Auth0 or your tenant settings. -* **Profile:** A link to your local tenant profile, as well as options to [change your theme](/docs/get-started/dashboard-profile/light-and-dark-themes) and log out. +| **Logs** | Search and filter authentication events and administrative actions. Each log entry includes timestamp, event type, IP address, and user details. | +| **Log Streams** | Forward log events to external services (Amazon EventBridge, Azure Event Grid, Datadog, Splunk, Sumo Logic, and others) for long-term retention and analysis. | +| **Action Logs** | View real-time execution logs for your Actions to debug custom pipeline logic. | +| **Metric Streams** | Stream Auth0 tenant metrics to external monitoring services for dashboards and alerting. | + +To learn more, read [Logs](/docs/deploy-monitor/logs), [Log Streaming](/docs/customize/log-streams), and [Metric Streams](/docs/deploy-monitor/metric-streams). + +### Marketplace + +Browse and install pre-built integrations from the [Auth0 Marketplace](https://marketplace.auth0.com/). Marketplace integrations cover social connections, Actions, SSO, and more. These are maintained by Auth0 and verified partners. + +### Extensions + +Add functionality directly to the Dashboard through Auth0 Extensions. For example, delegated administration, user import/export, or the authorization extension. Extensions are tenant-scoped and run within your Auth0 environment. + +To learn more, read [Auth0 Extensions](/docs/customize/extensions). + +### Settings + +Configure tenant-level defaults that affect your entire Auth0 environment: + +- **General**: Tenant name, environment tag (development, staging, production), support and logo URLs. +- **Subscription**: View your plan, usage, and billing details. +- **Payment & Billing**: View and edit your payment and billing information. +- **Tenant Members**: Invite team members and assign Dashboard access roles. +- **Custom Domains**: Manage domain verification and certificate status (also accessible under **Branding**). +- **Signing Keys**: Rotate and manage the keys Auth0 uses to sign tokens. +- **Encryption Keys**: Manage the keys used to protect the data in your tenant. +- **Advanced**: Session timeouts, extensibility runtimes, migration flags, and API access settings. + +To learn more, read [Tenant Settings](/docs/get-started/tenant-settings). + +## Navigate the Dashboard + +### Sidebar + +The left sidebar is the primary navigation. It groups configuration areas by domain (Applications, Authentication, Security, etc.). The sidebar stays visible on every page so you can move between sections without backtracking. + +### Tenant menu + +Click your tenant name in the top left to: + +- [Adjust tenant settings](/docs/get-started/tenant-settings) +- [Invite team members](/docs/get-started/manage-dashboard-access) +- [Create a new tenant](/docs/get-started/auth0-overview/create-tenants) +- [Switch between tenants](/docs/get-started/auth0-overview/create-tenants/create-multiple-tenants) (if you have more than one) +- [View quota utilization](https://support.auth0.com/reports/quota) + +### Top bar + +The top-right area gives you quick access to: + +- **Search** — Find applications, users, marketplace entries, and other tenant objects. +- **Notifications** — Alerts from Auth0 about your tenant. +- **Documentation** — Direct link to this documentation site. +- **Profile** — Theme preferences (light/dark) and sign-out. + +## Dashboard vs. Management API + +Everything you can do in the Dashboard is also available programmatically through the [Auth0 Management API](/docs/api/management/v2). Use the Dashboard for exploratory work, debugging, and one-off tasks. Use the Management API (or the [Auth0 CLI](https://auth0.github.io/auth0-cli/) and [Terraform provider](/docs/deploy-monitor/auth0-terraform-provider)) when you need automation, CI/CD integration, or infrastructure-as-code workflows. ## Learn more -* [Create Tenants](/docs/get-started/auth0-overview/create-tenants) -* [Tenant Settings](/docs/get-started/tenant-settings) -* [Application Settings](/docs/get-started/applications/application-settings) -* [Create Users](/docs/manage-users/user-accounts/create-users) -* [API Settings](/docs/get-started/apis/api-settings) -* [Logs](/docs/deploy-monitor/logs) +- [Activity Page](/docs/get-started/auth0-overview/dashboard/activity) — Understand the metrics on your Dashboard home screen. +- [Create Applications](/docs/get-started/auth0-overview/create-applications) — Register your first application. +- [Tenant Settings](/docs/get-started/tenant-settings) — Configure tenant-level defaults. +- [Create Users](/docs/manage-users/user-accounts/create-users) — Manually create user profiles. +- [Logs](/docs/deploy-monitor/logs) — Search and filter authentication events. diff --git a/main/docs/get-started/auth0-overview/tenants.mdx b/main/docs/get-started/auth0-overview/tenants.mdx new file mode 100644 index 0000000000..042bfb463f --- /dev/null +++ b/main/docs/get-started/auth0-overview/tenants.mdx @@ -0,0 +1,49 @@ +--- +title: Auth0 Tenants +sidebarTitle: Overview +description: Learn what an Auth0 tenant is, what resources it contains, and how tenants provide isolation for your identity infrastructure. +--- + +An Auth0 tenant is a logically isolated unit that holds your Auth0 configuration and data. + +Your tenant is where you configure your use of Auth0 and where Auth0 resources (such as [applications](/docs/get-started/applications), [connections](/docs/authenticate/identity-providers), and [user profiles](/docs/get-started/architecture-scenarios/business-to-business/profile-management)) are defined, managed, and stored. + +## Creating tenants + +When you sign up for Auth0, you immediately [create your first tenant](./create-tenants). + +Your tenant's name and region define your Auth0 domain (in the format `{tenant-name}.{region}.auth0.com`), which is the base URL for your authentication requests, Management API calls, and Universal Login page. + +Every tenant is fully independent. Tenants do not share users, configuration, credentials, or data unless you explicitly build an integration for it. + +Most teams start with one tenant, but you can use multiple tenants to [separate development environments](./create-tenants/set-up-multiple-environments), business units, or compliance domains. + +## Configuring tenants and resources + +We provide several options for configuring tenants and resources: + +* For browser-based workflows, [the Auth0 Dashboard](/docs/get-started/auth0-overview/dashboard) is our web management console. + +* For programmatic workflows, the [Management API](/docs/api/management/v2) is the equivalent of the Dashboard. + +* For terminal-based workflows, the [Auth0 CLI](https://auth0.github.io/auth0-cli/) is our offical command-line client. + +* For infrastructure-as-code, the [Auth0 Terraform provider](/docs/deploy-monitor/auth0-terraform-provider) lets you define and version your Auth0 configuration alongside the rest of your infrastructure. + +Typically, teams use the Dashboard for interactive work and use the API, CLI, or Terraform for automation and CI/CD workflows. + +## Tenant resource overview + +A tenant stores the following resources and configuration: + +| Resource | Description | +| --- | --- | +| **[Applications](/docs/get-started/applications)** | The web apps, SPAs, native apps, and machine-to-machine clients that use Auth0 for authentication. Each application gets its own client ID and credentials. | +| **[APIs](/docs/get-started/auth0-overview/set-up-apis)** | The resource servers you protect with access tokens. You define permissions (scopes) here that your applications can request. | +| **[Connections](/docs/authenticate/identity-providers)** | The identity sources your users log in with — databases, social providers (Google, GitHub, Apple), enterprise providers (SAML, Microsoft Entra ID, Okta Workforce Identity Cloud), and passwordless options (email, SMS). | +| **[Users](/docs/manage-users)** | Every user profile in your directory, including credentials, metadata, linked accounts, login history, and role assignments. | +| **[Branding](/docs/customize)** | The look and feel of your Universal Login page, email templates, phone message templates, and custom domain configuration. | +| **[Actions](/docs/customize/actions)** | Serverless functions that run at specific points in the Auth0 pipeline — login, registration, password reset, M2M token exchange — to add custom logic. | +| **[Security policies](/docs/secure)** | Attack protection rules (bot detection, brute-force protection, breached password detection), multi-factor authentication settings, and access control policies. | +| **[Logs](/docs/deploy-monitor/logs)** | A record of every authentication event and administrative action in your tenant, searchable by event type, user, IP address, and timestamp. | +| **[Tenant settings](/docs/get-started/tenant-settings)** | Global configuration that affects the entire environment — session timeouts, signing keys, environment tags, and team member access. | diff --git a/main/docs/get-started/auth0-teams.mdx b/main/docs/get-started/auth0-teams.mdx index 4d3ad56a88..076832be7b 100644 --- a/main/docs/get-started/auth0-teams.mdx +++ b/main/docs/get-started/auth0-teams.mdx @@ -1,8 +1,8 @@ --- -description: Describes how Auth0 Teams allows you to manage tenants and tenant administrators. -sidebarTitle: Overview title: Auth0 Teams +description: Describes how Auth0 Teams allows you to manage tenants and tenant administrators. --- + Auth0 Teams provides a single point of visibility and control over your Auth0 resources by providing centralized governance, compliance, and secure collaboration at scale. Teams membership sits on top of the tenant membership account. The main team member role is referred to as the Team Owner and has visibility into all tenants within their Auth0 Account. As an Auth0 Team Owner, you can manage a single tenant or multiple tenants. diff --git a/main/docs/get-started/auth0-teams/tenant-management.mdx b/main/docs/get-started/auth0-teams/tenant-management.mdx index e047037fe2..88d99accb8 100644 --- a/main/docs/get-started/auth0-teams/tenant-management.mdx +++ b/main/docs/get-started/auth0-teams/tenant-management.mdx @@ -1,39 +1,24 @@ --- -description: Manage the Auth0 teams information within a given tenant. title: Tenant Management +description: Manage tenants associated with a team. --- -Access and modify Team information from within your tenant. If you don't yet have a tenant associated with your account, see [Create Tenants.](/docs/get-started/auth0-overview/create-tenants) -## Access the Teams Dashboard +If you are a Team Owner, you can use the Teams Dashboard to: -If you are a Team Owner, you can use the Teams Dashboard to: +* View all tenants associated with your team +* Link existing tenants to your team +* Create new tenants associated with your team +* Allow or disallow tenant administrators to create new tenants associated with your team -* Choose who can create new tenants: Team Owners or all tenant administrators. -* View all tenants created under your Auth0 subscription or custom agreement. -* View and invite Team Owners. +You can access the [Teams Dashboard at `https://accounts.auth0.com`](https://accounts.auth0.com) or by following the link in the [Auth0 Dashboard](https://manage.auth0.com/dashboard) tenant drop-down menu (**Go to team**). -To access the Teams Dashboard from any of your tenants: - -1. Select your tenant name from the tenant drop-down menu in the [Auth0 Dashboard](https://manage.auth0.com/dashboard). -2. Find your Teams name at the bottom of the menu and select **Go to team**. - -![Access the Auth0 Team Dashboard](/docs/images/cdy7uua7fh8z/3207T6ELEBc56dLZT84hjT/13779947b38dd52ab4694b3869271961/Tenant_Management_-_Teams.png) - -To access the Teams Dashboard using a URL: - -1. Navigate to `https://accounts.auth0.com/` -2. If your user account is a member of only one Team, enter your credentials to be taken to your Teams dashboard. If your user account is a member of one or more Teams, select the Team from the list of Teams your user account is associated with to login. - -If the option for Teams access isn't visible, try the following: +## View tenants -| Possible Cause | Action | -| --- | --- | -| The current tenant isn’t in Teams. | Try switching to a different tenant. | -| You’re not a Teams owner. | Ask a Teams owner to invite you to the team. | +1. Navigate to the [Teams Dashboard](https://accounts.auth0.com). -## View tenants +2. In the left menu, select **Tenants**. For Private Cloud Environments, select **Overview > Tenants**. -In the Teams Dashboard, you can view all tenants within your Auth0 custom agreement or subscription present in either the Public or Private Cloud Environment. For each tenant, you can review: +On this page, you can view all tenants under your Auth0 subscription present in either the Public or Private Cloud Environment. For each tenant, you can review: * Tenant name * Region @@ -41,111 +26,90 @@ In the Teams Dashboard, you can view all tenants within your Auth0 custom agreem * Environment (Development, Staging, or Production) * Tenant administrators -1. Select **Tenants** on the left side of the Teams Dashboard. - - For Private Cloud Environments, select the **Overview** menu drop-down to reveal the **Tenants** menu option. -2. If you’re an administrator for a tenant, select the tenant name to access the tenant. If you are not a tenant administrator, you will not be able to select the tenant. -3. To review tenant members, select **View Members**. +Team Owners can review tenant members by selecting **View Members**. Tenant administrators can select the tenant name to access the tenant in the Auth0 Dashboard. ## View private cloud environments -A list of private cloud environments can be viewed from the Teams Dashboard. You are able to view the following information +1. Navigate to the [Teams Dashboard](https://accounts.auth0.com). + +2. In the left menu, select **Overview > Private Cloud**. + +On this page, you can view a list of private cloud environments with the following information: * Environment name * Cloud provider type (AWS or Azure) * Deployment region * Failover region -* Current environment release version. - -1. Select the **Overview** menu drop-down to reveal the **Private Cloud** menu option. - -## Link tenants - - +* Current environment release version -This feature is currently available for the following Team Subscription types: +## Manage multiple tenants -* B2C - Essentials -* B2B - Essentials -* B2C - Professional -* B2B - Professional +If your [Auth0 subscription](/docs/troubleshoot/customer-support/manage-subscriptions) supports multiple tenants, Team Owners can link tenants, create tenants, and choose who else can create new tenants (only Team Owners or all tenant administrators). - +### Link existing tenants -Linking tenants allows you to share features and quota limits available within your Team Subscription with the linked tenant. Once linked, that tenants subscriptions will be tied to your Team and you would no longer have to individually manage the subscription for that tenant. +You can link a existing tenant to your team. Doing so cancels the subscription currently associated with the tenant and instead associates it with your team's subscription. This gives the tenant access to the features and quota limits of the team's subscription. Linking a tenant to your team also allows Team Owners to manage the tenant and its membership. -You are able to link tenants to your team, if the following conditions are true: +To link a tenant to a team, the following prerequisites must be satisfied: -* The tenant is not part of an existing Team. -* You are an administrator of the tenant you want to link. -* You have a Team Owner role on the team. +* The tenant must not be part of an existing team. - +* You must be a tenant administrator. -Linking a tenant cancels the subscription attached to the tenant. +* You must have the Team Owner role on the team. - +* Your team's [Auth0 subscription](/docs/troubleshoot/customer-support/manage-subscriptions) must support multiple tenants and your team must not be at the maximum number of tenants. -If these conditions are met, the tenant will show up as a possible option to link to your team when you select **Link Existing Tenant** from the Tenants page. +Then, to link a tenant: -## Create new tenant +1. Navigate to the [Teams Dashboard](https://accounts.auth0.com) and select the **Tenants** page. - +2. Under the list of tenants, select **Link Existing Tenants**. -This feature is currently available for the following Team Subscription types: +3. In the **Link Tenant** window that opens, select the tenant you want to link. -* B2C - Essentials -* B2B - Essentials -* B2C - Professional -* B2B - Professional -* Enterprise Private Cloud +### Create additional tenants -By using this feature, you agree to the applicable Free Trial terms in Okta’s [Master Subscription Agreement](https://www.okta.com/legal/). - +To create additional tenants on a team, the following prerequisites must be satisfied: -Team Owners can create a tenant from within the Teams Dashboard, automatically linking the created tenant with the team, including associating the Team Subscription details (available features and quota limits) with the newly created tenant. +* You must have the Team Owner role on the team, or a Team Owner must configure the team to allow tenant administrators to create tenants. -You can do this by clicking on the **Create New Tenant** button on the Tenants page, which will open the Create Tenant form. +* Your team's [Auth0 subscription](/docs/troubleshoot/customer-support/manage-subscriptions) must support multiple tenants and your team must not be at the maximum number of tenants. -## Manage tenants +Then, to create an additional tenant on a team, you can use either the Teams Dashboard or the Auth0 Dashboard: -You can control who can create new tenants under your Auth0 custom agreement or subscription under **Team Settings**. When creating a new tenant, administrators can: + + +When Team Owners (or tenant administrators, if allowed) create a tenant from the Auth0 Dashboard, the **Create Under** section lets them choose between: -* Link the tenant to custom agreement. The new tenant exists under your custom agreement or subscription. It benefits from the same features, counts toward limits, and is visible to Team Owners. - or -* Create a tenant under their personal account. The new tenant is not a part of your Teams' custom agreement or subscription. The administrator who creates the tenant can access it with the same login credentials. +* **Custom Agreement**: Create the tenant under the team's subscription. It benefits from the same features, counts toward limits, and is visible to Team Owners. -To allow administrators to link a tenant to a custom agreement, the Team Owner must: +* **Personal Account**: Create a tenant separately from the team. The new tenant is not a part of the team's subscription. -1. Select **Settings** on the left side of the Teams Dashboard. -2. Select the option **Allow Tenant Admins to Create Tenants under the Teams Account**. If this option is unchecked, then tenant administrators can create personal accounts only. +![](/docs/images/cdy7uua7fh8z/7ggqdv5yw011z0TsdlaHOO/7707d826dd585e074bd0d8e25b30d9d6/publiccloudtenants.png) - +If a tenant administrator tries to choose the **Custom Agreement** option when the team settings disallow it, the page prompts them to contact a Team Owner. + - The **Tenant Creation** option does not apply to Team Owners. Owners have permissions to create new tenants in the Teams instance under the custom agreement or subscription. + +Creating additional tenants from within the Teams Dashboard automatically links the new tenant with the team. This associates the tenant with your team's subscription and gives it access to the subscription's available features and quota limits. -
-3. Select **Save**. - - +1. Navigate to the [Teams Dashboard](https://accounts.auth0.com) and select the **Tenants** page. - If a Tenant administrator without permission attempts to create tenants, they will be prompted to contact the Team Owner. +2. In the top right corner of the page, select **+ Create Tenant**. - +3. In the **New Tenant** window that opens, choose the tenant's **Environment Tag**, **Region**, and **Tenant Domain** (name). - ![](/docs/images/cdy7uua7fh8z/1c7QzOKaTGVemnWkfNosXi/44fe024b9c0e0d875557b3854b7a2409/2022-08-10_11-18-32.png) +4. Select **Create**. + + -## View Team Subscription details +### Allow tenant admins to create tenants on the team - +Team Owners always have the ability to create tenants on a team. Team Owners can additionally choose whether or not tenant administrators can also create tenants on a team: -This feature is currently available for the following Team Subscription types: +1. Navigate to the [Teams Dashboard](https://accounts.auth0.com) and select the **Settings** page. -* B2C - Essentials -* B2B - Essentials -* B2C - Professional -* B2B - Professional +2. Toggle the **Allow Tenant Admins to Create Tenants under the Teams Account** option. - - -Team Owners can view Team Subscription details by visiting Subscription tab within the Setting page. \ No newline at end of file +3. Select **Save**. diff --git a/main/docs/get-started/authentication-and-authorization-flow/authenticate-with-mtls.mdx b/main/docs/get-started/authentication-and-authorization-flow/authenticate-with-mtls.mdx index 6987b3cbc0..ef92757e01 100644 --- a/main/docs/get-started/authentication-and-authorization-flow/authenticate-with-mtls.mdx +++ b/main/docs/get-started/authentication-and-authorization-flow/authenticate-with-mtls.mdx @@ -1,7 +1,8 @@ --- -description: Learn how to authenticate a client using mTLS. title: Authenticate with mTLS +description: Learn how to authenticate a client using mTLS. --- + ## mTLS in OAuth/OIDC Default OAuth/OIDC flows are not always secure because of the following issues: @@ -19,7 +20,7 @@ Optionally, mTLS can also be used to ensure an access token is used only by the ![](/docs/images/cdy7uua7fh8z/7qocbfqySAnu85ph6WVSGU/ee8cd3514ed1bb6fea554cbd63d230cf/HRI_diagrams_-_mtls_diagram_2__1_.png) -**Note**: mTLS client authentication and mTLS Token Binding can be used independently of each other. mTLS client authentication can be used without mTLS Token Binding, and mTLS Token Binding can be used with other forms of client authentication such as Client Secret or Private Key JWT. Even if other forms of client authentication are used, the client still sends the client certificate to the authorization server for mTLS Token Binding. +mTLS client authentication and mTLS Token Binding can be used independently of each other. mTLS client authentication can be used without mTLS Token Binding, and mTLS Token Binding can be used with other forms of client authentication such as Client Secret or Private Key JWT. Even if other forms of client authentication are used, the client still sends the client certificate to the authorization server for mTLS Token Binding. ## mTLS at Auth0 @@ -47,11 +48,6 @@ If mTLS client authentication is enabled, the OIDC discovery document includes t } ``` - - - - - If mTLS Token Binding is enabled, the OIDC discovery document sets the  `tls_client_certificate_bound_access_tokens` property to `true:` ```json lines @@ -62,11 +58,6 @@ If mTLS Token Binding is enabled, the OIDC discovery document sets the  `tls_cl } ``` - - - - - Environments that support mTLS endpoint aliases expose a new property, `mtls_endpoint_aliases`, that contains a list of endpoints that support mTLS. For clients that support mTLS, the endpoints listed under `mtls_endpoint_aliases` take precedence over the same endpoints exposed outside of `mtls_endpoint_aliases`. In the following code sample, the `token_endpoint` property is exposed twice. The endpoint to use for mTLS calls is listed under `mtls_endpoint_aliases`, or `https://mtls.auth.bank.com/oauth/token`: @@ -83,14 +74,9 @@ In the following code sample, the `token_endpoint` property is exposed twice. Th } ``` - - - - - If an endpoint is not listed under `mtls_endpoint_aliases`, use the same endpoint listed outside of `mtls_endpoint_aliases`. In the example above, `pushed_authorization_request_endpoint` is not listed under `mtls_endpoint_aliases`. As a result, use the `pushed_authorization_request_endpoint` exposed outside of `mtls_endpoint_aliases`, or `https://auth.bank.com/oauth/par`. -For more information, see RFC 8705’s [section on endpoint aliases](https://www.rfc-editor.org/rfc/rfc8705#name-metadata-for-mutual-tls-end). +For more information, see [RFC 8705’s section on endpoint aliases](https://www.rfc-editor.org/rfc/rfc8705#name-metadata-for-mutual-tls-end). ## Call the resource server @@ -100,4 +86,4 @@ When the client calls the resource server with a mTLS-bound access token, the re ## Learn more -* [Configure mTLS Authentication](/docs/get-started/applications/configure-mtls) \ No newline at end of file +* [Configure mTLS Authentication](/docs/get-started/applications/configure-mtls) diff --git a/main/docs/get-started/authentication-and-authorization-flow/authenticate-with-private-key-jwt.mdx b/main/docs/get-started/authentication-and-authorization-flow/authenticate-with-private-key-jwt.mdx index 7ab2d9de5a..d68f3e94d8 100644 --- a/main/docs/get-started/authentication-and-authorization-flow/authenticate-with-private-key-jwt.mdx +++ b/main/docs/get-started/authentication-and-authorization-flow/authenticate-with-private-key-jwt.mdx @@ -1,11 +1,10 @@ --- -description: Describes how to build an assertion to use Private Key JWT Authentication. title: Authenticate with Private Key JWT +description: Describes how to build an assertion to use Private Key JWT Authentication. --- - + You need to create a new application in Auth0 Dashboard or convert an existing application before you continue. To learn more, read [Configure Private Key JWT Authentication](/docs/get-started/applications/configure-private-key-jwt). - You need to complete two steps when authenticating with `private_key_jwt:` @@ -20,9 +19,7 @@ You can use one of Auth0’s SDKs to build an assertion automatically for you. I The assertion is a JSON Web Token (JWT) that should contain the following properties and claims: - All claims are required unless otherwise stated. To learn more about JWT claims, read [JSON Web Token Claims](/docs/secure/tokens/json-web-tokens/json-web-token-claims). - * Header @@ -36,17 +33,13 @@ All claims are required unless otherwise stated. To learn more about JWT claims, + `aud`**:** The URL of the Auth0 tenant or custom domain that receives the assertion. For example: `https://{yourTenant}.auth0.com/`**.** Include the trailing slash. - If you have configured a custom domain for your Auth0 tenant, this can be used as the `aud` claim. We recommend using the custom domain in this case. - + `iat` (optional), `nbf` (optional), and `exp`: Issued At, Not Before, and Expiration claims set to the correct timestamps. A clock skew of up to 10 seconds is allowed for `iat` and `nbf` (if present) to support inter-operability. The client assertion is a one-time use token, and we recommend the shortest possible expiry time. Auth0 supports a maximum of 5 minutes for the lifetime of a token. + `jti`: A unique claim ID created by the client. We recommend using the Universally Unique Identifier (UUID) format. - This JWT is a one-time use only token and should be considered as such by having a short expiry. We recommend setting a maximum of 1 minute. - The token must then be signed with the private key you generated when you created or configured your application for Private Key JWT Authentication. To learn how, review the [JSON Web Token specification](https://www.rfc-editor.org/rfc/rfc7519#section-7.1). @@ -86,11 +79,6 @@ async function main() { main(); ``` - - - - - Example client assertion signed with a private key: ![private key example](/docs/images/cdy7uua7fh8z/4O8zb1gZnEmUQ6FrRkfmlc/a30b73e09d51ca0b4bf929b91571a80a/2023-03-13_16-53-54.png) @@ -112,19 +100,12 @@ Corresponds to: } ``` - - - - - After you generate the JWT with the required information, you are ready to authenticate your application against Auth0. ## Exchange assertion for access tokens - The following example uses the [Client Credential Flow](/docs/get-started/authentication-and-authorization-flow/client-credentials-flow). Private Key JWT authentication can be used for other grant types that also allow replacing `client_secret` with `client_assertion`. - To exchange the JWT assertion for an access token, call the Authentication API [token endpoint](https://auth0.com/docs/api/authentication#authenticate-user) with the following parameters: @@ -141,11 +122,6 @@ curl --location --request POST 'https://$tenant/oauth/token' \ --data-urlencode 'audience=$resource_server_idenifier' ``` - - - - - ## Supported endpoints In addition to the [https://$tenant/oauth/token](https://auth0.com/docs/api/authentication#get-token) endpoint, the following Auth0 Authentication API endpoints support `private_key_jwt` authentication for configured applications: @@ -168,4 +144,4 @@ Claims within the assertion have the following limits: ## Learn more * [Configure Private Key JWT Authentication](/docs/get-started/applications/configure-private-key-jwt) -* [Private Key JWT Client Authentication for Okta and OIDC Connections](/docs/authenticate/enterprise-connections/private-key-jwt-client-auth) \ No newline at end of file +* [Private Key JWT Client Authentication for Okta and OIDC Connections](/docs/authenticate/enterprise-connections/private-key-jwt-client-auth) diff --git a/main/docs/get-started/authentication-and-authorization-flow/authorization-code-flow-with-pkce.mdx b/main/docs/get-started/authentication-and-authorization-flow/authorization-code-flow-with-pkce.mdx index 0230bad55d..50a17f97bb 100644 --- a/main/docs/get-started/authentication-and-authorization-flow/authorization-code-flow-with-pkce.mdx +++ b/main/docs/get-started/authentication-and-authorization-flow/authorization-code-flow-with-pkce.mdx @@ -2,26 +2,24 @@ description: Learn how the Authorization Code flow with Proof Key for Code Exchange (PKCE) works and why you should use it for native and mobile apps. title: Authorization Code Flow with Proof Key for Code Exchange (PKCE) --- - + Key Concepts * Learn about the OAuth 2.0 grant type, Authorization Code Flow with Proof Key for Code Exchange (PKCE). * Use this grant type for applications that cannot store a client secret, such as native or single-page apps. * Review different implementation methods with Auth0 SDKs. - -When public clients (e.g., native and single-page applications) request access tokens, some additional security concerns are posed that are not mitigated by the Authorization Code Flow alone. This is because: +When public clients (e.g., native and single-page applications) request access tokens, some additional security concerns are posed that are not mitigated by the Authorization Code Flow alone. -**Native apps** +For native apps, this is because they: * Cannot securely store a Client Secret. Decompiling the app will reveal the Client Secret, which is bound to the app and is the same for all users and devices. * Are vulnerable to authorization code interception and injection attacks. Without a client secret, an attacker who intercepts the authorization code can exchange it for tokens. * May make use of a custom URL scheme to capture redirects (e.g., MyApp://) potentially allowing malicious applications to receive an Authorization Code from your Authorization Server. Because of this risk, **Auth0 strongly discourages the use of custom URI schemes**. To learn more, read [Measures Against Application Impersonation](/docs/secure/security-guidance/measures-against-app-impersonation.mdx). - -**Single-page apps** +For single-page apps, this is because they: * Cannot securely store a Client Secret because their entire source is available to the browser. @@ -48,39 +46,27 @@ Because the PKCE-enhanced Authorization Code Flow builds upon the [standard Aut 11. The API responds with requested data. - If you have [Refresh Token Rotation](/docs/secure/tokens/refresh-tokens/refresh-token-rotation) enabled, a new Refresh Token is generated with each request and issued along with the Access Token. When a Refresh Token is exchanged, the previous Refresh Token is invalidated but information about the relationship is retained by the authorization server. - ## How to implement it The easiest way to implement the Authorization Code Flow with PKCE is to [follow our Native Quickstarts](/docs/quickstart/native) or [follow our Single-Page Quickstarts](/docs/quickstart/spa). -Depending on your application type, you can also use our mobile or single-page app SDKs: - -**Mobile** - -* [Auth0 Swift SDK](/docs/libraries/auth0-swift) -* [Auth0 Android SDK](/docs/libraries/auth0-android) +Depending on your application type, you can also use our SDKs: -**Single-page** +* For mobile apps, use the [Auth0 Swift SDK](/docs/libraries/auth0-swift) or [Auth0 Android SDK](/docs/libraries/auth0-android). -* [Auth0 Single-Page App SDK](/docs/libraries/auth0-single-page-app-sdk) -* [Auth0 React SDK](/docs/libraries/auth0-react) +* For single-page apps, use the [Auth0 Single-Page App SDK](/docs/libraries/auth0-single-page-app-sdk) or [Auth0 React SDK](/docs/libraries/auth0-react). - Recent advancements in user privacy controls in browsers adversely impact the user experience by preventing access to third-party cookies; therefore, browser-based flows must use [Refresh Token Rotation](/docs/secure/tokens/refresh-tokens/refresh-token-rotation), which provides a secure method for using refresh tokens in SPAs while providing end-users with seamless access to resources without the disruption in UX caused by browser privacy technology like ITP. - You can follow our tutorials to use our API endpoints to [Add Login Using the Authorization Code Flow with PKCE](/docs/get-started/authentication-and-authorization-flow/authorization-code-flow-with-pkce/add-login-using-the-authorization-code-flow-with-pkce) or [Call Your API Using the Authorization Code Flow with PKCE](/docs/get-started/authentication-and-authorization-flow/authorization-code-flow-with-pkce/call-your-api-using-the-authorization-code-flow-with-pkce). ## Learn more -* [Auth0 Rules](/docs/customize/rules) -* [Auth0 Hooks](/docs/customize/hooks) * [Tokens](/docs/secure/tokens) * [Token Best Practices](/docs/secure/tokens/token-best-practices) * [Which OAuth 2.0 Flow Should I Use?](/docs/get-started/authentication-and-authorization-flow/which-oauth-2-0-flow-should-i-use) diff --git a/main/docs/get-started/authentication-and-authorization-flow/authorization-code-flow.mdx b/main/docs/get-started/authentication-and-authorization-flow/authorization-code-flow.mdx index c3daf55d2b..2a216c4705 100644 --- a/main/docs/get-started/authentication-and-authorization-flow/authorization-code-flow.mdx +++ b/main/docs/get-started/authentication-and-authorization-flow/authorization-code-flow.mdx @@ -1,8 +1,8 @@ --- -description: Learn how the Authorization Code flow works and why you should use it for regular web apps. -sidebarTitle: Overview title: Authorization Code Flow +description: Learn how the Authorization Code flow works and why you should use it for regular web apps. --- + The Authorization Code Flow (defined in [OAuth 2.0 RFC 6749, section 4.1](https://tools.ietf.org/html/rfc6749#section-4.1)), involves exchanging an authorization code for a token. This flow can only be used for confidential applications (such as Regular Web Applications) because the application's authentication methods are included in the exchange and must be kept secure. @@ -29,15 +29,11 @@ The easiest way to implement the Authorization Code Flow is to follow our [Regul Alternatively, you can use the Authentication API to implement the Authorization Code Flow. For more information, read [Add Login Using the Authorization Code Flow](/docs/get-started/authentication-and-authorization-flow/authorization-code-flow/add-login-auth-code-flow) or [Call Your API Using the Authorization Code Flow](/docs/get-started/authentication-and-authorization-flow/authorization-code-flow/call-your-api-using-the-authorization-code-flow). - If a browser application, with an Origin header, makes a `POST` request to the `/oauth/token` endpoint, Auth0 doesn’t issue refresh tokens, even if the application has [Allow Refresh Token Rotation](/docs/secure/tokens/refresh-tokens/configure-refresh-token-rotation) enabled and sends the [offline_access](/docs/secure/tokens/refresh-tokens/configure-refresh-token-rotation#configure-with-the-auth0-spa-sdk) scope. - ## Learn more -* [Auth0 Rules](/docs/customize/rules) -* [Auth0 Hooks](/docs/customize/hooks) * [Tokens](/docs/secure/tokens) * [Token Best Practices](/docs/secure/tokens/token-best-practices) * [Which OAuth 2.0 Flow Should I Use?](/docs/get-started/authentication-and-authorization-flow/which-oauth-2-0-flow-should-i-use) diff --git a/main/docs/get-started/authentication-and-authorization-flow/client-credentials-exchange.mdx b/main/docs/get-started/authentication-and-authorization-flow/client-credentials-exchange.mdx index 359933983d..7af56c3a7c 100644 --- a/main/docs/get-started/authentication-and-authorization-flow/client-credentials-exchange.mdx +++ b/main/docs/get-started/authentication-and-authorization-flow/client-credentials-exchange.mdx @@ -1,9 +1,9 @@ --- -description: Learn how Hooks can be used with the Client Credentials Exchange extensibility point, which is available for database connections and passwordless connections. title: Client Credentials Exchange +description: Learn how Hooks can be used with the Client Credentials Exchange extensibility point, which is available for database connections and passwordless connections. --- - + The End of Life (EOL) date of Rules and Hooks will be **November 18, 2026**, and they are no longer available to new tenants created as of **October 16, 2023**. Existing tenants with active Hooks will retain Hooks product access through end of life. We highly recommend that you use Actions to extend Auth0. With Actions, you have access to rich type information, inline documentation, and public `npm` packages, and can connect external integrations that enhance your overall extensibility experience. To learn more about what Actions offer, read [Understand How Auth0 Actions Work](/docs/customize/actions/actions-overview). @@ -11,7 +11,6 @@ We highly recommend that you use Actions to extend Auth0. With Actions, you have To help with your migration, we offer guides that will help you [migrate from Rules to Actions](/docs/customize/actions/migrate/migrate-from-rules-to-actions) and [migrate from Hooks to Actions](/docs/customize/actions/migrate/migrate-from-hooks-to-actions). We also have a dedicated [Move to Actions](https://auth0.com/extensibility/movetoactions) page that highlights feature comparisons, [an Actions demo](https://www.youtube.com/watch?v=UesFSY1klrI), and other resources to help you on your migration journey. To read more about the Rules and Hooks deprecation, read our blog post: [Preparing for Rules and Hooks End of Life](https://auth0.com/blog/preparing-for-rules-and-hooks-end-of-life/). - At the Client Credentials Exchange extensibility point, Hooks let you execute custom actions when an Access Token is issued through the Authentication API [`POST /oauth/token` endpoint](https://auth0.com/docs/api/authentication#client-credentials-flow) using the Client Credentials Flow. For example, you may deny the token from being issued, add custom claims to the access token, or modify its scopes. To learn more, read [Client Credentials Flow](/docs/get-started/authentication-and-authorization-flow/client-credentials-flow). @@ -19,9 +18,7 @@ At the Client Credentials Exchange extensibility point, Hooks let you execute cu Hooks at this extensibility point are blocking (synchronous), which means they execute as part of the trigger's process and prevent the rest of the Auth0 pipeline from running until the Hook is complete. - The `triggerId` for the Client Credentials Exchange extensibility point is `credentials-exchange`. To learn how to create hooks for this extensibility point, read [Create Hooks](/docs/customize/hooks/create-hooks). - To learn about other extensibility points, read Extensibility Points. @@ -68,16 +65,9 @@ module.exports = function(client, scope, audience, context, cb) { }; ``` +The callback function (`cb`) at the end of the sample code signals completion and must be included. - - - - -Please note: - -* The callback function (`cb`) at the end of the sample code signals completion and must be included. - -* The line `access_token.scope = scope` ensures that all granted scopes will be present in the access token. Removing it will reset all scopes, and the token will include only scopes you add with the script. +The line `access_token.scope = scope` ensures that all granted scopes will be present in the access token. Removing it will reset all scopes, and the token will include only scopes you add with the script. ### Default response @@ -89,19 +79,12 @@ When you run a Hook executed at the Client Credentials Exchange extensibility po } ``` - - - - - ### Starter code response Once you've customized the starter code with your scopes and additional claims, you can test the Hook using the runner embedded in the Hook Editor. The runner simulates a call to the Hook with the same body and response that you would get with a Client Credentials Exchange. - Executing the code using the runner requires a save, which means that the original code will be overwritten. - When you run a Hook based on the starter code, the response object is: @@ -123,11 +106,6 @@ When you run a Hook based on the starter code, the response object is: } ``` - - - - - ## Sample script: Add an additional scope to the access token In this example, we use a Hook to add an additional scope to those already existing for the access token. @@ -151,11 +129,6 @@ module.exports = function(client, scope, audience, context, cb) { }; ``` - - - - - To learn more, read [Scopes](/docs/get-started/apis/scopes). ### Response @@ -171,11 +144,6 @@ When we run this Hook, the response object is: } ``` - - - - - ## Sample script: Add a claim to the access token In this example, we add a namespaced custom claim and its value to the access token. To learn more, read [Create Namespaced Custom Claims](/docs/secure/tokens/json-web-tokens/create-custom-claims). @@ -188,9 +156,7 @@ You can add the following as claims to the issued token: The extensibility point ignores all other response object properties. - To access a configured Hook Secret from within a hook, use `context.webtask.secrets.SECRET_NAME`. - ```js lines @@ -206,11 +172,6 @@ module.exports = function(client, scope, audience, context, cb) { }; ``` - - - - - ### Response When we run this Hook, the response object is: @@ -221,11 +182,6 @@ When we run this Hook, the response object is: } ``` - - - - - ## Sample script: Raise an error or deny an access token In this example, we use custom Error objects to generate OAuth2 Error Responses. (To learn more, see [OAuth2 RFC - Section 5.2 in the IETF Datatracker](https://tools.ietf.org/html/rfc6749#section-5.2).) @@ -239,11 +195,6 @@ module.exports = function(client, scope, audience, context, cb) { }; ``` - - - - - Then when you request a `client_credentials` grant from the `/oauth/token` endpoint, Auth0 will respond with: ```json lines @@ -251,11 +202,6 @@ HTTP 500 { "error": "server_error", "error_description": "Unknown error occurred." } ``` - - - - - However, if you like additional control over the OAuth2 Error Response, three custom Error objects are available to use instead. ### InvalidScopeError @@ -270,11 +216,6 @@ module.exports = function(client, scope, audience, context, cb) { }; ``` - - - - - Then when you request a `client_credentials` grant is from the `/oauth/token` endpoint, Auth0 responds with: ```json lines @@ -299,11 +240,6 @@ module.exports = function(client, scope, audience, context, cb) { }; ``` - - - - - Then when you request a `client_credentials` grant from the `/oauth/token` endpoint, Auth0 will respond with: ```json lines @@ -311,11 +247,6 @@ HTTP 400 { "error": "invalid_request", "error_description": "Bad request." } ``` - - - - - ### ServerError ```js lines @@ -328,11 +259,6 @@ module.exports = function(client, scope, audience, context, cb) { }; ``` - - - - - Then when you request a `client_credentials` grant from the `/oauth/token` endpoint, Auth0 responds with: ```json lines @@ -340,15 +266,6 @@ HTTP 400 { "error": "server_error", "error_description": "Error calling remote system: ..." } ``` - - - - - - Currently, the behavior of the built-in JavaScript `Error` class and `ServerError` is identical, but the `ServerError` class allows you to be explicit about the OAuth2 error that will be returned. - - -## Learn more diff --git a/main/docs/get-started/authentication-and-authorization-flow/client-credentials-flow.mdx b/main/docs/get-started/authentication-and-authorization-flow/client-credentials-flow.mdx index 58aaf88142..5de539fd3e 100644 --- a/main/docs/get-started/authentication-and-authorization-flow/client-credentials-flow.mdx +++ b/main/docs/get-started/authentication-and-authorization-flow/client-credentials-flow.mdx @@ -1,8 +1,8 @@ --- -description: Learn how the Client Credentials flow works and why you should use it for machine-to-machine (M2M) applications. -sidebarTitle: Overview title: Client Credentials Flow +description: Learn how the Client Credentials flow works and why you should use it for machine-to-machine (M2M) applications. --- + The Client Credentials Flow (defined in [OAuth 2.0 RFC 6749, section 4.4](https://tools.ietf.org/html/rfc6749#section-4.4)) involves an application exchanging its application credentials, such as client ID and client secret, for an access token. This flow is best suited for Machine-to-Machine (M2M) applications, such as CLIs, daemons, or backend services, because the system must authenticate and authorize the application instead of a user. @@ -25,8 +25,6 @@ Alternatively, you can use the Auth0 Authentication API to implement the Client ## Learn more -* [Auth0 Rules](/docs/customize/rules) -* [Auth0 Hooks](/docs/customize/hooks) * [Tokens](/docs/secure/tokens) * [Token Best Practices](/docs/secure/tokens/token-best-practices) * [Which OAuth 2.0 Flow Should I Use?](/docs/get-started/authentication-and-authorization-flow/which-oauth-2-0-flow-should-i-use) diff --git a/main/docs/get-started/authentication-and-authorization-flow/client-initiated-backchannel-authentication-flow.mdx b/main/docs/get-started/authentication-and-authorization-flow/client-initiated-backchannel-authentication-flow.mdx index 04cd366799..4d7953ce90 100644 --- a/main/docs/get-started/authentication-and-authorization-flow/client-initiated-backchannel-authentication-flow.mdx +++ b/main/docs/get-started/authentication-and-authorization-flow/client-initiated-backchannel-authentication-flow.mdx @@ -1,6 +1,5 @@ --- description: Learn how the Client-Initiated Backchannel Authentication Flow works. -sidebarTitle: Overview title: Client-Initiated Backchannel Authentication Flow --- @@ -54,18 +53,11 @@ The following diagram describes the end-to-end CIBA flow: Because the CIBA flow is used for one-time asynchronous user authentication and authorization, CIBA does not create or store a grant containing the user’s consent for an application to access an API’s resources. If the user later authenticates using a different authentication flow, and that flow requests the same scopes the user previously consented to using CIBA, Auth0 will not have a record of that consent. Therefore, it will prompt the user to consent again.
+You can read [Configure Client-Initiated Backchannel Authentication](/docs/get-started/applications/configure-client-initiated-backchannel-authentication) to learn how to configure the CIBA grant type and notification channel for your application. + ## Entity Limits The CIBA flow has the following limits: - Up to 500 CIBA requests may be created per minute per tenant. - Up to 5000 pending CIBA requests per tenant at any one time. A pending CIBA request is a request that has been initiated but has not yet received a response from the user. If a CIBA request expires without receiving a response, it may continue to count towards the 5000 limit for up to 24 hours. - -## Get started - -| Read... | To Learn... | -| --- | --- | -| [Configure Client-Initiated Backchannel Authentication](/docs/get-started/applications/configure-client-initiated-backchannel-authentication) | How to configure the CIBA grant type and notification channel for your application. | -| [Mobile push notifications with CIBA](/docs/get-started/authentication-and-authorization-flow/client-initiated-backchannel-authentication-flow/mobile-push-notifications-with-ciba) | How to authenticate users using the CIBA flow with mobile push notifications. | -| [Email notifications with CIBA](/docs/get-started/authentication-and-authorization-flow/client-initiated-backchannel-authentication-flow/email-notifications-with-ciba) | How to authenticate users using the CIBA flow with email notifications. | -| [User Authorization with CIBA](/docs/get-started/authentication-and-authorization-flow/client-initiated-backchannel-authentication-flow/user-authorization-with-ciba) | How to authorize users using the CIBA with Rich Authorization Requests (RAR) flow. | diff --git a/main/docs/get-started/authentication-and-authorization-flow/device-authorization-flow.mdx b/main/docs/get-started/authentication-and-authorization-flow/device-authorization-flow.mdx index b2f669aa5c..b2f391648d 100644 --- a/main/docs/get-started/authentication-and-authorization-flow/device-authorization-flow.mdx +++ b/main/docs/get-started/authentication-and-authorization-flow/device-authorization-flow.mdx @@ -1,8 +1,8 @@ --- -description: Learn how the Device Authorization flow works and why you should use it for input-constrained devices, such as smart TVs and media consoles. For use with native apps. -sidebarTitle: Overview title: Device Authorization Flow +description: Learn how the Device Authorization flow works and why you should use it for input-constrained devices, such as smart TVs and media consoles. For use with native apps. --- + With input-constrained devices that connect to the internet, rather than authenticate the user directly, the device asks the user to go to a link on their computer or smartphone and authorize the device. This avoids a poor user experience for devices that do not have an easy way to enter text. To do this, device apps use the Device Authorization Flow (ratified in [OAuth 2.0](https://tools.ietf.org/html/rfc8628)), in which they pass along their Client ID to initiate the authorization process and get a token. ## How it works diff --git a/main/docs/get-started/authentication-and-authorization-flow/hybrid-flow.mdx b/main/docs/get-started/authentication-and-authorization-flow/hybrid-flow.mdx index 15d6d46083..839151a63e 100644 --- a/main/docs/get-started/authentication-and-authorization-flow/hybrid-flow.mdx +++ b/main/docs/get-started/authentication-and-authorization-flow/hybrid-flow.mdx @@ -1,8 +1,8 @@ --- -description: Learn how the Hybrid Flow works to provide optimum access to the ID Token while still leveraging the Authorization Code Flow for the secure and safe retrieval of Access and Refresh Tokens. -sidebarTitle: Overview title: Hybrid Flow +description: Learn how the Hybrid Flow works to provide optimum access to the ID Token while still leveraging the Authorization Code Flow for the secure and safe retrieval of Access and Refresh Tokens. --- + Applications that are able to securely store [Client Credentials](/docs/secure/application-credentials) may benefit from the use of the Hybrid Flow (defined in the [OpenID Connect specification, section 3.3](https://openid.net/specs/openid-connect-core-1_0.html#HybridFlowAuth)). The Hybrid flow allows your application to have immediate access to an ID token while ensuring secure and safe retrieval of access tokens and refresh tokens. This can be useful in situations where your application needs to immediately access information about the user, but must perform some processing before gaining access to protected resources for an extended period of time. ## How it works @@ -21,9 +21,7 @@ The Hybrid Flow combines steps from the [Implicit Flow with Form Post](/docs/get 10. API responds with requested data. - If your application only needs to use Hybrid Flow for sign-on, you will not need a Refresh Token or an Access Token, only an ID Token with claims. - ## How to implement it @@ -32,8 +30,6 @@ You can follow our tutorial to use the Authentication API to [Call Your API Usin ## Learn more -* [Auth0 Rules](/docs/customize/rules) -* [Auth0 Hooks](/docs/customize/hooks) * [Tokens](/docs/secure/tokens) * [Token Best Practices](/docs/secure/tokens/token-best-practices) * [Which OAuth 2.0 Flow Should I Use?](/docs/get-started/authentication-and-authorization-flow/which-oauth-2-0-flow-should-i-use) diff --git a/main/docs/get-started/authentication-and-authorization-flow/implicit-flow-with-form-post.mdx b/main/docs/get-started/authentication-and-authorization-flow/implicit-flow-with-form-post.mdx index 289f4d2efa..f0e502e3f2 100644 --- a/main/docs/get-started/authentication-and-authorization-flow/implicit-flow-with-form-post.mdx +++ b/main/docs/get-started/authentication-and-authorization-flow/implicit-flow-with-form-post.mdx @@ -1,12 +1,10 @@ --- -description: Learn how the Implicit flow with Form Post works and why you should use it for traditional web apps that need only an ID Token to perform user authentication. -sidebarTitle: Overview title: Implicit Flow with Form Post +description: Learn how the Implicit flow with Form Post works and why you should use it for traditional web apps that need only an ID Token to perform user authentication. --- - + Don't let the term "implicit" mislead you! Although OAuth now discourages the use of the implicit grant for obtaining access tokens in SPAs, the scenario addressed by Implicit Flow with Form Post is completely different and is **unaffected by the security issues** that led to discouraging use with SPAs. Specifically, Implicit Flow with Form Post applies to traditional web apps as opposed to SPAs. You obtain ID tokens as opposed to access tokens, which have a completely different intended use. The flow uses POST as opposed to placing tokens in URL fragments (as with SPAs) which can expose token bits to browser history attacks, redirect headers, and so on. - You can use OpenID Connect (OIDC) with many different flows to achieve web sign-in for a traditional web app. In one common flow, you obtain an ID token using authorization code flow performed by the app backend. This method is effective and robust, however, it requires your web app to obtain and manage a secret. You can avoid that burden if all you want to do is implement sign-in and you don’t need to obtain access tokens for invoking APIs. @@ -16,9 +14,7 @@ Implicit Flow with Form Post flow uses OIDC to implement web sign-in that is ver ## How it works - You should use this flow for login-only use cases; if you need to request Access Tokens while logging the user in so you can call an API, use the [Authorization Code Flow with PKCE](/docs/get-started/authentication-and-authorization-flow/authorization-code-flow-with-pkce) or the [Hybrid Flow](/docs/get-started/authentication-and-authorization-flow/hybrid-flow). - ![Flows - Implicit with Form Post - Authorization sequence diagram](/docs/images/cdy7uua7fh8z/6m0uE4E7Hpzbdhyh9dEuYK/e36c910ff47a7540bf27e23c02822624/auth-sequence-implicit-form-post.png) @@ -34,17 +30,13 @@ You should use this flow for login-only use cases; if you need to request Access You can [use our Express OpenID Connect SDK](https://www.npmjs.com/package/express-openid-connect) to securely implement the Implicit Flow with Form Post. - The [Auth0 Single-Page App SDK](/docs/libraries/auth0-single-page-app-sdk) and [Single-Page Quickstarts](/docs/quickstart/spa) adhere to the new recommendations and use the [Authorization Code Flow with PKCE](/docs/get-started/authentication-and-authorization-flow/authorization-code-flow-with-pkce). - Finally, you can follow our tutorials to use our API endpoints to [Add Login Using the Implicit Flow with Form Post](/docs/get-started/authentication-and-authorization-flow/implicit-flow-with-form-post/add-login-using-the-implicit-flow-with-form-post). ## Learn more -* [Auth0 Rules](/docs/customize/rules) -* [Auth0 Hooks](/docs/customize/hooks) * [Tokens](/docs/secure/tokens) * [Token Best Practices](/docs/secure/tokens/token-best-practices) * [Which OAuth 2.0 Flow Should I Use?](/docs/get-started/authentication-and-authorization-flow/which-oauth-2-0-flow-should-i-use) diff --git a/main/docs/get-started/authentication-and-authorization-flow/resource-owner-password-flow.mdx b/main/docs/get-started/authentication-and-authorization-flow/resource-owner-password-flow.mdx index 34847f1d6d..a3776c5158 100644 --- a/main/docs/get-started/authentication-and-authorization-flow/resource-owner-password-flow.mdx +++ b/main/docs/get-started/authentication-and-authorization-flow/resource-owner-password-flow.mdx @@ -1,12 +1,10 @@ --- -description: Learn how the Resource Owner Password flow works and why you should use it for highly-trusted applications. -sidebarTitle: Overview title: Resource Owner Password Flow +description: Learn how the Resource Owner Password flow works and why you should use it for highly-trusted applications. --- - + Because the Resource Owner Password (ROP) Flow involves the application handling the user's password, it must not be used by third-party clients. - Though we do not recommend it, highly-trusted applications can use the Resource Owner Password Flow (defined in [OAuth 2.0 RFC 6749, section 4.3](https://tools.ietf.org/html/rfc6749#section-4.3) and sometimes called Resource Owner Password Grant or ROPG), which requests that users provide credentials (username/email/phone and password), typically using an interactive form. Because credentials are sent to the backend and can be stored for future use before being exchanged for an Access Token, it is imperative that the application is absolutely trusted with this information. @@ -50,8 +48,6 @@ When using the Resource Owner Password Flow with -Remember that `subject_tokens` used with Custom Token Exchange can be any token format or type, as long as your Action code can interpret them. -Each `subject_token_type` maps to a Custom Token Exchange Profile and is associated with an Action that will be executed to control that transaction. -
- -| Parameter | Description | -| --- | --- | -| `grant_type` | For Custom Token Exchange, use `urn:ietf:params:oauth:grant-type:token-exchange`. | -| `subject_token_type` | The type of the subject token. For Custom Token Exchange, this can be any URI scoped under your own ownership, such as `http://acme.com/legacy-token` or `urn:acme:legacy-token`.

The following namespaces are reserved and cannot be used: | -| `subject_token` | The subject token, which your action should validate and use to identify the user. | -| `client_id` | The client ID of the application you are using for the Token Exchange. As for other grant types, you can also pass the client ID in the Authorization header using HTTP Basic Auth. | -| `client_secret` | The client secret of the application you are using for the Token Exchange. As for other grant types, you can also pass the client secret in the Authorization header using HTTP Basic Auth.

Other alternatives are also available as explained in [Auth0 Authentication API reference docs](https://auth0.com/docs/api/authentication#authentication-methods).

Note Custom Token Exchange can be used by public Applications. Make sure to read [Attack Protection](#attack-protection) in that case. | -| `audience` | The API identifier defined in Auth0. The default tenant audience will be used when not present, as configured in [Tenant Settings](/docs/get-started/tenant-settings). | -| `scope` | (Optional) The OAuth2 scope parameter. | -| `organization` | (Optional) The organization identifier you want the request to be associated with. Alternatively, you can specify an organization name if [Use Organization Names in Authentication API](/docs/manage-users/organizations/configure-organizations/use-org-name-authentication-api) is allowed for your tenant. To learn more about how the request is processed, read about the [api.authentication.setOrganization() API method](/docs/customize/actions/explore-triggers/signup-and-login-triggers/custom-token-exchange-trigger/custom-token-exchange-api-object#api-authentication-setorganization-organization). | - -Other extension parameters are ignored, although they are included in the `event.request.body` in the corresponding Action. - -## Sample request - -```bash lines -curl --location 'https://{yourDomain}/oauth/token' \ ---header 'Content-Type: application/x-www-form-urlencoded' \ ---data-urlencode 'grant_type=urn:ietf:params:oauth:grant-type:token-exchange' \ ---data-urlencode 'audience=https://api.acme.com' \ ---data-urlencode 'scopes=openid offline_access acme-scope1 acme-scope2' \ ---data-urlencode 'subject_token_type=urn:acme:external-idp-migration' \ ---data-urlencode 'subject_token=t8e7S2D9trQm73e .... iqBR3GjxDtbDVjpfQU' \ ---data-urlencode 'client_id=' \ ---data-urlencode 'client_secret=' ---data-urlencode 'organization=periscope-acme' -``` diff --git a/main/docs/get-started/authentication-and-authorization-flow/which-oauth-2-0-flow-should-i-use.mdx b/main/docs/get-started/authentication-and-authorization-flow/which-oauth-2-0-flow-should-i-use.mdx index 89027834ab..7c56c68060 100644 --- a/main/docs/get-started/authentication-and-authorization-flow/which-oauth-2-0-flow-should-i-use.mdx +++ b/main/docs/get-started/authentication-and-authorization-flow/which-oauth-2-0-flow-should-i-use.mdx @@ -1,7 +1,8 @@ --- -description: Learn how to identify the proper OAuth 2.0 flow for your use case. title: Which OAuth 2.0 Flow Should I Use? +description: Learn how to identify the proper OAuth 2.0 flow for your use case. --- + The [OAuth 2.0 Authorization Framework](/docs/authenticate/protocols/oauth) supports several different flows (or grants). Flow are ways of retrieving an Access Token. Deciding which one is suited for your use case depends mostly on your [application type](/docs/get-started/applications), but other parameters weigh in as well, like the level of trust for the client, or the experience you want your users to have. ## OAuth 2.0 terminology @@ -58,9 +59,7 @@ Sure! You can use our [Authentication API Debugger Extension](/docs/customize/ex ## Does the Client Application need to challenge users for authentication without browser interaction? - Client-Initiated Backchannel Authentication is currently in Early Access. To enable CIBA, contact your Technical Account Manager. - Client-Initiated Backchannel Authentication (CIBA) is an OpenID Foundation standard for implementing an alternative authentication flow to [OpenID Connect](https://openid.net/developers/how-connect-works/). CIBA differs from the standard OpenID Connect flow in that: diff --git a/main/docs/get-started/dashboard-profile.mdx b/main/docs/get-started/dashboard-profile.mdx deleted file mode 100644 index 6dcc9ff849..0000000000 --- a/main/docs/get-started/dashboard-profile.mdx +++ /dev/null @@ -1,11 +0,0 @@ ---- -description: Explore options in Auth0 Dashboard's Profile menu. -sidebarTitle: Overview -title: Dashboard Profile ---- -Explore options in Auth0 Dashboard's profile option. - -| Read... | To learn... | -| --- | --- | -| [Light and Dark themes](/docs/get-started/dashboard-profile/light-and-dark-themes) | How to choose your preferred theme. | -| [Auth0 Dashboard Login Session Management](/docs/get-started/dashboard-profile/auth0-dashboard-login-session-management) | How to manage Auth0 Dashboard sessions. | \ No newline at end of file diff --git a/main/docs/get-started/dashboard-profile/light-and-dark-themes.mdx b/main/docs/get-started/dashboard-profile/light-and-dark-themes.mdx deleted file mode 100644 index 2ddfb5df8e..0000000000 --- a/main/docs/get-started/dashboard-profile/light-and-dark-themes.mdx +++ /dev/null @@ -1,16 +0,0 @@ ---- -description: How to toggle between light and dark themes for your Dashboard -title: Light and Dark themes ---- -Auth0 customers can use light mode or dark mode in their tenant Dashboard. You can also set your Dashboard to use the same settings as your local system environment. - -There are two ways to change your Dashboard theme: - -1. Select the profile dropdown menu at the top-right of your Dashboard. -2. Use the menu to switch between themes. - -![Where to find the Dark mode and Light mode toggle](/docs/images/cdy7uua7fh8z/1BImxFvHXoULQVTkqCsQL0/a37f6cfdfce935fd20731aa68f8067de/2024-09-10_09-08-27.png) - -You may also click **Your Profile** in the same dropdown and scroll to the bottom, where you can choose from the three themes. - -![Where you can change your theme in the Profile section](/docs/images/cdy7uua7fh8z/231W9kPYTeEABOsV3rOZxF/1c451d4942d86432a0e701f497c32f24/Light_mode_profile_section.png) \ No newline at end of file diff --git a/main/docs/get-started/identity-fundamentals.mdx b/main/docs/get-started/identity-fundamentals.mdx deleted file mode 100644 index a370fbb7bd..0000000000 --- a/main/docs/get-started/identity-fundamentals.mdx +++ /dev/null @@ -1,12 +0,0 @@ ---- -description: Learn the basics of identity and access management. -sidebarTitle: Overview -title: Identity Fundamentals ---- -Explore topics related to the fundamentals of identity and access management. - -| Read... | To learn... | -| --- | --- | -| [Introduction to Identity and Access Management (IAM)](/docs/get-started/identity-fundamentals/identity-and-access-management) | Basic concepts of IAM. | -| [Authentication vs. Authorization](/docs/get-started/identity-fundamentals/authentication-and-authorization) | About the differences between authentication and authorization. | -| [Glossary](/docs/glossary) | Definitions of various terms related to identity. | \ No newline at end of file diff --git a/main/docs/get-started/identity-fundamentals/introduction-to-auth0.mdx b/main/docs/get-started/identity-fundamentals/introduction-to-auth0.mdx index 6b38dab7e8..20f999d455 100644 --- a/main/docs/get-started/identity-fundamentals/introduction-to-auth0.mdx +++ b/main/docs/get-started/identity-fundamentals/introduction-to-auth0.mdx @@ -2,8 +2,26 @@ description: Describes Auth0 services and features. title: Introduction to Auth0 --- + Auth0 is an identity access management (IAM) provider. But what does this mean? If you've read [Introduction to Identity and Access Management (IAM)](/docs/get-started/identity-fundamentals/identity-and-access-management), you know an IAM solution is a gatekeeper to the resources you provide to customers as web applications, APIs, etc. The gatekeeper initiates authorization as outlined in OAuth 2.0. The addition of the OpenID Connect layer adds authentication to secure your users’ digital identities and your product. + +* You built a app and you want to add user authentication and authorization. Your users should be able to log in either with an identifier (username, email, or phone number) and password or with their social accounts (such as Facebook or X). You want to retrieve the user's profile after the login so you can customize the UI and apply your authorization policies. +* You built an API and you want to secure it with [OAuth 2.0](/docs/authenticate/protocols/oauth). +* You have more than one app, and you want to implement [Single Sign-on (SSO)](/docs/authenticate/single-sign-on). +* You built a JavaScript front-end app and a mobile app, and you want them both to securely access your API. +* You have a web app that needs to authenticate users using [Security Assertion Markup Language (SAML)](/docs/authenticate/protocols/saml/saml-configuration). +* You believe passwords are broken and you want your users to log in with one-time codes delivered by email or SMS. +* If one of your user's email addresses is compromised in some site's public data breach, you want to be notified, and you want to notify the users and/or block them from logging in to your app until they reset their password. +* You want to act proactively to block suspicious IP addresses if they make consecutive failed login attempts, in order to avoid DDoS attacks. +* You are part of a large organization that wants to federate your existing enterprise directory service to allow employees to log in to the various internal and third-party applications using their existing enterprise credentials. +* You don't want (or you don't know how) to implement your own user management solution. Password resets, creating, provisioning, blocking, and deleting users, and the UI to manage all these. You just want to focus on your app. +* You want to enforce [multi-factor authentication (MFA)](/docs/secure/multi-factor-authentication) when your users want to access sensitive data. +* You are looking for an identity solution that will help you stay on top of the constantly growing compliance requirements of SOC2, GDPR, PCI DSS, HIPAA, and others. +* You want to monitor users on your site or application. You plan on using this data to create funnels, measure user retention, and improve your sign-up flow. +* You want robust authorization policy to allow your users access to resources based on [their relationship](https://docs.fga.dev/authorization-concepts) to the resource or [their role](/docs/manage-users/access-control/rbac) in your organization. + + The Auth0 identity platform supports different application types and frameworks. Whether your application is a regular web app, a mobile app, or a machine-to-machine app, Auth0 provides configurations for the most secure authorization grant, or workflow, for each. You can read more about authorization grants and choose the one for your application in our article [Which OAuth 2.0 Flow Should I Use?](/docs/get-started/authentication-and-authorization-flow/which-oauth-2-0-flow-should-i-use) Aside from supporting secure protocols, the Auth0 identity platform allows you to customize login services to fit your business, your technology, and your customer base. Using the Auth0 Dashboard and Management API, you can create your own Auth0 instance to authenticate and authorize your customers. You can configure login behaviors, connect your user data store, manage those users, choose an authorization grant, and establish authentication factors for a seamless, scalable product with an impactful user experience. @@ -91,4 +109,4 @@ When you’ve finished testing your Auth0 instance and are ready to deploy, you To keep your deployment on track, we provide guidance in the form of pre-deployment recommendations, a deployment checklist, best practices, common fixes, and other tips to help make deployment as seamless as possible. -Once you’ve established your production environment ready for users, you can be on the lookout with error tracking and alerts. The System Center Operations Manager allows you to monitor, while event logs can be exported to an analytical tool and allow you insight on trends, user behavior, or issues. \ No newline at end of file +Once you’ve established your production environment ready for users, you can be on the lookout with error tracking and alerts. The System Center Operations Manager allows you to monitor, while event logs can be exported to an analytical tool and allow you insight on trends, user behavior, or issues. diff --git a/main/docs/get-started/manage-dashboard-access.mdx b/main/docs/get-started/manage-dashboard-access.mdx index 64a385117f..722a2e9b06 100644 --- a/main/docs/get-started/manage-dashboard-access.mdx +++ b/main/docs/get-started/manage-dashboard-access.mdx @@ -1,25 +1,13 @@ --- -description: Describes how to manage your team members to have access permissions on your Auth0 Dashboard. -sidebarTitle: Overview -title: Manage Dashboard Access +title: Tenant Membership +description: Manage tenant membership to control access to your tenant and its resources. --- -As an Auth0 tenant administrator, you are responsible for all activities that occur under your Auth0 account and tenants including managing your tenant members. You can add, change, and remove tenant members (dashboard users) in the Auth0 Dashboard or from the [Auth0 Teams Dashboard](/docs/get-started/auth0-teams/tenant-member-management). Auth0 recommends that you periodically review the list of Auth0 Dashboard tenant members with access to your Auth0 tenant and make sure that: -* Each person has a legitimate need for tenant member access. -* Members are registered with a company account. -* Former employees no longer have access. -* There's more than one Dashboard admin. +Tenant administrators can share access to the tenant and its resources by adding additional tenant members. -| Read... | To learn... | -| --- | --- | -| [Dashboard Access by Role](/docs/get-started/manage-dashboard-access/feature-access-by-role) | About tenant member roles and Auth0 Dashboard feature access. | -| [Add Tenant Members](/docs/get-started/manage-dashboard-access/add-dashboard-users) | How to add tenant members to access the Auth0 Dashboard. | -| [Edit Tenant Members](/docs/get-started/manage-dashboard-access/edit-dashboard-users) | How to edit tenant member roles. | -| [Remove Tenant Members](/docs/get-started/manage-dashboard-access/remove-dashboard-users) | How to revoke a tenant member's access to the Auth0 Dashboard. | -| [Add Multi-factor Authentication (MFA) for Auth0 Dashboard Access](/docs/get-started/manage-dashboard-access/add-change-remove-mfa) | How Auth0 Dashboard users can implement multi-factor authentication (MFA). | -| [Update Dashboard User Email Addresses](/docs/get-started/manage-dashboard-access/update-dashboard-user-email) | How to update a tenant member's email address. | +Every tenant member has a [tenant membership role](./feature-access-by-role) that defines their permissions on the tenant. Different roles provide different levels of access to tenant resources (like applications, connections, or users). -Here are some examples of users who may have special access requirements: +Roles allow tenant administrators limit each member's access to only what they need, following [the principle of least privilege](https://en.wikipedia.org/wiki/Principle_of_least_privilege). For example, the following types of users need different permissions: * Support specialists who need to troubleshoot login issues for your app end users. * Support/IT specialists who need to assign roles and permissions to end users. @@ -27,3 +15,5 @@ Here are some examples of users who may have special access requirements: * Product managers who need to analyze their applications' configuration and usage. * Developers who need to configure settings for their own applications. * Support/IT specialists that need to create connections for their customers in a B2B use case. + +Tenant administrators can manange tenant membership using the Auth0 Dashboard or from the [Auth0 Teams Dashboard](/docs/get-started/auth0-teams/tenant-member-management). diff --git a/main/docs/get-started/manage-dashboard-access/add-change-remove-mfa.mdx b/main/docs/get-started/manage-dashboard-access/add-change-remove-mfa.mdx index 191d043b78..b8a9a4cd34 100644 --- a/main/docs/get-started/manage-dashboard-access/add-change-remove-mfa.mdx +++ b/main/docs/get-started/manage-dashboard-access/add-change-remove-mfa.mdx @@ -1,7 +1,9 @@ --- -description: Learn how Auth0 Dashboard users can implement multi-factor authentication (MFA). -title: Multi-Factor Authentication for Dashboard Users +title: Multi-Factor Authentication for the Auth0 Dashboard +sidebarTitle: Multi-Factor Authentication +description: Increase security for Dashboard logins by enrolling in multi-factor authentication. --- + Multi-factor authentication (MFA) adds an additional level of security to an Auth0 account. When users with MFA enabled log into the Auth0 Dashboard, Auth0 prompts for their credentials plus an additional piece of identifying information. This ensures that only valid users can access their accounts, even if a bad actor has compromised a username and password. Any Dashboard user can self-enroll in MFA in [Your Profile](https://manage.auth0.com/#/profile). The MFA indicator in the [Auth0 Dashboard > Settings > Tenant Members](https://manage.auth0.com/#/tenant/admins) list identifies whether a user has enabled MFA for their account. @@ -17,13 +19,10 @@ Auth0 supports these authentication factors for Dashboard users: To learn how to enroll in Dashboard MFA, read [Add Multi-Factor Authentication for Auth0 Dashboard Access](/docs/get-started/manage-dashboard-access/add-change-remove-mfa/add-mfa). - Auth0 recommends WebAuthn factors as the most secure and usable authentication methods. To learn more, read [FIDO Authentication with WebAuthn](/docs/secure/multi-factor-authentication/fido-authentication-with-webauthn). - - Admins must enable at least one factor to use MFA. Auth0 highly recommends setting up multiple factors so you can still access your account if you lose your primary device. An ideal setup is to use three factors: @@ -33,7 +32,6 @@ An ideal setup is to use three factors: 3. A recovery code. If you can't provide your MFA token and you don’t have proper backup methods, your account may be irrecoverable. - ## Learn more diff --git a/main/docs/get-started/manage-dashboard-access/add-dashboard-users.mdx b/main/docs/get-started/manage-dashboard-access/add-dashboard-users.mdx index b04b4caf05..ead9b94293 100644 --- a/main/docs/get-started/manage-dashboard-access/add-dashboard-users.mdx +++ b/main/docs/get-started/manage-dashboard-access/add-dashboard-users.mdx @@ -1,55 +1,40 @@ --- -description: Learn how to add tenant members to access the Auth0 Dashboard. -title: Add Tenant Members +title: How to Add Members to a Tenant using the Auth0 Dashboard +sidebarTitle: Add Tenant Members +description: Invite collaborators to become members of your tenant to share access to tenant resources. --- -If you are a tenant administrator, you can add colleagues to the tenant and assign them a specific role to allow them access to the Auth0 Dashboard features they need. - +When you invite new members to your tenant, you assign one or more roles that define their level of access to tenant resources. You can view a list of [all roles and their associated permissions](/docs/get-started/manage-dashboard-access/feature-access-by-role). -If your tenant administrator account authenticates with username and password, you must verify your email address before you can invite other members. +## Prerequisites - +* Your Auth0 account must have the **Admin** role on the tenant. - +* If you authenticate to Auth0 with a username and password, you must verify your email address. + If Teams is provisioned for your enterprise account, manage your tenant members via Auth0 Teams. To learn more, read [Team Member Management](/docs/get-started/auth0-teams/team-member-management). - -When you add new tenant members, you can assign roles that allow them access without putting production applications and sensitive information at risk. You can assign a user more than one role and the permissions will be combined. For further protection, users can turn on [multi-factor authentication](/docs/get-started/manage-dashboard-access/add-change-remove-mfa) (MFA). To learn more about which Dashboard features are accessible with each role, read [Dashboard Access by Role](/docs/get-started/manage-dashboard-access/feature-access-by-role). +## Add tenant members -| Role | Permissions | -| --- | --- | -| **Admin** | Read and write access to all resources in the Auth0 Dashboard, including extensions. | -| **Editor - Connections** | Read, write, and create access to all types of connections. | -| **Editor - Key Management** | Create and manage cryptographic keys. | -| **Editor - Organizations** | Read, write, and create access to Organization configuration. Read-only access to Users, Roles, and Connections. | -| **Editor - Specific Apps** | Read and write access to specific applications only. | -| **Editor - Users** | User management operations (create, delete, block, unblock, reset MFA, reset password, update metadata, assign roles, etc.) and access to logs. | -| **Viewer - Users** | Read-only access to users and user-related logs. | -| **Viewer - Config Settings** | Read-only access to all configuration settings (applications, APIs, rules, security settings, etc.) except for sensitive information such as secrets, billing, users, and logs. | -| **Support Access - Deprecated** | Access to tickets (submit, view, and update) and aggregated metrics. | -| **Elevated Support Access** | Read, write, and create access to **all** support tickets created by **all users** on a tenant (Subscripton Tickets in Auth0 Support Center). Access to aggregated metrics. | +1. Go to [Dashboard > Settings > Tenant Members](https://manage.auth0.com/#/tenant/admins). - +2. Select **Add Member**. -Both your specific login implementation and your Auth0 plan or custom agreement affect whether this feature is available. To learn more, read [Pricing](https://auth0.com/pricing). +3. On the **Add New Tenant Member** screen, enter the user's email address and select their role(s). - +4. Select **Invite**. When you do, Auth0 sends an email to the user containing an invitation link. -1. Go to [Dashboard > Settings > Tenant Members](https://manage.auth0.com/#/tenant/admins). -2. Click **Add Member**. -3. On the **Add New Tenant Member** screen, enter the user's email address and select the roles you would like to assign to them. -4. Click **Invite**. - Auth0 will send an email to the user with a link for them to click to accept the invitation. Before the user accepts the invitation, they will appear in the Invitations list as pending. If you click the `...` you will see **Remove invitation** or **Copy invitation link**. +Before the user accepts the invitation, they appear in the **Invitations** list as pending. In the **...** menu next to the user, there are options to **Remove invitation** and **Copy invitation link**. +If your tenant members cannot see all of their tenants after logging in, check to see if they have multiple Auth0 accounts. This can happen if users create multiple Auth0 accounts in different ways (for example, signing up with a social provider like Google or GitHub, and then signing up again using ane mail address). -Users can create Auth0 accounts in different ways. For example, they can sign up with a social provider (e.g., Google, GitHub), then sign up again using their email address. If your tenant members cannot see all of their tenants after logging in, check to see if they have multiple Auth0 accounts. You can view the signup method used by the Dashboard tenant member by going to [Dashboard > Tenant Settings > Tenant Members](https://manage.auth0.com/#/tenant/admins). - +You can view the signup method used by tenant members by going to [Dashboard > Tenant Settings > Tenant Members](https://manage.auth0.com/#/tenant/admins). -When the invited user clicks the link to accept the invitation, they will be asked to log in with the invited email address. They can then choose whether to log in with a social provider or to log in with their email address and password. If they choose to log in with their email address and password, they must have already created an account with Auth0, or they will need to sign up first and then accept the invitation again. +When the invited user clicks the link to accept the invitation, they are prompted to log in with the invited email address. They can then choose whether to log in with a social provider or with their email address and password. If they choose to log in with their email address and password, they must have already created an account with Auth0, or they will need to sign up first and then accept the invitation again. ## Learn more @@ -58,4 +43,4 @@ When the invited user clicks the link to accept the invitation, they will be ask * [Remove Tenant Members](/docs/get-started/manage-dashboard-access/remove-dashboard-users) * [Troubleshoot Role-Based Access Control and Authorization](/docs/troubleshoot/authentication-issues/troubleshoot-rbac-authorization) * [Troubleshoot Multi-Factor Authentication Issues](/docs/troubleshoot/authentication-issues/troubleshoot-mfa-issues) -* [Troubleshoot Authentication Issues](/docs/troubleshoot/authentication-issues) \ No newline at end of file +* [Troubleshoot Authentication Issues](/docs/troubleshoot/authentication-issues) diff --git a/main/docs/get-started/manage-dashboard-access/configure-single-sign-on-for-auth0-dashboard.mdx b/main/docs/get-started/manage-dashboard-access/configure-single-sign-on-for-auth0-dashboard.mdx index fe1a675bd7..5516448485 100644 --- a/main/docs/get-started/manage-dashboard-access/configure-single-sign-on-for-auth0-dashboard.mdx +++ b/main/docs/get-started/manage-dashboard-access/configure-single-sign-on-for-auth0-dashboard.mdx @@ -1,6 +1,7 @@ --- +title: Single Sign-On (SSO) for the Auth0 Dashboard +sidebarTitle: Single Sign-On (SSO) description: Learn how to configure single sign-on (SSO) for the Auth0 Dashboard. -title: Configure Single Sign-on for Auth0 Dashboard --- @@ -307,4 +308,4 @@ To migrate Tenant members with HRD enabled, you need to follow steps similar to 2. Open the invitation link in the invitation email they received. 3. Log in on the new connection. - 4. Accept the invitation. \ No newline at end of file + 4. Accept the invitation. diff --git a/main/docs/get-started/manage-dashboard-access/edit-dashboard-users.mdx b/main/docs/get-started/manage-dashboard-access/edit-dashboard-users.mdx index a9ef44e620..b85b43785e 100644 --- a/main/docs/get-started/manage-dashboard-access/edit-dashboard-users.mdx +++ b/main/docs/get-started/manage-dashboard-access/edit-dashboard-users.mdx @@ -1,6 +1,6 @@ --- -description: Learn how to edit Auth0 Dashboard user roles for your Auth0 tenant. title: Edit Tenant Members +description: Learn how to edit Auth0 Dashboard user roles for your Auth0 tenant. --- If you are a tenant administrator, you can change a user's assigned role(s). The changes take effect after users refresh their Dashboard. diff --git a/main/docs/get-started/manage-dashboard-access/feature-access-by-role.mdx b/main/docs/get-started/manage-dashboard-access/feature-access-by-role.mdx index 936699971d..f49f68068c 100644 --- a/main/docs/get-started/manage-dashboard-access/feature-access-by-role.mdx +++ b/main/docs/get-started/manage-dashboard-access/feature-access-by-role.mdx @@ -1,22 +1,17 @@ --- -description: Describes each tenant member role and provides details about what Auth0 Dashboard features they have access to. -title: Dashboard Access by Role +title: Available Roles for Tenant Members +description: Describes the roles and associated permissions available for tenant members. --- -As a tenant administrator, you can assign roles to your colleagues that grant them limited access to the Auth0 Dashboard. This allows tenant members to complete their jobs without putting production applications at risk, while also complying with the principle of least privilege. - - -Every role receives access to [Support Center](https://support.auth0.com/). - - - -## Dashboard roles + +Your Auth0 plan or custom agreement affects the availability of this feature. To learn more, read [Auth0's Pricing Page](https://auth0.com/pricing). + -You can assign the following roles for Auth0 Dashboard access: +The following roles are available for tenant members: | Role | Permissions | | --- | --- | -| **Admin** | Read and write access to all resources in the Auth0 Dashboard, including extensions. | +| **Admin** | Read and write access to all resources, including extensions. | | **Editor - Connections** | Read, write, and create access to all types of connections. | | **Editor - Key Management** | Create and manage cryptographic keys. | | **Editor - Organizations** | Read, write, and create access to Organization configuration. Read-only access to Users, Roles, and Connections. | @@ -27,26 +22,19 @@ You can assign the following roles for Auth0 Dashboard access: | **Support Access - Deprecated** | Access to tickets (submit, view, and update) and aggregated metrics. | | **Elevated Support Access** | Read, write, and create access to **all** support tickets created by **all users** on a tenant (Subscripton Tickets in Auth0 Support Center). Access to aggregated metrics. | - - -Your Auth0 plan or custom agreement affects the availability of this feature. To learn more, read [Auth0's Pricing Page](https://auth0.com/pricing). - - - -Limited-access roles restrict a tenant member's Dashboard experience to only the sections and actions necessary for their job. +Every role receives access to [Support Center](https://support.auth0.com/). -The feature permissions associated with each role are outlined below. If a specific permission is not listed for a role, tenant members given that role will not have access to that area of the Auth0 Dashboard. +## Available Dashboard sections by role +Each member can only access the sections of the Dashboard that their role's permissions allow. If a specific permission is not listed for a role, tenant members given that role do not have access to that area of the Dashboard. - + Admin users have read/write access to all areas of the Auth0 Dashboard, including extensions. - - | Dashboard Section | Subsection (if applicable) | Read/Write Access | Read-Only Access | | --- | --- | --- | --- | | Authentication | Database | ✅ | | @@ -57,20 +45,16 @@ Admin users have read/write access to all areas of the Auth0 Dashboard, includin | Get Support | Support Tickets - Create | ✅ | | | | Usage Reports | ✅ | | | | Compliance | ✅ | | - - | Dashboard Section | Subsection (if applicable) | Read/Write Access | Read-Only Access | | --- | --- | --- | --- | | Settings | General | | ✅ | | | Encryption Keys | ✅ | | - - | Dashboard Section | Subsection (if applicable) | Read/Write Access | Read-Only Access | | --- | --- | --- | --- | | Authentication | Database | | ✅ | @@ -88,11 +72,9 @@ Admin users have read/write access to all areas of the Auth0 Dashboard, includin | Get Support | Support Tickets - Create | ✅ | | | | Usage Reports | ✅ | | | | Compliance | ✅ | | - - | Dashboard Section | Subsection (if applicable) | Read/Write Access | Read-Only Access | | --- | --- | --- | --- | | Applications | Applications | ✅ + | | @@ -103,11 +85,9 @@ Admin users have read/write access to all areas of the Auth0 Dashboard, includin | | Compliance | ✅ | | + Update-only access for specific applications. Users cannot create new applications. - - | Dashboard Section | Subsection (if applicable) | Read/Write Access | Read-Only Access | | --- | --- | --- | --- | | Organizations | List | | ✅ | @@ -122,11 +102,9 @@ Admin users have read/write access to all areas of the Auth0 Dashboard, includin | | Compliance | ✅ | | + Access to user events only. - - | Dashboard Section | Subsection (if applicable) | Read/Write Access | Read-Only Access | | --- | --- | --- | --- | | Organizations | List | | ✅ | @@ -140,11 +118,9 @@ Admin users have read/write access to all areas of the Auth0 Dashboard, includin | | Compliance | ✅ | | + Access to user events only. - - | Dashboard Section | Subsection (if applicable) | Read/Write Access | Read-Only Access | | --- | --- | --- | --- | | Applications | Applications | | ✅ + | @@ -175,11 +151,9 @@ Admin users have read/write access to all areas of the Auth0 Dashboard, includin | | Compliance | ✅ | | + Excludes access to secrets. - - | Dashboard Section | Subsection (if applicable) | Read/Write Access | Read-Only Access | | --- | --- | --- | --- | | Activity | Stats | ✅ + | | @@ -189,16 +163,15 @@ Admin users have read/write access to all areas of the Auth0 Dashboard, includin | | Compliance | ✅ | | + Access to metrics only. - -## Log events available to user roles +## Access to different log types -Logs can contain sensitive data, such as secrets, PII, etc. It is important not to disclose sensitive data to users whose role does not require that information. However, the **Editor - Users** or **Viewer - Users** roles need to have some access to logs to identity user issues. For example, finding out if the user signed up correctly, if the user was blocked, etc. +Logs can contain sensitive data, such as secrets and PII, which should not be available to users whose role does not require that information. The **Editor - Users** and **Viewer - Users** roles need some access to logs to identity user issues (for example, to find out if a user signed up correctly or was blocked). -We allow the **Editor - Users** and **Viewer - Users** with access to a limited set of log types, that are connected to user events. The log events in the list provide the necessary information about user actions but do not disclose sensitive information about other parts of the tenant configuration. To learn more, read [Log Event Type Codes](/docs/deploy-monitor/logs/log-event-type-codes). +We allow the **Editor - Users** and **Viewer - Users** with access to the following limited set of log types that are connected to user events. These log events provide necessary information about user actions but do not disclose sensitive information about other parts of the tenant configuration. ```text lines expandable cls @@ -283,25 +256,14 @@ ublkdu w ``` - - - - +To learn more, read [Log Event Type Codes](/docs/deploy-monitor/logs/log-event-type-codes). ## Limitations -* Users with **Admin** role can invite **Editor - Specific Apps** users to one application at a time. To work around this, the **Admin** user can [edit their role](/docs/get-started/manage-dashboard-access/edit-dashboard-users) to assign multiple applications after the user accepts the invitation. +* Users with the **Admin** role can invite **Editor - Specific Apps** users to one application at a time. To work around this, the **Admin** user can [edit their role](/docs/get-started/manage-dashboard-access/edit-dashboard-users) to assign multiple applications after the user accepts the invitation. * The **Viewer - Users** and **Editor - Users** roles don't have access to the Users' **Devices** and **Authorized Apps** sections. * The [New Activity Page](/docs/get-started/auth0-overview/dashboard/activity) is visible to **Admins** and **Elevated Support Access** users only. **Editor - Users** and **Viewer - Users** can access daily activity (such as logins or signups) through the [Auth0 Management API](https://auth0.com/docs/api/management/v2#!/Stats/get_daily). ## Private Cloud requirements The **Editor - Users** and the **Viewer - Users** roles require that User Search v3 and Logs Search v3 are enabled in your environment. If your environments don’t support these versions, these two roles are unavailable. - -## Learn more - -* [Add Tenant Members](/docs/get-started/manage-dashboard-access/add-dashboard-users) -* [Edit Tenant Members](/docs/get-started/manage-dashboard-access/edit-dashboard-users) -* [Remove Tenant Members](/docs/get-started/manage-dashboard-access/remove-dashboard-users) -* [Troubleshoot Role-Based Access Control and Authorization](/docs/troubleshoot/authentication-issues/troubleshoot-rbac-authorization) -* [Check Error Messages](/docs/troubleshoot/basic-issues/check-error-messages) diff --git a/main/docs/get-started/manage-dashboard-access/remove-dashboard-users.mdx b/main/docs/get-started/manage-dashboard-access/remove-dashboard-users.mdx index 59832e9b4f..ff33ad5b9f 100644 --- a/main/docs/get-started/manage-dashboard-access/remove-dashboard-users.mdx +++ b/main/docs/get-started/manage-dashboard-access/remove-dashboard-users.mdx @@ -1,6 +1,6 @@ --- -description: Learn how to remove tenant members from access to the Auth0 Dashboard for your Auth0 tenant. title: Remove Tenant Members +description: Learn how to remove tenant members from access to the Auth0 Dashboard for your Auth0 tenant. --- If you are a tenant administrator, you can revoke access to the Dashboard. diff --git a/main/docs/get-started/manage-dashboard-access/support-center-users.mdx b/main/docs/get-started/manage-dashboard-access/support-center-users.mdx deleted file mode 100644 index 364d6a5059..0000000000 --- a/main/docs/get-started/manage-dashboard-access/support-center-users.mdx +++ /dev/null @@ -1,307 +0,0 @@ ---- -description: Describes each tenant member role and provides details about what Auth0 Dashboard features they have access to. -title: Dashboard Access by Role ---- -As a tenant administrator, you can assign roles to your colleagues that grant them limited access to the Auth0 Dashboard. This allows tenant members to complete their jobs without putting production applications at risk, while also complying with the principle of least privilege. - - - -Every role receives access to [Support Center](https://support.auth0.com/). - - - -## Dashboard roles - -You can assign the following roles for Auth0 Dashboard access: - -| Role | Permissions | -| --- | --- | -| **Admin** | Read and write access to all resources in the Auth0 Dashboard, including extensions. | -| **Editor - Connections** | Read, write, and create access to all types of connections. | -| **Editor - Key Management** | Create and manage cryptographic keys. | -| **Editor - Organizations** | Read, write, and create access to Organization configuration. Read-only access to Users, Roles, and Connections. | -| **Editor - Specific Apps** | Read and write access to specific applications only. | -| **Editor - Users** | User management operations (create, delete, block, unblock, reset MFA, reset password, update metadata, assign roles, etc.) and access to logs. | -| **Viewer - Users** | Read-only access to users and user-related logs. | -| **Viewer - Config Settings** | Read-only access to all configuration settings (applications, APIs, rules, security settings, etc.) except for sensitive information such as secrets, billing, users, and logs. | -| **Support Access - Deprecated** | Access to tickets (submit, view, and update) and aggregated metrics. | -| **Elevated Support Access** | Read, write, and create access to **all** support tickets created by **all users** on a tenant (Subscripton Tickets in Auth0 Support Center). Access to aggregated metrics. | - - - -Your Auth0 plan or custom agreement affects the availability of this feature. To learn more, read [Auth0's Pricing Page](https://auth0.com/pricing). - - - -Limited-access roles restrict a tenant member's Dashboard experience to only the sections and actions necessary for their job. - -The feature permissions associated with each role are outlined below. If a specific permission is not listed for a role, tenant members given that role will not have access to that area of the Auth0 Dashboard. - - - - - -Admin users have read/write access to all areas of the Auth0 Dashboard, including extensions. - - - - - -| Dashboard Section | Subsection (if applicable) | Read/Write Access | Read-Only Access | -| --- | --- | --- | --- | -| Authentication | Database | ✅ | | -| | Social | ✅ | | -| | Enterprise | ✅ | | -| | Passwordless | ✅ | | -| Marketplace | | | ✅ | -| Get Support | Support Tickets - Create | ✅ | | -| | Usage Reports | ✅ | | -| | Compliance | ✅ | | - - - - - -| Dashboard Section | Subsection (if applicable) | Read/Write Access | Read-Only Access | -| --- | --- | --- | --- | -| Settings | General | | ✅ | -| | Encryption Keys | ✅ | | - - - - - -| Dashboard Section | Subsection (if applicable) | Read/Write Access | Read-Only Access | -| --- | --- | --- | --- | -| Authentication | Database | | ✅ | -| | Social | | ✅ | -| | Enterprise | | ✅ | -| | Passwordless | | ✅ | -| Organizations | List | ✅ | | -| | Overview | ✅ | | -| | Members | ✅ | | -| | Invitations | ✅ | | -| | Connections | ✅ | | -| User Management | Users | | ✅ | -| | Roles | | ✅ | -| Marketplace | | | ✅ | -| Get Support | Support Tickets - Create | ✅ | | -| | Usage Reports | ✅ | | -| | Compliance | ✅ | | - - - - - -| Dashboard Section | Subsection (if applicable) | Read/Write Access | Read-Only Access | -| --- | --- | --- | --- | -| Applications | Applications | ✅ + | | -| | SSO Integrations | ✅ + | | -| Marketplace | | | ✅ | -| Get Support | Support Tickets - Create | ✅ | | -| | Usage Reports | ✅ | | -| | Compliance | ✅ | | - -+ Update-only access for specific applications. Users cannot create new applications. - - - - - -| Dashboard Section | Subsection (if applicable) | Read/Write Access | Read-Only Access | -| --- | --- | --- | --- | -| Organizations | List | | ✅ | -| | Members | | ✅ | -| | Invitations | | ✅ | -| User Management | Users | ✅ | | -| | Roles | | ✅ | -| Monitoring | Logs | | ✅ + | -| Marketplace | | | ✅ | -| Get Support | Support Tickets - Create | ✅ | | -| | Usage Reports | ✅ | | -| | Compliance | ✅ | | - -+ Access to user events only. - - - - - -| Dashboard Section | Subsection (if applicable) | Read/Write Access | Read-Only Access | -| --- | --- | --- | --- | -| Organizations | List | | ✅ | -| | Members | | ✅ | -| User Management | Users | | ✅ | -| | Roles | | ✅ | -| Monitoring | Logs | | ✅ + | -| Marketplace | | | ✅ | -| Get Support | Support Tickets - Create | ✅ | | -| | Usage Reports | ✅ | | -| | Compliance | ✅ | | - -+ Access to user events only. - - - - - -| Dashboard Section | Subsection (if applicable) | Read/Write Access | Read-Only Access | -| --- | --- | --- | --- | -| Applications | Applications | | ✅ + | -| | APIs | | ✅ + | -| | SSO Integrations | | ✅ + | -| Authentication | Database | | ✅ + | -| | Social | | ✅ + | -| | Enterprise | | ✅ + | -| | Passwordless | | ✅ + | -| Organizations | List | | ✅ | -| | Overview | | ✅ | -| | Connections | | ✅ | -| User Management | Roles | | ✅ | -| Branding | Universal Login | | ✅ | -| | Custom Domains | | ✅ | -| | Email Templates | | ✅ | -| | Email Providers | | ✅ + | -| Security | Attack Protection | | ✅ | -| | Multi-factor Auth | | ✅ + | -| Actions | Flows | | ✅ | -| | Library | | ✅ | -| Auth Pipeline | Rules | | ✅ + | -| Marketplace | | | ✅ | -| Settings | General | | ✅ | -| | Advanced | | ✅ | -| Get Support | Support Tickets - Create | ✅ | | -| | Usage Reports | ✅ | | -| | Compliance | ✅ | | - -+ Excludes access to secrets. - - - - - -| Dashboard Section | Subsection (if applicable) | Read/Write Access | Read-Only Access | -| --- | --- | --- | --- | -| Activity | Stats | ✅ + | | -| Get Support | Support Tickets - Create | ✅ | | -| | Support Tickets - Manage All Users Tickets | ✅ | | -| | Usage Reports | ✅ | | -| | Compliance | ✅ | | - -+ Access to metrics only. - - - - - -## Log events available to user roles - -Logs can contain sensitive data, such as secrets, PII, etc. It is important not to disclose sensitive data to users whose role does not require that information. However, the **Editor - Users** or **Viewer - Users** roles need to have some access to logs to identity user issues. For example, finding out if the user signed up correctly, if the user was blocked, etc. - -We allow the **Editor - Users** and **Viewer - Users** with access to a limited set of log types, that are connected to user events. The log events in the list provide the necessary information about user actions but do not disclose sensitive information about other parts of the tenant configuration. To learn more, read [Log Event Type Codes](/docs/deploy-monitor/logs/log-event-type-codes). - -```text lines expandable -cls -cs -f -fce -fcoa -fcp -fcpn -fcpr -fcu -fdeac -fdeaz -fdecc -fdu -feacft -feccft -fede -fens -feoobft -feotpft -fepft -fepotpft -fercft -fi -flo -fn -fp -fs -fsa -fu -fui -fv -fvr -gd_auth_failed -gd_auth_rejected -gd_auth_succeed -gd_enrollment_complete -gd_otp_rate_limit_exceed -gd_recovery_failed -gd_recovery_rate_limit_exceed -gd_recovery_succeed -gd_send_email -gd_send_email_failure -gd_send_pn -gd_send_pn_failure -gd_send_sms -gd_send_sms_failure -gd_send_voice -gd_send_voice_failure -gd_start_auth -gd_start_enroll -gd_tenant_update -gd_unenroll -gd_update_device_account -limit_mu -limit_wc -mfar -pwd_leak -s -sce -scoa -scp -scpn -scpr -scu -sdu -seacft -sede -sens -seoobft -seotpft -sepft -sercft -si -slo -ss -ssa -sv -svr -ublkdu -w -``` - - - - - - -## Limitations - -* Users with **Admin** role can invite **Editor - Specific Apps** users to one application at a time. To work around this, the **Admin** user can [edit their role](/docs/get-started/manage-dashboard-access/edit-dashboard-users) to assign multiple applications after the user accepts the invitation. -* The **Viewer - Users** and **Editor - Users** roles don't have access to the Users' **Devices** and **Authorized Apps** sections. -* The [New Activity Page](/docs/get-started/auth0-overview/dashboard/activity) is visible to **Admins** and **Elevated Support Access** users only. **Editor - Users** and **Viewer - Users** can access daily activity (such as logins or signups) through the [Auth0 Management API](https://auth0.com/docs/api/management/v2#!/Stats/get_daily). - -## Private Cloud requirements - -The **Editor - Users** and the **Viewer - Users** roles require that User Search v3 and Logs Search v3 are enabled in your environment. If your environments don’t support these versions, these two roles are unavailable. - -## Learn more - -* [Add Tenant Members](/docs/get-started/manage-dashboard-access/add-dashboard-users) -* [Edit Tenant Members](/docs/get-started/manage-dashboard-access/edit-dashboard-users) -* [Remove Tenant Members](/docs/get-started/manage-dashboard-access/remove-dashboard-users) -* [Troubleshoot Role-Based Access Control and Authorization](/docs/troubleshoot/authentication-issues/troubleshoot-rbac-authorization) -* [Check Error Messages](/docs/troubleshoot/basic-issues/check-error-messages) diff --git a/main/docs/get-started/onboarding.mdx b/main/docs/get-started/onboarding.mdx deleted file mode 100644 index c5318b9dd9..0000000000 --- a/main/docs/get-started/onboarding.mdx +++ /dev/null @@ -1,32 +0,0 @@ ---- -description: Integrate Auth0 into your existing infrastructure by following the B2B, B2C, or M2M pathway. -sidebarTitle: Overview -title: Auth0 Onboarding ---- -Welcome to Auth0 Onboarding! - -This section of our documentation is to help you integrate Auth0 into your existing infrastructure and give you the confidence to go live with your integration. In this section, you can find relevant resources. - -As a complement to this guided onboarding, you can enroll in our free course [Introduction to Okta](https://www.okta.com/training/introduction-to-okta-formerly-okta-basics), which has relevant modules to assist you as you get started. - -Follow our guided onboarding to start your journey with Auth0. - -| Read... | To learn... | -| --- | --- | -| [Self-Service Machine-to-Machine](/docs/get-started/onboarding/self-service-m2m) | How to onboard for machine-to-machine authentication. | - -## Resources and support - -Along with documentation and possible [architecture scenarios](/docs/get-started/architecture-scenarios), Auth0 has several means of support. - -* **Auth0 Community:** Engage in discussions with our [developer community and Auth0 experts](https://community.auth0.com/) or you can review our robust [Documentation](https://auth0.com/docs) and [FAQs](https://community.auth0.com/c/faq). -* **Auth0 Marketplace**: [Marketplace](http://marketplace.auth0.com/) aims to simplify your development process with a straightforward way to add an integration to your application built and supported by trusted Marketplace Partners. The marketplace makes it easier and faster to extend and customize your Auth0 solution. All of the integrations you find in the Marketplace are validated by Auth0, so you know you can trust them. -* **Auth0 Status Page:** Should you encounter service disruptions. Follow [our status page](https://status.auth0.com/) and subscribe to RSS feed to get the latest information around our operational status. - -## Learn more - -* [Introduction to Auth0](/docs/get-started/identity-fundamentals/introduction-to-auth0) -* [Identity Fundamentals](/docs/get-started/identity-fundamentals) -* [Architecture Scenarios](/docs/get-started/architecture-scenarios) -* [Login](/docs/authenticate/login) -* [Check Auth0 Status](/docs/deploy-monitor/monitor/check-auth0-status) \ No newline at end of file diff --git a/main/docs/get-started/onboarding/self-service-m2m.mdx b/main/docs/get-started/onboarding/self-service-m2m.mdx deleted file mode 100644 index b609ad8e8c..0000000000 --- a/main/docs/get-started/onboarding/self-service-m2m.mdx +++ /dev/null @@ -1,463 +0,0 @@ ---- -description: Describes how to onboard with an M2M business case. -title: Self-Service Machine-to-Machine ---- -import {AuthCodeBlock} from "/snippets/AuthCodeBlock.jsx"; - -import {AuthCodeGroup} from "/snippets/AuthCodeGroup.jsx"; - -If your business case services a non-interactive audience, like APIs or backend servers, you will onboard with a machine-to-machine (M2M) configuration. - -## Use cases - -Use the M2M onboarding path if you: - -* Support service-to-service communications -* Have scheduled jobs or cron tasks running on servers that need to access protected resources or APIs -* Allow IoT devices to communicate with backend services or APIs -* Have an API layer that needs to communicate with other API layers without user involvement or after a user token has expired -* Have a privileged API that may need to be called before a user has authenticated (i.e. from an Action or custom database script in your Auth0 tenant) -* Use an API Gateway to manage backend services -* Use or support non-interactive applications or other tooling not involving human interaction such as daemons or backend services - - - -These services will still need an M2M access token for authentication. - - - -## How to use this guide - -This guide is a pathway to create your M2M implementation in Auth0. We provide considerations, best practices, and concepts you should review. - -* In Architecture, we advise you to configure Auth0 to support your Software Development Life Cycle and existing infrastructure. -* In Create an account, we provide instructions to create your API instance in Auth0 and an application to support the authentication flow (or grant) needed for machine-to-machine authentication. -* In Authentication, we walk through the grant you need to use for authentication as well as access tokens and permissions (or scopes) you can set. -* In Branding, we advise you where to find information on how to configure Custom Domains depending on how you plan to manage certificates. -* In Deployment Automations, you can read about our tooling to assist with deployment. -* In Quality Assurance, you can learn more about unit testing, and the readiness checks we provide in Auth0 Dashboard. - -## Architecture - -Before you configure your Auth0 account and tenant, or the groups and structures of your Auth0 services, create a map of your existing infrastructure so you can best leverage Auth0’s capabilities in your existing ecosystem. - -As mentioned in common scenarios, you may have other non-interactive technologies in your application domain, network domain, or M2M device domain to consider before you configure Auth0. To review an example M2M scenario, read [Server + API](/docs/get-started/architecture-scenarios/server-application-api/part-1). To attempt a hands-on lab working with Node and test API deployment, visit our [GitHub repository](https://www.google.com/url?q=https://github.com/auth0-training/labs-node-working-with-apis&sa=D&source=docs&ust=1723578190947730&usg=AOvVaw3IXRQG9ogH4pW6LEY047T6). - -You may want to create a visualization of your current tech stack as well as plan how Auth0 fits in with your current Software Development Lifecycle (SDLC). This can help you determine how many tenants you may need. - -### Considerations - -Before you create a new account or configure your first tenant, you may want to consider: - -* How you partition or group your APIs to call specific endpoints. - - + This may determine the audience and other claims on access tokens. -* Any third-party consumers to your resource may request an access token for each call. Excessive calls could affect your [rate limit](/docs/troubleshoot/customer-support/operational-policies/rate-limit-policy/rate-limit-configurations/essentials-professional-b2b). - - + You can use an API Gateway to limit the number of access tokens a third-party can request. To learn more about API Gateways and Auth0, read [Configure an Identity Provider in Access Gateway](/docs/get-started/auth0-overview/create-applications/configure-an-identity-provider-in-access-gateway). - -## Create an account - -Now that you have a plan for your architecture, you’ll configure your Auth0 account and tenants. When you sign up for Auth0 services, you will create your first [tenant](/docs/get-started/auth0-overview/create-tenants). This is where you configure Auth0 assets, services, and resources. [Sign up](https://auth0.com/signup) to start. - - - -In the Auth0 Dashboard or with the Auth0 Management API, create: - -* An API to represent your API -* An M2M application to use the Client Credential Flow - -You may want to plan some configuration details before you create an account. - -* Your tenant name has a role in your Auth0 domain. Before you determine a name, you should review [tenant characteristics](/docs/get-started/auth0-overview/create-tenants#create-a-tenant-and-domain). -* Which Auth0 features you need for your use case. Some features are only available on Professional and Enterprise plans. -* Determine if you need to support multiple environments, such as development, staging, and production. To learn more, read [Set Up Multiple Environments](/docs/get-started/auth0-overview/create-tenants/set-up-multiple-environments). -* If you have a use case involving thirty-party applications you want to register in a tenant, you can use [Dynamic Application Registration](/docs/get-started/applications/dynamic-client-registration) based on the [OIDC Client Registration](https://openid.net/specs/openid-connect-registration-1_0.html) specification. - - - -### Provision a tenant - -Now that you have a plan for your architecture, you’ll configure your Auth0 account and Tenant. - - - -Once you create an API in Auth0 Dashboard, a test application for the API automatically generates. If you create an API programmatically in [Management API](https://auth0.com/docs/api/management/v2/), you may need to create a test application in a separate call. - - - -#### Register an API - -In this section, create your API in Auth0. - - - -You can always update your API in Auth0 Dashboard or by calling the Management API [Update a resource server](https://auth0.com/docs/api/management/v2/resource-servers/patch-resource-servers-by-id) endpoint. - - - - - -Start by creating an instance in the Auth0 Dashboard for your APIs. - -1. Follow instructions to [register your API](/docs/get-started/auth0-overview/set-up-apis). - -In the [Authentication](/docs/get-started/onboarding/self-service-m2m#authentication) section, configure your API settings for M2M authentication. - - - -To register an API programmatically, use the Management API. You will need an access token to use Management API. To learn how, read [Management API Tokens](/docs/secure/tokens/access-tokens/management-api-access-tokens). - -Use the sample provided in Management API Explorer to call the Management API [Create a Resource Server](https://auth0.com/docs/api/management/v2/resource-servers/post-resource-servers) endpoint and include the following parameters in the body: - -| Field | Description | Example | -| --- | --- | --- | -| **Name** | A friendly name for the API. Does not affect any functionality. | `yourDomain` | -| **Identifier** | A unique identifier for the API. Auth0 recommends using a URL. Auth0 does differentiate between URLs that include the last forward slash. For example, `https://example.com` and `https://example.com/` are two different identifiers. The URL does not have to be a publicly available URL. Auth0 will not call your API. This value cannot be modified afterwards. | `https://{yourDomain}` | -| **JSON Web Token (JWT) Profile** | The profile determines the format of the access tokens issued for the API. The available values are `Auth0` and `RFC 9068`. To learn more, read [Access Token Profiles](/docs/secure/tokens/access-tokens/access-token-profiles). | `access_token` | -| **JSON Web Token (JWT) Signing Algorithm** | The algorithm to sign the access tokens with. The available values are `HS256`, `PS256`, `RS256`. If you select `RS256`, the token will be signed with the tenant's private key. | `HS256` | - - - -### Associate an application - -You need to create an association between your application and your API so your application can request access tokens from it. You will learn more about client grants in the Authentication section. - - - -Auth0’s API has multiple settings you may need to review before you configure. To learn more, read [API Settings](/docs/get-started/apis/api-settings). - - - - - -If you create your API in the Dashboard, Auth0 automatically generates a test application and associates it with your API. - -1. Navigate to [Auth0 Dashboard > Applications](https://manage.auth0.com/#/applications). -2. Select the test M2M test application created when you created your API. - - - - You can create another application for development or production later by following the instructions on [Register Machine-to-Machine Applications](/docs/get-started/auth0-overview/create-applications/machine-to-machine-apps). - - -3. Switch to the **API** view, and then locate the API you’d like to enable for this application. -4. Enable the **Authorize** toggle, and then select the arrow button on the right to expand the card. -5. Select **Update**. - - ![Dashboard > Applications > APIs](/docs/images/cdy7uua7fh8z/6L2R46XVdYw1kifRfMifRz/87e3b9f75039d55af6028be0eb0598ac/Timesheets_API_-_English.png) - - - - In this view, you can select the drop-down and choose the scopes you want to add. We will learn more about scopes when discussing access tokens under the Authentication section. - - - - - -Create an application to associate with your API. Use the sample provided in Management API Explorer to: - -1. Call the [Create a Client](https://auth0.com/docs/api/management/v2/clients/post-clients) endpoint. You need to set the `app_type` to `non-interactive`. -2. Call the [Create Client Grant](https://auth0.com/docs/api/management/v2/client-grants/post-client-grants) endpoint to associate your application to your API. - -To learn about application and tenant settings, read [Tenant Settings](/docs/get-started/tenant-settings). - - - -## Authentication - -When calling one API from another API, or from any situation where there is no authenticated user context, you need a way to authorize the application instead of a user. This is a one step process where the application is authenticated (using a `client_id` and `client_secret`) and then authorized in one call. - -For non-interactive applications or services to authentication, you must select a client grant, or authentication flow. The OAuth 2.0 [Client Credentials Flow](https://tools.ietf.org/html/rfc6749#section-4.4) does not require human interaction and is best suited for M2M applications. - - - -In Auth0 Dashboard or Management API, you will: - -* Set your application to use the Client Credentials Flow -* Update the scopes for your M2M access tokens - -Before you configure your authentication method: - -* Review the [Client Credentials Flow](/docs/get-started/authentication-and-authorization-flow/client-credentials-flow) for machine-to-machine authentication. This is the workflow for non-interactive authentication and authorization. -* Determine the level of access for your APIs. This helps determine what [scopes](/docs/get-started/apis/scopes/api-scopes), or permissions, you will configure when you create your API. - - - -### Configure the Client Credential Flow - -You can use the Auth0 Dashboard or Management API to set the authentication flow to provide a client credential in exchange for an access token. - -Follow the instructions on [Update Grant Types](/docs/get-started/applications/update-grant-types) to use Auth0 Dashboard or Management API. - -### M2M access tokens - -In token-based authentication, non-interactive clients provide `client_id` and `client_secret` in a call to the [Authentication API token endpoint](/docs/customize/actions/explore-triggers/machine-to-machine-trigger) to get an [access token](/docs/secure/tokens/access-tokens). This access token permits access to your protected API. - -The default profile, or format, is the Auth0 token profile associated with two token profiles. You can choose to change the token profile to RFC 9068. To learn more, read [Access Token Profiles](/docs/secure/tokens/access-tokens/access-token-profiles). To verify the token is valid, your API will check the [Signing Algorithms](/docs/get-started/applications/signing-algorithms). The default signing algorithm is RSA256, a key-based algorithm. - - - -Auth0 supports other client authentication methods besides providing Client ID and Client Secret as credentials. These methods, including our recommendation of [Private Key JWT](/docs/get-started/authentication-and-authorization-flow/authenticate-with-private-key-jwt) for M2M configurations, are available with an Enterprise plan. To learn more, read [Application Credentials](/docs/secure/application-credentials). - - - -#### Example - -A request to the `/oauth/token` endpoint should be similar to the sample below: - - -```bash cURL -curl --request POST \ - --url 'https://{yourDomain}/oauth/token' \ - --header 'content-type: application/x-www-form-urlencoded' \ - --data grant_type=client_credentials \ - --data client_id={yourClientId} \ - --data client_secret={yourClientSecret} \ - --data audience=YOUR_API_IDENTIFIER -``` -```csharp C# -var client = new RestClient("https://{yourDomain}/oauth/token"); -var request = new RestRequest(Method.POST); -request.AddHeader("content-type", "application/x-www-form-urlencoded"); -request.AddParameter("application/x-www-form-urlencoded", "grant_type=client_credentials&client_id={yourClientId}&client_secret={yourClientSecret}&audience=YOUR_API_IDENTIFIER", ParameterType.RequestBody); -IRestResponse response = client.Execute(request); -``` -```go Go -package main - -import ( - "fmt" - "strings" - "net/http" - "io/ioutil" -) - -func main() { - - url := "https://{yourDomain}/oauth/token" - - payload := strings.NewReader("grant_type=client_credentials&client_id={yourClientId}&client_secret={yourClientSecret}&audience=YOUR_API_IDENTIFIER") - - req, _ := http.NewRequest("POST", url, payload) - - req.Header.Add("content-type", "application/x-www-form-urlencoded") - - res, _ := http.DefaultClient.Do(req) - - defer res.Body.Close() - body, _ := ioutil.ReadAll(res.Body) - - fmt.Println(res) - fmt.Println(string(body)) - -} -``` -```java Java -HttpResponse response = Unirest.post("https://{yourDomain}/oauth/token") - .header("content-type", "application/x-www-form-urlencoded") - .body("grant_type=client_credentials&client_id={yourClientId}&client_secret={yourClientSecret}&audience=YOUR_API_IDENTIFIER") - .asString(); -``` -```javascript Node.JS -var axios = require("axios").default; - -var options = { - method: 'POST', - url: 'https://{yourDomain}/oauth/token', - headers: {'content-type': 'application/x-www-form-urlencoded'}, - data: new URLSearchParams({ - grant_type: 'client_credentials', - client_id: '{yourClientId}', - client_secret: '{yourClientSecret}', - audience: 'YOUR_API_IDENTIFIER' - }) -}; - -axios.request(options).then(function (response) { - console.log(response.data); -}).catch(function (error) { - console.error(error); -}); -``` -```php PHP -$curl = curl_init(); - -curl_setopt_array($curl, [ - CURLOPT_URL => "https://{yourDomain}/oauth/token", - CURLOPT_RETURNTRANSFER => true, - CURLOPT_ENCODING => "", - CURLOPT_MAXREDIRS => 10, - CURLOPT_TIMEOUT => 30, - CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1, - CURLOPT_CUSTOMREQUEST => "POST", - CURLOPT_POSTFIELDS => "grant_type=client_credentials&client_id={yourClientId}&client_secret={yourClientSecret}&audience=YOUR_API_IDENTIFIER", - CURLOPT_HTTPHEADER => [ - "content-type: application/x-www-form-urlencoded" - ], -]); - -$response = curl_exec($curl); -$err = curl_error($curl); - -curl_close($curl); - -if ($err) { - echo "cURL Error #:" . $err; -} else { - echo $response; -} -``` -```python Python -import http.client - -conn = http.client.HTTPSConnection("") - -payload = "grant_type=client_credentials&client_id={yourClientId}&client_secret={yourClientSecret}&audience=YOUR_API_IDENTIFIER" - -headers = { 'content-type': "application/x-www-form-urlencoded" } - -conn.request("POST", "/{yourDomain}/oauth/token", payload, headers) - -res = conn.getresponse() -data = res.read() - -print(data.decode("utf-8")) -``` -```ruby Ruby -require 'uri' -require 'net/http' -require 'openssl' - -url = URI("https://{yourDomain}/oauth/token") - -http = Net::HTTP.new(url.host, url.port) -http.use_ssl = true -http.verify_mode = OpenSSL::SSL::VERIFY_NONE - -request = Net::HTTP::Post.new(url) -request["content-type"] = 'application/x-www-form-urlencoded' -request.body = "grant_type=client_credentials&client_id={yourClientId}&client_secret={yourClientSecret}&audience=YOUR_API_IDENTIFIER" - -response = http.request(request) -puts response.read_body -``` - - -The response should be similar to the sample below: - -```json lines -HTTP/1.1 200 OK -Content-Type: application/json -{ - "access_token":"eyJz93a...k4laUWw", - "token_type":"Bearer", - "expires_in":86400 -} -``` - -#### Token expiration - -Your access tokens have a limit for how long the token is valid. Since your communications are on the back-channel, you cannot use refresh tokens to extend sessions, and should consider configuring your access tokens with a 1-hour expiration time. You may need to strike your own balance between security and performance for your specific environment. To learn more, read [Update Access Token Lifetime](/docs/secure/tokens/access-tokens/update-access-token-lifetime). - -### Scopes - -Before any non-interactive clients or services call your API, you need to define the permissions or Scopes your API allows. You can set the scopes in Auth0 Dashboard to include in your authentication request to Authentication API. To read more examples of ways to use API scopes, read [API Scopes](/docs/get-started/apis/scopes/api-scopes). - -To configure scopes, follow the instructions on [Add API Permissions](/docs/get-started/apis/add-api-permissions) for Auth0 Dashboard or use the sample provided for Management API. - - - -To add custom claims to an access token, you can use the Actions Machine-to-Machine Flow. To learn more, read Machine to Machine Flow. - - - -## Branding - -Even if you service non-interactive clients or services working on the back-channel, you can still customize your experience to align with the look and feel of your existing brand. - -### Custom domains - -Auth0 supports the use of custom domains when you call the `/authorize` endpoint to request access tokens. - - - -In Auth0 Dashboard, you must: - -* Register and verify your domain before you can use it with your Auth0 services. -* Determine if you want to manage your own certificate or use an Auth0 managed certificate. To learn more about certificates, read [Certificate management options](/docs/customize/custom-domains#certificate-management-options). -* Verify the TLS (SSL) version and cipher you want to use for self-managed certificates is supported by Auth0. To learn more, read [TLS (SSL) Versions and Ciphers](/docs/customize/custom-domains/self-managed-certificates/tls-ssl). - - - -1. To configure your custom domain with Auth0-managed certificates, follow the instructions on [Configure Custom Domains with Auth0-Managed Certificates](/docs/customize/custom-domains/auth0-managed-certificates). - - 1. If you want to manage your own certificates, follow the instructions on [Configure Custom Domains with Self-Managed Certificates](/docs/customize/custom-domains/self-managed-certificates). - - - - You must have an Enterprise subscription to manage certificates in your custom domain. To learn more, read [Auth0 Pricing](https://auth0.com/pricing/) and [Login](/docs/authenticate/login). - - -2. Review [API configuration with custom domains](/docs/customize/custom-domains/configure-features-to-use-custom-domains#apis). You may need to adjust your API settings to incorporate a custom domain. - -If you experience issues with your custom domain, review [Troubleshoot Custom Domains](/docs/troubleshoot/integration-extensibility-issues/troubleshoot-custom-domains). - -## Deployment Automation - -Auth0 provides support for a couple of different options when it comes to the deployment automation approaches you can use, and each can be used in conjunction with the other. - - - -However you configure deployment automation, we’d recommend you unit test your custom code and Actions prior to deployment, and run some integration tests against your tenant post-deployment too. - - - -### Deploy CLI Tool - -As recommended under the Architecture section, you should have Auth0 tenants for development, test, and production. These tenants should share identical configurations for quality checks and testing; however, you may be faced with errors as a result of mismatched configurations between your environments. For example, each environment will have different Client IDs and Client Secrets. - -To mitigate these mismatch errors, you can use the Deploy CLI Tool to help you integrate your Auth0 instance with your existing CI/CD pipeline.  With dynamic keyword replacement, you can replace environmental variables on tenants sharing similar configurations. To learn more, read [Deploy CLI Tool](/docs/deploy-monitor/deploy-cli-tool) and [Keyword Replacement](/docs/deploy-monitor/deploy-cli-tool/keyword-replacement). - -### Actions Real-time Logs - -Actions Real-time Logs displays all logs for custom cSode in real-time, including `console.log` output and other exceptions. If you are using Auth0 Actions or other custom logic, you can use this extension to debug and troubleshoot. To learn more about installation and configuration, read [Actions Real-time Logs](/docs/customize/actions/actions-real-time-logs). - -## Quality Assurance - -Quality Assurance is important in identifying issues before you go live. Depending on the nature of your project, there are several different types of quality assurance testing that you’re going to want to consider as part of your integration with Auth0: - -* How will your APIs perform when subjected to unexpected production loads? -* How will your rate limits be affected by third-party applications? - -If you are not using Auth0 widgets or features, like Universal Login, you will not have the built-in usability and accessibility best practices out-of-the-box on a host of browsers and devices. To ensure functional requirements are met and unexpected events are handled correctly, guidance is provided for testing the integration between your application(s) and Auth0, and for unit testing individual extensibility modules, such as Auth0 Actions. We also recommend you review Auth0’s [penetration testing policy](/docs/troubleshoot/customer-support/operational-policies/penetration-testing-policy) and complete Mock testing you can leverage in conjunction with our [load testing policy](/docs/troubleshoot/customer-support/operational-policies/load-testing-policy) to help ensure your application(s) perform under unexpected load. - -### Unit testing - -Unit testing is verifying units of extensibility, like Auth0 Actions. If you are using custom code we recommend using a test framework (such as [Mocha](https://mochajs.org/)) to test the additional code before deployment. - -### Mock testing - -In a balance between Auth0’s [load testing policy](/docs/troubleshoot/customer-support/operational-policies/load-testing-policy) and the desire to load test, it is common practice to create a mock test of Auth0’s endpoints. This is a valuable practice in order to ensure that your configuration works with your expected interfaces without having to restrict your testing, and tools such as [MockServer](http://www.mock-server.com/), [JSON Server](https://github.com/typicode/json-server), or even [Postman](https://learning.getpostman.com/docs/postman/mock_servers/setting_up_mock/) can be used to assist. - -## Deployment - -Our [Deploy and Monitor](/docs/deploy-monitor) section provides guidance for deployment best practices. We advise your review [Pre-Deploym](/docs/deploy-monitor/pre-deployment-checks)[ent Checks](/docs/deploy-monitor/pre-deployment-checks), especially the built-in [Auth0 Dashboard Readiness Checks](/docs/deploy-monitor/pre-deployment-checks/how-to-run-production-checks). - -To review the Readiness Check, select the drop-down menu below your tenant name and environmental tag at [Auth0 Dashboard > Run Readiness Checks](https://manage.auth0.com/#/production-checks). - -![Auth0 Dashboard > Readiness Checklist](/docs/images/cdy7uua7fh8z/7iu1CzH0NgaXJbLBNWXZli/b598b8cdaad0c676e83a0fb0595d4603/Readiness_Checks_-_English.png) - -You can use the filter to apply the Readiness Checks to selected applications. **These checks do not apply to your configured APIs**. - -For checks that do not apply to your specific configuration, you can select **Dismiss** to remove them from the final results. - -We advise you to review [Deployment Best Practices](/docs/deploy-monitor/deployment-best-practices) for final checks before you go live and take advantage of [Logs](/docs/deploy-monitor/logs) to monitor your services. - -## Learn more - -* [Auth0 Overview](/docs/get-started/auth0-overview) -* [Solution Overview (Server Apps + API)](/docs/get-started/architecture-scenarios/server-application-api/part-1) -* [Call Your API Using the Client Credentials Flow](/docs/get-started/authentication-and-authorization-flow/client-credentials-flow/call-your-api-using-the-client-credentials-flow) -* [Retrieve Log Logs Using the Management API](/docs/deploy-monitor/logs/retrieve-log-events-using-mgmt-api) -* [Get Management API Access Tokens for Production](/docs/secure/tokens/access-tokens/management-api-access-tokens/get-management-api-access-tokens-for-production) \ No newline at end of file diff --git a/main/docs/get-started/tenant-settings.mdx b/main/docs/get-started/tenant-settings.mdx index 9ff72ecd71..696ccebf3b 100644 --- a/main/docs/get-started/tenant-settings.mdx +++ b/main/docs/get-started/tenant-settings.mdx @@ -1,8 +1,8 @@ --- -description: Describes the settings related to tenants available in the Auth0 Dashboard. -sidebarTitle: Overview title: Tenant Settings +description: Describes the settings related to tenants available in the Auth0 Dashboard. --- + Use the **Tenant Settings** page in the Auth0 Dashboard at [Dashboard > Settings](https://manage.auth0.com/#/tenant) to configure various settings related to your Auth0 tenant. ## Recommended settings diff --git a/main/docs/get-started/tenant-settings/configure-device-user-code-settings.mdx b/main/docs/get-started/tenant-settings/configure-device-user-code-settings.mdx deleted file mode 100644 index b101514589..0000000000 --- a/main/docs/get-started/tenant-settings/configure-device-user-code-settings.mdx +++ /dev/null @@ -1,18 +0,0 @@ ---- -description: Learn how to configure the user code generated by your applications during the device authorization flow using the Auth0 Dashboard. -title: Configure Device User Code Settings ---- -You can configure settings for the user code generated by your application during the [Device Authorization Flow](/docs/get-started/authentication-and-authorization-flow/device-authorization-flow) using the Auth0 Dashboard. - -1. Go to [Dashboard > Settings](https://manage.auth0.com/#/tenant) and click the **Advanced** tab. -2. Scroll to the **Device Flow User Code Format** section, locate **User Code Character Set** and **User Code Mask**, enter the desired settings, and click **Save**. - -| Setting | Description | -| --- | --- | -| **Device Flow User Code Format** | Character set used to when randomly generating a user code. | -| **User Code Mask** | Mask used to define length and format of a randomly-generated user code. Its purpose is to increase the user code's readability and ease of input. | - -## Learn more - -* [Device Authorization Flow](/docs/get-started/authentication-and-authorization-flow/device-authorization-flow) -* [Unlink Devices from Users](/docs/manage-users/user-accounts/unlink-devices-from-users) diff --git a/main/docs/get-started/tenant-settings/enable-sso-for-legacy-tenants.mdx b/main/docs/get-started/tenant-settings/enable-sso-for-legacy-tenants.mdx index 4c775d54fe..91d95c3ff6 100644 --- a/main/docs/get-started/tenant-settings/enable-sso-for-legacy-tenants.mdx +++ b/main/docs/get-started/tenant-settings/enable-sso-for-legacy-tenants.mdx @@ -1,6 +1,6 @@ --- description: Describes how to enable Single Sign-on (SSO) for a tenant using the Auth0 Dashboard. Only for use with legacy tenants. -title: Enable Single Sign-On for Tenants +title: Enable Single Sign-On for Legacy Tenants --- diff --git a/main/docs/get-started/tenant-settings/signing-keys.mdx b/main/docs/get-started/tenant-settings/signing-keys.mdx index 8e9c47089a..dfc76b6b08 100644 --- a/main/docs/get-started/tenant-settings/signing-keys.mdx +++ b/main/docs/get-started/tenant-settings/signing-keys.mdx @@ -1,7 +1,7 @@ --- +title: Signing Keys on Auth0 Tenants +sidebarTitle: Signing Keys description: Describes how your tenant's application signing keys work. -sidebarTitle: Overview -title: Signing Keys --- When you select our recommended signing algorithm (RS256), Auth0 uses public-key cryptography to establish trust with your applications. In more general terms, we use a signing key that consists of a public and private key pair.