Availability varies by Auth0 plan
Both your specific login implementation and your Auth0 plan or custom agreement affect whether this feature is available. To learn more, read Pricing.
- Action with external linking application
- Auth0
- Auth0.js library
Action with external linking application
You can use an Action along with an external linking application to link user accounts with the Management API. The following steps illustrate an example implementation:- Action identifies the potential user accounts to link (if they exist).
-
Action redirects the user to an external linking application with a token payload that contains candidate user identities:
- External linking application prompts the user to authenticate using the credentials for the account they wish to link.
-
External linking application redirects the user back to the Action with a token payload that contains the primary and secondary user identities:
- Action validates the authenticity and contents of the token.
- Action calls the Management API to link the accounts based on the results from the external linking application.
-
Action switches to the primary user if it doesn’t match the
event.user.user_id.
Example: Account linking Action
Management API
You can use the Management API Link a user account endpoint in two ways:- User-initiated client-side account linking using with the
update:current_user_identitiesscope. - Server-side account linking using access tokens with the
update:usersscope.
User-initiated client-side account linking
For user-initiated client-side account linking, you need an access token that contains the following items in the payload:update:current_user_identitesscopeuser_idof the primary account as part of the URL- of the secondary account that is signed with RS256 and includes an
audclaim identifying the client that matches the value of the requesting access token’sazpclaim.
update:current_user_identities scope can only be used to update the information of the currently logged-in user. Therefore, this method is suitable for scenarios where the user initiates the linking process.
Using the Auth0 CLI? If you haven’t already, set up and authenticate your CLI session before running this command.
Server-side account linking
For server-side account linking, you need an access token that contains the following items in the payload:update:usersscopeuser_idof the primary account as part of the URLuser_idof the secondary account- ID token of the secondary account that is signed with RS256 and includes an
audclaim identifying the client that matches the value of the requesting access token’sazpclaim.
update:users scope can be used to update the information of any user. Therefore, this method is intended for use in server-side code only.
The secondary user account’s user_id and provider can be deduced by its unique identifier. For example, for the identifier google-oauth2|108091299999329986433:
providerisgoogle-oauth2user_idis108091299999329986433
provider and user_id: