Skip to main content
Auth0 user profiles contain two kinds of metadata:
  • user_metadata stores user information, such as preferences that do not impact a user’s core functionality. This data can be edited by logged in users if you build a form using the Management API and should not be used as a secure data store.
  • app_metadata stores access information, such as permissions, Auth0 plan, and external IDs that can impact user access to features. This data cannot be edited by users and there are restrictions for what can be stored in this field.
The metadata can be modified as part of a user’s login flow. You can use metadata to:
  • Store application-specific data in the user profile.
  • Record whether or not specific operations have occurred for a user.
  • Cache the results of expensive operations on the user profile so they can be re-used in future logins.
  • Store information that does not originate from an or that overrides what an identity provider supplies.
  • Store information that you want to use to customize Auth0 emails. For example, use user_metadata.lang if you want the user to be able to change the field’s value, then use the information to customize the language for an email.
Auth0 applications (or clients, in OIDC OAuth0 terminology) also have their own client_metadata, which is separate from user profile metadata.