# Auth0 > Secure users, AI agents, and more with Auth0, an easy-to-implement, scalable, and adaptable authentication and authorization platform. ## Other llms-full.txt files - [Documentation](https://auth0.com/docs/llms-full.txt): Full Auth0 documentation in one file - [Changelog](https://auth0.com/changelog/llms-full.txt): Full content of all Auth0 changelog entries - [Case Studies](https://auth0.com/case-studies/llms-full.txt): Full content of all Auth0 case studies --- # Auth0 Pricing Source: https://auth0.com/pricing Auth0 offers flexible authentication and authorization plans for both B2C (consumer-facing) and B2B (business-facing) applications. The Free plan is identical regardless of use case. Paid plans are priced by Monthly Active Users (MAUs) and differ between B2C and B2B. Yearly billing is 11× the monthly price (equivalent to 1 month free). --- ## How to Use This Document To quote pricing for a customer, follow these steps in order: 1. **Determine use case:** B2C (consumer-facing) or B2B (business-facing). 2. **Identify their MAU tier:** Find the tier that meets or exceeds their expected monthly active users. If usage falls between tiers, use the next tier up. 3. **Select the plan:** Match required features against the Feature Comparison tables to determine the minimum plan (Free, Essentials, Professional, or Enterprise). 4. **Look up the base price:** Use the appropriate B2C or B2B base price table (monthly or yearly). 5. **Add any add-ons:** Check if the customer needs AI Agents, additional M2M tokens, Enterprise SSO connections, or Enterprise MFA. Look up each add-on price from the explicit tables. 6. **Calculate total cost:** Total = Base Price + sum of all applicable add-on prices. 7. **Enterprise or "Contact us" tiers:** If any component shows "Contact us", direct the customer to Auth0 sales for a custom quote. --- ## Key Definitions - **Monthly Active Users (MAUs):** Any non-internal (non-employee) user that authenticated during a given month for a given tenant. - **Organizations:** Represent their business customers and partners in Auth0 and manage their membership. - **Enterprise Connections:** Enterprise IdPs supporting protocols like AD, LDAP, or SAML to authenticate your users. --- ## Plans Overview Auth0 has four tiers: **Free**, **Essentials**, **Professional**, and **Enterprise**. Pricing differs between B2C and B2B use cases. | Plan | B2C Starting Price | B2B Starting Price | MAUs at Starting Price | |---|---|---|---| | Free | $0/month | $0/month | Up to 25,000 | | Essentials | $35/month | $150/month | 500 MAUs | | Professional | $240/month | $800/month | 500 MAUs | | Enterprise | Contact us | Contact us | Custom | --- ## Free Plan **Free — $0/month** (same for B2C and B2B) No credit card needed to sign up. - Up to 25,000 monthly active users - 1 Custom Domain* - Secure Agentic AI workflows - Passwordless Authentication - Unlimited Social Connections** - 5 Organizations - Brand Customization - Basic Attack Protection - Community Support - 1 Enterprise Connection (NEW) - Self-Service SSO (NEW) - SCIM (NEW) --- ## B2C Pricing ### Plan Highlights **Essentials — from $35/month** - Everything in Free, plus: - Higher Auth, API limits, and feature limits - Pro Multi-Factor Authentication - Role-based Access Control Per Organization - 10 Organizations (How we model your customers) - Stream Auth0 Audit Logs to Datadog, Splunk, AWS, Azure, etc. - Separate Production & Development Environments - Standard Support - Add-ons: Enterprise MFA, Enterprise SSO Connections, M2M Tokens **Professional — from $240/month** - Everything in Essentials, plus: - Enhanced Attack Protection - Use your existing User Database for Logins - Enterprise Multi-Factor Authentication - Add-ons: M2M Tokens **Enterprise — Contact us** - Everything in Professional, plus: - Custom User & SSO Tiers - 99.99% SLA - Enterprise Rate Limits - Enterprise Administration & Support - Add-ons: Advanced Security Features, Private Deployment *Pricing is available only at the listed MAU tiers. If your usage falls between tiers, you are billed at the next tier up.* ### B2C Base Price by MAUs (monthly) | MAUs | Essentials | Professional | |------|-----------|--------------| | 500 | $35 | $240 | | 1,000 | $70 | $240 | | 2,500 | $175 | $545 | | 5,000 | $350 | $1,000 | | 7,500 | $525 | $1,200 | | 10,000 | $700 | $1,600 | | 20,000 | $1,400 | $3,200 | | 30,000 | $2,100 | Contact us | | 40,000 | $2,800 | Not available | | 50,000 | $3,500 | Not available | ### B2C Base Price by MAUs (yearly) | MAUs | Essentials | Professional | |------|-----------|--------------| | 500 | $385 | $2,640 | | 1,000 | $770 | $2,640 | | 2,500 | $1,925 | $5,995 | | 5,000 | $3,850 | $11,000 | | 7,500 | $5,775 | $13,200 | | 10,000 | $7,700 | $17,600 | | 20,000 | $15,400 | $35,200 | | 30,000 | $23,100 | Contact us | | 40,000 | $30,800 | Not available | | 50,000 | $38,500 | Not available | ### B2C Add-ons **Auth0 for AI Agents** - Adds 50% to the base price (rounded up to the dollar) - Unlimited Token Vault - All forms of CIBA *B2C AI Agents Add-On Price by MAUs (monthly)* | MAUs | Essentials | Professional | |------|-----------|--------------| | 500 | $18 | $120 | | 1,000 | $35 | $120 | | 2,500 | $88 | $273 | | 5,000 | $175 | $500 | | 7,500 | $263 | $600 | | 10,000 | $350 | $800 | | 20,000 | $700 | $1,600 | | 30,000 | $1,050 | Contact us | | 40,000 | $1,400 | Not available | | 50,000 | $1,750 | Not available | *B2C AI Agents Add-On Price by MAUs (yearly — 11× monthly)* | MAUs | Essentials | Professional | |------|-----------|--------------| | 500 | $198 | $1,320 | | 1,000 | $385 | $1,320 | | 2,500 | $968 | $3,003 | | 5,000 | $1,925 | $5,500 | | 7,500 | $2,893 | $6,600 | | 10,000 | $3,850 | $8,800 | | 20,000 | $7,700 | $17,600 | | 30,000 | $11,550 | Contact us | | 40,000 | $15,400 | Not available | | 50,000 | $19,250 | Not available | **M2M Token Add-On Tier Pricing** (Professional plan only; 5,000 included) *B2C M2M Token Add-On (monthly)* | M2M Tokens | Price/month | |-----------|-------------| | 5,000 | Included | | 7,500 | $30 | | 10,000 | $40 | | 20,000 | $80 | | 30,000 | $120 | | 40,000 | $160 | | 50,000 | $200 | | 60,000 | $240 | | 70,000 | $280 | | 80,000 | $320 | | 90,000 | $360 | | 100,000 | $400 | | 125,000 | $500 | | 150,000 | $600 | | 175,000 | $700 | | 200,000 | $800 | | 250,000 | $1,000 | | 300,000 | $1,200 | *B2C M2M Token Add-On (yearly — 11× monthly)* | M2M Tokens | Price/year | |-----------|------------| | 5,000 | Included | | 7,500 | $330 | | 10,000 | $440 | | 20,000 | $880 | | 30,000 | $1,320 | | 40,000 | $1,760 | | 50,000 | $2,200 | | 60,000 | $2,640 | | 70,000 | $3,080 | | 80,000 | $3,520 | | 90,000 | $3,960 | | 100,000 | $4,400 | | 125,000 | $5,500 | | 150,000 | $6,600 | | 175,000 | $7,700 | | 200,000 | $8,800 | | 250,000 | $11,000 | | 300,000 | $13,200 | --- ## B2B Pricing ### Plan Highlights **Essentials — from $150/month** - Everything in Free, plus: - Unlimited** Organizations - 3 SSO Enterprise Connections - Role-based Access Control - Higher Auth and API limits - Pro Multi-Factor Authentication - Stream Auth0 Audit Logs - Dev & Prod tenant configuration - Standard Support - Add-ons: Enterprise MFA, Enterprise SSO Connections, M2M Tokens **Professional — from $800/month** - Everything in Essentials, plus: - Enhanced Attack Protection - Use your existing User Database for Logins - Enterprise Multi-Factor Authentication - Custom Token Exchange - Security Center - Additional Enterprise Connections - Add-ons: Enterprise SSO Connections, M2M Tokens **Enterprise — Contact us** - Everything in Professional, plus: - Custom User & SSO Tiers - 99.99% SLA - Enterprise Rate Limits - Enterprise Administration & Support - Add-ons: Advanced Security Features, Private Deployment ### B2B Base Price by MAUs (monthly) | MAUs | Essentials | Professional | |------|-----------|--------------| | 500 | $150 | $800 | | 1,000 | $300 | $800 | | 2,500 | $700 | $1,200 | | 5,000 | $1,300 | $1,500 | | 7,500 | $1,725 | $1,800 | | 10,000 | $2,100 | $2,400 | | 20,000 | $3,800 | Contact us | | 30,000+ | Contact us | Contact us | ### B2B Base Price by MAUs (yearly) | MAUs | Essentials | Professional | |------|-----------|--------------| | 500 | $1,650 | $8,800 | | 1,000 | $3,300 | $8,800 | | 2,500 | $7,700 | $13,200 | | 5,000 | $14,300 | $16,500 | | 7,500 | $18,975 | $19,800 | | 10,000 | $23,100 | $26,400 | | 20,000 | $41,800 | Contact us | | 30,000+ | Contact us | Contact us | ### B2B Add-ons **Auth0 for AI Agents** - Adds 50% to the base price (rounded up to the dollar) - Unlimited Token Vault - All forms of CIBA *B2B AI Agents Add-On Price by MAUs (monthly)* | MAUs | Essentials | Professional | |------|-----------|--------------| | 500 | $75 | $400 | | 1,000 | $150 | $400 | | 2,500 | $350 | $600 | | 5,000 | $650 | $750 | | 7,500 | $863 | $900 | | 10,000 | $1,050 | $1,200 | | 20,000 | $1,900 | Contact us | | 30,000+ | Contact us | Contact us | *B2B AI Agents Add-On Price by MAUs (yearly — 11× monthly)* | MAUs | Essentials | Professional | |------|-----------|--------------| | 500 | $825 | $4,400 | | 1,000 | $1,650 | $4,400 | | 2,500 | $3,850 | $6,600 | | 5,000 | $7,150 | $8,250 | | 7,500 | $9,493 | $9,900 | | 10,000 | $11,550 | $13,200 | | 20,000 | $20,900 | Contact us | | 30,000+ | Contact us | Contact us | **M2M Tokens — Essentials and Professional plan** (Professional plan 5,000 included) *B2B M2M Token Add-On (monthly)* | M2M Tokens | Price/month | |-----------|-------------| | 2,500 | $10 | | 5,000 | $20 | | 7,500 | $30 | | 10,000 | $40 | | 20,000 | $80 | | 30,000 | $120 | | 40,000 | $160 | | 50,000 | $200 | | 60,000 | $240 | | 70,000 | $280 | | 80,000 | $320 | | 90,000 | $360 | | 100,000 | $400 | | 125,000 | $500 | | 150,000 | $600 | | 175,000 | $700 | | 200,000 | $800 | | 250,000 | $1,000 | | 300,000 | $1,200 | *B2B M2M Token Add-On (yearly — 11× monthly)* | M2M Tokens | Price/year | |-----------|------------| | 2,500 | $110 | | 5,000 | $220 | | 7,500 | $330 | | 10,000 | $440 | | 20,000 | $880 | | 30,000 | $1,320 | | 40,000 | $1,760 | | 50,000 | $2,200 | | 60,000 | $2,640 | | 70,000 | $3,080 | | 80,000 | $3,520 | | 90,000 | $3,960 | | 100,000 | $4,400 | | 125,000 | $5,500 | | 150,000 | $6,600 | | 175,000 | $7,700 | | 200,000 | $8,800 | | 250,000 | $11,000 | | 300,000 | $13,200 | **Enterprise SSO Connections** - Essentials: 3 included. $100/month ($1,100/year) per additional connection (max 30 total) - Professional: 5 included. $100/month ($1,100/year) per additional connection (max 30 total) **Enterprise MFA** - Essentials: $100/month ($1,100/year) - Professional: Included --- ## Feature Comparison > ADD-ON = available as paid add-on > * credit card verification required for custom domains > ** subject to system limitations > The Free column is identical for B2C and B2B. ### B2C Feature Comparison #### Authentication | Feature | Free | Essentials | Professional | Enterprise | |---|---|---|---|---| | External Active Users | Up to 25,000 | Custom Tiers | Custom Tiers | Custom Tiers | | Machine-to-Machine Authentication | 1,000 | 1,000 | 5,000 | 5,000 | | M2M Add-on | No | No | Yes | Yes | | Passwordless | Included | Included | Included | Included | | Social Connections | Unlimited** | Unlimited** | Unlimited** | Unlimited** | | Custom Social Connections | Included | Included | Included | Included | | Passkeys | Included | Included | Included | Included | | Auth0 Database Connection | Included | Included | Included | Included | | Custom Database Connections | Not available | Not available | Included | Included | | Cross APP SSO | Not available | Not available | Included | Included | | Enterprise Connections | 1 | Not available | Not available | Custom Tiers | | Inbound SCIM | Included | Included | Included | Included | | Okta Connections | Unlimited** | Unlimited** | Unlimited** | Unlimited** | | Express Configuration | Included | Included | Included | Included | | Organizations | 5 | 10 | 10 | Custom Tiers | | Self-Service SSO | Included | Not available | Not available | Select Enterprise Plans | | M2M Access for Organizations | Not available | Not available | Not available | Select Enterprise Plans | | Home Realm Discovery | Not available | Not available | Not available | Included | | Long Lived Sessions | Not available | Not available | Not available | Included | #### AI | Feature | Free | Essentials | Professional | Enterprise | |---|---|---|---|---| | CIBA | Not available | ADD-ON | ADD-ON | Included + ADD-ON | | Token Vault | 2 | 3 + ADD-ON | 3 + ADD-ON | 4 + ADD-ON | #### Branding | Feature | Free | Essentials | Professional | Enterprise | |---|---|---|---|---| | Configurable Login Experience | Included | Included | Included | Included | | Accessibility | Included | Included | Included | Included | | Custom Domains* | 1 | Included | Included | Included | | Email Workflow | Not available | Included | Included | Included | | Customize Signup & Login | Not available | Included | Included | Included | #### Extensibility | Feature | Free | Essentials | Professional | Enterprise | |---|---|---|---|---| | Actions + Forms | 5 | 10 | 15 | 30 + ADD-ON | | The Actions Library | Included | Included | Included | Included | | [Event Streams](https://auth0.com/docs/customize/events/create-an-event-stream) | 1 | 3 | 4 | 8 | | Marketplace | Included | Included | Included | Included | | Pro Forms | Not available | Not available | Included | Included | #### Security & Compliance | Feature | Free | Essentials | Professional | Enterprise | |---|---|---|---|---| | Brute Force Protection | Included | Included | Included | Included | | Suspicious IP Throttling | Included | Included | Included | Included | | Enhanced Password Protection | Not available | Not available | Included | Included | | Basic Breached Password Detection | Not available | Not available | Included | Included | | Credential Guard | Not available | Not available | Not available | ADD-ON | | Bot Detection | Not available | Not available | Not available | ADD-ON | | Tenant Access Control List (ACL) | Not available | Not available | Not available | 1 + ADD-ON | | Integration with Okta Universal Logout | Included | Included | Included | Included | | Pro MFA Factors | Not available | Included | Included | Included | | Enterprise MFA Factors | Not available | Included | Included | Included | | Adaptive MFA | Not available | Not available | Not available | ADD-ON | | Security Center | Not available | Not available | Included | Included | | Continuous Session Protection | Not available | Not available | Not available | Included | | FAPI certified Security Profile | Not available | Not available | Not available | ADD-ON | | Compliance Certifications | Included | Included | Included | Included | | HIPAA/BAA | Not available | Not available | Not available | ADD-ON | | Prioritized Security Log Streams | Not available | Not available | Not available | Included | | Private Key JWT | Not available | Not available | Not available | Included | | OIDC Back-Channel Logout | Not available | Not available | Not available | Included | #### User Management | Feature | Free | Essentials | Professional | Enterprise | |---|---|---|---|---| | User Import | Included | Included | Included | Included | | Custom Attributes | Included | Included | Included | Included | | Role Management | Not available | Included | Included | Included | | Account Linking | Not available | Included | Included | Included | #### Platform | Feature | Free | Essentials | Professional | Enterprise | |---|---|---|---|---| | Number of Tenants Included | 1 | 3 | 12 | Unlimited** | | Number of Admin/Contributors | 3 | Unlimited** | Unlimited** | Unlimited** | | Admin Access Controls | Admin | Admin and Viewer | Admin, Viewer and Editor | Admin, Viewer and Editor | | Auth0 Dashboard SSO | Not available | Not available | Not available | Included | | Log Retention | 1 Day | 5 Days | 10 Days | 30 Days | | Log Streaming | Not available | 1 Log Stream | 2 Log Streams | 2 Log Streams | | Private Deployment | Not available | Not available | Not available | ADD-ON | | SLA | Not available | Not available | Not available | 99.99% | | Community Support | Included | Included | Included | Included | | Standard Support | Not available | Included | Included | Included | | Premier Support | Not available | Not available | Not available | Premier Success Options | --- ### B2B Feature Comparison #### Authentication | Feature | Free | Essentials | Professional | Enterprise | |---|---|---|---|---| | External Active Users | Up to 25,000 | Custom Tiers | Custom Tiers | Custom Tiers | | Machine-to-Machine Authentication | 1,000 | 1,000 | 5,000 | 5,000 | | M2M Add-on | No | No | Yes | Yes | | Passwordless | Included | Included | Included | Included | | Social Connections | Unlimited** | Unlimited** | Unlimited** | Unlimited** | | Custom Social Connections | Included | Included | Included | Included | | Passkeys | Included | Included | Included | Included | | Auth0 Database Connection | Included | Included | Included | Included | | Custom Database Connections | Not available | Not available | Included | Included | | Cross APP SSO | Not available | Not available | Included | Included | | Enterprise Connections | 1 | 3 + ADD-ON | 5 + ADD-ON | Custom Tiers | | Inbound SCIM | Included | Included | Included | Included | | Okta Connections | Unlimited** | Unlimited** | Unlimited** | Unlimited** | | Express Configuration | Included | Included | Included | Included | | Organizations | 5 | Unlimited** | Unlimited** | Custom Tiers | | Self-Service SSO | Included | Included | Included | Select Enterprise Plans | | M2M Access for Organizations | Not available | Not available | Included | Select Enterprise Plans | | Home Realm Discovery | Not available | Included | Included | Included | | Long Lived Sessions | Not available | Not available | Not available | Included | #### AI | Feature | Free | Essentials | Professional | Enterprise | |---|---|---|---|---| | CIBA | Not available | ADD-ON | ADD-ON | Included + ADD-ON | | Token Vault | 2 | 3 + ADD-ON | 3 + ADD-ON | 4 + ADD-ON | #### Branding | Feature | Free | Essentials | Professional | Enterprise | |---|---|---|---|---| | Configurable Login Experience | Included | Included | Included | Included | | Accessibility | Included | Included | Included | Included | | Custom Domains* | 1 | Included | Included | Included | | Email Workflow | Not available | Included | Included | Included | | Customize Signup & Login | Not available | Included | Included | Included | #### Extensibility | Feature | Free | Essentials | Professional | Enterprise | |---|---|---|---|---| | Actions + Forms | 5 | 10 | 15 | 30 + ADD-ON | | The Actions Library | Included | Included | Included | Included | | [Event Streams](https://auth0.com/docs/customize/events/create-an-event-stream) | 1 | 3 | 4 | 8 | | Marketplace | Included | Included | Included | Included | | Pro Forms | Not available | Not available | Included | Included | #### Security & Compliance | Feature | Free | Essentials | Professional | Enterprise | |---|---|---|---|---| | Brute Force Protection | Included | Included | Included | Included | | Suspicious IP Throttling | Included | Included | Included | Included | | Enhanced Password Protection | Not available | Not available | Included | Included | | Basic Breached Password Detection | Not available | Not available | Included | Included | | Credential Guard | Not available | Not available | Not available | ADD-ON | | Bot Detection | Not available | Not available | Not available | ADD-ON | | Tenant Access Control List (ACL) | Not available | Not available | Not available | 1 + ADD-ON | | Integration with Okta Universal Logout | Included | Included | Included | Included | | Pro MFA Factors | Not available | Included | Included | Included | | Enterprise MFA Factors | Not available | ADD-ON | Included | Included | | Adaptive MFA | Not available | Not available | Not available | ADD-ON | | Security Center | Not available | Not available | Not available | Included | | Continuous Session Protection | Not available | Not available | Not available | Included | | FAPI certified Security Profile | Not available | Not available | Not available | ADD-ON | | Compliance Certifications | Included | Included | Included | Included | | HIPAA/BAA | Not available | Not available | Not available | ADD-ON | | Prioritized Security Log Streams | Not available | Not available | Not available | Included | | Private Key JWT | Not available | Not available | Not available | Included | | OIDC Back-Channel Logout | Not available | Not available | Not available | Included | #### User Management | Feature | Free | Essentials | Professional | Enterprise | |---|---|---|---|---| | User Import | Included | Included | Included | Included | | Custom Attributes | Included | Included | Included | Included | | Role Management | Not available | Included | Included | Included | | Account Linking | Not available | Included | Included | Included | #### Platform | Feature | Free | Essentials | Professional | Enterprise | |---|---|---|---|---| | Number of Tenants Included | 1 | 3 | 12 | Unlimited** | | Number of Admin/Contributors | 3 | Unlimited** | Unlimited** | Unlimited** | | Admin Access Controls | Admin | Admin and Viewer | Admin, Viewer and Editor | Admin, Viewer and Editor | | Auth0 Dashboard SSO | Not available | Not available | Not available | Included | | Log Retention | 1 Day | 5 Days | 10 Days | 30 Days | | Log Streaming | Not available | 1 Log Stream | 2 Log Streams | 2 Log Streams | | Private Deployment | Not available | Not available | Not available | ADD-ON | | SLA | Not available | Not available | Not available | 99.99% | | Community Support | Included | Included | Included | Included | | Standard Support | Not available | Included | Included | Included | | Premier Support | Not available | Not available | Not available | Premier Success Options | --- ## Notes - Yearly billing = 11× the monthly price (equivalent to 1 month free) - * Custom domains require credit card verification - ** Subject to system limitations - Enterprise plan pricing is custom; contact Auth0 sales - The Free plan is identical for B2C and B2B: up to 25,000 MAUs, no credit card required --- # Agent Experience Score > How well AI coding agents integrate Auth0 — measured across real-world tasks, not synthetic benchmarks. **Average without Auth0 tools**: 71% **Average with Auth0 tools**: 98% **Models tested**: 8 (Claude Haiku 4.5, Claude Opus 4.8, Claude Sonnet 5, GPT-5.6 Luna, GPT-5.6 Sol, GPT-5.6 Terra, Gemini 3.1 Pro, Gemini 3.5 Flash) **Frameworks tested**: 13 (Android, Angular, Express, Express API, FastAPI, Fastify API, Flask, Next.js, Nuxt, React, SPA JS, Swift, Vue) **Total configurations**: 104 [Methodology](https://auth0.com/docs/get-started/auth0-agent-experience) ## Scores | # | Model | Framework | Without Tools | With Auth0 Tools | Grade | Cost | Time | |---|-------|-----------|---------------|------------------|-------|------|------| | 1 | GPT-5.6 Luna | React | 100% | 100% | A | $0.17 | 35s | | 2 | GPT-5.6 Terra | React | 100% | 100% | A | $0.33 | 32s | | 3 | Claude Opus 4.8 | SPA JS | 100% | 100% | A | $0.46 | 52s | | 4 | Claude Opus 4.8 | React | 100% | 100% | A | $0.62 | 1m 12s | | 5 | Claude Opus 4.8 | Vue | 100% | 100% | A | $0.63 | 1m 28s | | 6 | Claude Sonnet 5 | Vue | 100% | 100% | A | $0.67 | 2m 1s | | 7 | Gemini 3.1 Pro | React | 100% | 100% | A | $0.72 | 59s | | 8 | Claude Sonnet 5 | Angular | 100% | 100% | A | $0.74 | 2m 25s | | 9 | Gemini 3.1 Pro | Angular | 100% | 100% | A | $0.74 | 1m 16s | | 10 | Gemini 3.5 Flash | Vue | 100% | 100% | A | $0.76 | 1m 46s | | 11 | Gemini 3.1 Pro | Vue | 100% | 100% | A | $0.92 | 1m 14s | | 12 | Gemini 3.5 Flash | SPA JS | 93% | 100% (+7%) | A | $0.43 | 1m 4s | | 13 | Gemini 3.1 Pro | SPA JS | 93% | 100% (+7%) | A | $0.50 | 51s | | 14 | GPT-5.6 Terra | Vue | 92% | 100% (+8%) | A | $0.45 | 36s | | 15 | Gemini 3.5 Flash | Express | 80% | 100% (+20%) | A | $0.39 | 59s | | 16 | Gemini 3.1 Pro | Express API | 80% | 100% (+20%) | A | $0.44 | 55s | | 17 | Claude Opus 4.8 | Next.js | 79% | 100% (+21%) | A | $0.62 | 1m 44s | | 18 | Claude Sonnet 5 | Next.js | 79% | 100% (+21%) | A | $0.91 | 2m 46s | | 19 | GPT-5.6 Terra | Nuxt | 65% | 100% (+35%) | A | $0.36 | 42s | | 20 | Gemini 3.1 Pro | Next.js | 57% | 100% (+43%) | A | $0.95 | 1m 50s | | 21 | Gemini 3.5 Flash | Next.js | 57% | 100% (+43%) | A | $1.39 | 2m 40s | | 22 | Gemini 3.1 Pro | Android | 56% | 100% (+44%) | A | $2.36 | 2m 46s | | 23 | Claude Sonnet 5 | Flask | 50% | 100% (+50%) | A | $0.60 | 1m 46s | | 24 | Claude Sonnet 5 | FastAPI | 43% | 100% (+57%) | A | $0.30 | 47s | | 25 | Gemini 3.1 Pro | FastAPI | 43% | 100% (+57%) | A | $0.39 | 40s | | 26 | Claude Haiku 4.5 | Fastify API | 38% | 100% (+62%) | A | $0.08 | 37s | | 27 | Gemini 3.5 Flash | FastAPI | 36% | 100% (+64%) | A | $0.47 | 1m 14s | | 28 | GPT-5.6 Terra | Flask | 36% | 100% (+64%) | A | $0.57 | 42s | | 29 | Gemini 3.5 Flash | Nuxt | 35% | 100% (+65%) | A | $0.91 | 1m 54s | | 30 | Gemini 3.1 Pro | Fastify API | 31% | 100% (+69%) | A | $0.38 | 44s | | 31 | Gemini 3.1 Pro | Nuxt | 30% | 100% (+70%) | A | $1.66 | 1m 55s | | 32 | Gemini 3.5 Flash | Fastify API | 23% | 100% (+77%) | A | $0.67 | 1m 38s | | 33 | GPT-5.6 Luna | Flask | 21% | 100% (+79%) | A | $0.23 | 58s | | 34 | Gemini 3.1 Pro | Flask | 21% | 100% (+79%) | A | $0.79 | 1m 22s | | 35 | GPT-5.6 Luna | Angular | 100% | 99% (-1%) | A | $0.19 | 45s | | 36 | GPT-5.6 Terra | Angular | 100% | 99% (-1%) | A | $0.44 | 39s | | 37 | Gemini 3.5 Flash | Angular | 100% | 99% (-1%) | A | $0.75 | 1m 39s | | 38 | Gemini 3.5 Flash | React | 100% | 99% (-1%) | A | $0.93 | 1m 47s | | 39 | GPT-5.6 Luna | Next.js | 86% | 99% (+13%) | A | $0.24 | 1m 4s | | 40 | GPT-5.6 Terra | SPA JS | 86% | 99% (+13%) | A | $0.43 | 33s | | 41 | GPT-5.6 Sol | Express API | 80% | 99% (+19%) | A | $1.61 | 1m 12s | | 42 | GPT-5.6 Terra | Next.js | 79% | 99% (+20%) | A | $0.54 | 45s | | 43 | GPT-5.6 Sol | FastAPI | 71% | 99% (+28%) | A | $0.79 | 52s | | 44 | GPT-5.6 Luna | Swift | 70% | 99% (+29%) | A | $0.29 | 1m 2s | | 45 | Claude Sonnet 5 | Android | 67% | 99% (+32%) | A | $0.67 | 2m 12s | | 46 | Claude Haiku 4.5 | Next.js | 57% | 99% (+42%) | A | $0.20 | 1m 39s | | 47 | Gemini 3.5 Flash | Android | 56% | 99% (+43%) | A | $0.64 | 1m 22s | | 48 | Claude Opus 4.8 | Android | 56% | 99% (+43%) | A | $0.85 | 1m 50s | | 49 | Gemini 3.1 Pro | Express | 47% | 99% (+52%) | A | $0.69 | 1m 10s | | 50 | GPT-5.6 Terra | Fastify API | 46% | 99% (+53%) | A | $0.42 | 35s | | 51 | Claude Haiku 4.5 | Android | 33% | 99% (+66%) | A | $0.27 | 1m 43s | | 52 | Gemini 3.5 Flash | Flask | 29% | 99% (+70%) | A | $0.86 | 1m 47s | | 53 | GPT-5.6 Luna | SPA JS | 100% | 98% (-2%) | A | $0.14 | 37s | | 54 | Claude Sonnet 5 | React | 100% | 98% (-2%) | A | $0.47 | 2m 39s | | 55 | GPT-5.6 Sol | Vue | 100% | 98% (-2%) | A | $0.93 | 59s | | 56 | GPT-5.6 Sol | Angular | 100% | 98% (-2%) | A | $1.15 | 1m 20s | | 57 | Claude Haiku 4.5 | Angular | 92% | 98% (+6%) | A | $0.58 | 5m 59s | | 58 | GPT-5.6 Sol | SPA JS | 86% | 98% (+12%) | A | $0.99 | 1m 3s | | 59 | GPT-5.6 Sol | Next.js | 86% | 98% (+12%) | A | $1.07 | 1m 16s | | 60 | GPT-5.6 Terra | Express API | 80% | 98% (+18%) | A | $0.48 | 34s | | 61 | GPT-5.6 Terra | Express | 80% | 98% (+18%) | A | $0.50 | 42s | | 62 | GPT-5.6 Terra | FastAPI | 79% | 98% (+19%) | A | $0.33 | 30s | | 63 | GPT-5.6 Luna | FastAPI | 71% | 98% (+27%) | A | $0.25 | 47s | | 64 | GPT-5.6 Terra | Swift | 70% | 98% (+28%) | A | $0.63 | 49s | | 65 | GPT-5.6 Terra | Android | 67% | 98% (+31%) | A | $1.34 | 1m 11s | | 66 | GPT-5.6 Sol | Fastify API | 62% | 98% (+36%) | A | $1.57 | 58s | | 67 | GPT-5.6 Luna | Android | 44% | 98% (+54%) | A | $0.25 | 50s | | 68 | GPT-5.6 Luna | Fastify API | 31% | 98% (+67%) | A | $0.20 | 47s | | 69 | GPT-5.6 Luna | Nuxt | 30% | 98% (+68%) | A | $0.38 | 1m 2s | | 70 | Claude Haiku 4.5 | React | 100% | 97% (-3%) | A | $0.16 | 1m 2s | | 71 | GPT-5.6 Luna | Vue | 100% | 97% (-3%) | A | $0.18 | 48s | | 72 | GPT-5.6 Sol | React | 100% | 97% (-3%) | A | $1.58 | 1m 2s | | 73 | Claude Haiku 4.5 | SPA JS | 93% | 97% (+4%) | A | $0.13 | 46s | | 74 | Claude Sonnet 5 | SPA JS | 93% | 97% (+4%) | A | $0.44 | 1m 18s | | 75 | GPT-5.6 Luna | Express | 87% | 97% (+10%) | A | $0.30 | 48s | | 76 | GPT-5.6 Sol | Express | 87% | 97% (+10%) | A | $0.80 | 1m 1s | | 77 | Claude Sonnet 5 | Express | 80% | 97% (+17%) | A | $0.47 | 1m 37s | | 78 | Claude Sonnet 5 | Express API | 80% | 97% (+17%) | A | $0.52 | 1m 27s | | 79 | Gemini 3.5 Flash | Express API | 80% | 97% (+17%) | A | $1.07 | 1m 59s | | 80 | GPT-5.6 Sol | Android | 78% | 97% (+19%) | A | $2.41 | 1m 49s | | 81 | GPT-5.6 Luna | Express API | 70% | 97% (+27%) | A | $0.30 | 58s | | 82 | Gemini 3.5 Flash | Swift | 70% | 97% (+27%) | A | $0.62 | 1m 11s | | 83 | Claude Opus 4.8 | Swift | 70% | 97% (+27%) | A | $0.73 | 1m 20s | | 84 | Gemini 3.1 Pro | Swift | 70% | 97% (+27%) | A | $1.11 | 1m 22s | | 85 | GPT-5.6 Sol | Nuxt | 70% | 97% (+27%) | A | $1.95 | 1m 45s | | 86 | Claude Sonnet 5 | Swift | 60% | 97% (+37%) | A | $0.57 | 1m 34s | | 87 | Claude Opus 4.8 | Angular | 100% | 96% (-4%) | A | $0.95 | 2m 4s | | 88 | Claude Opus 4.8 | Express API | 80% | 96% (+16%) | A | $0.57 | 1m 12s | | 89 | Claude Opus 4.8 | Fastify API | 77% | 96% (+19%) | A | $0.47 | 1m 1s | | 90 | Claude Haiku 4.5 | Express | 73% | 96% (+23%) | A | $0.11 | 53s | | 91 | Claude Opus 4.8 | FastAPI | 57% | 96% (+39%) | A | $0.58 | 1m 8s | | 92 | Claude Opus 4.8 | Nuxt | 55% | 96% (+41%) | A | $0.94 | 1m 39s | | 93 | Claude Sonnet 5 | Nuxt | 45% | 96% (+51%) | A | $1.05 | 2m 54s | | 94 | Claude Haiku 4.5 | FastAPI | 43% | 96% (+53%) | A | $0.09 | 37s | | 95 | GPT-5.6 Sol | Flask | 36% | 96% (+60%) | A | $2.11 | 1m 57s | | 96 | Claude Opus 4.8 | Express | 80% | 95% (+15%) | A | $0.55 | 1m 18s | | 97 | Claude Haiku 4.5 | Flask | 43% | 95% (+52%) | A | $0.12 | 56s | | 98 | Claude Haiku 4.5 | Vue | 100% | 94% (-6%) | A | $0.24 | 1m 38s | | 99 | Claude Haiku 4.5 | Swift | 70% | 94% (+24%) | A | $0.16 | 52s | | 100 | GPT-5.6 Sol | Swift | 70% | 92% (+22%) | A | $4.21 | 2m 45s | | 101 | Claude Sonnet 5 | Fastify API | 69% | 92% (+23%) | A | $0.34 | 1m 16s | | 102 | Claude Opus 4.8 | Flask | 29% | 91% (+62%) | A | $0.66 | 1m 21s | | 103 | Claude Haiku 4.5 | Nuxt | 40% | 89% (+49%) | B | $0.48 | 4m 27s | | 104 | Claude Haiku 4.5 | Express API | 60% | 87% (+27%) | B | $0.42 | 4m 11s | ## Methodology ### 1. Real integration tasks We test each model with realistic developer prompts — the kind you'd actually type when building an app. No optimized instructions, no guided walkthroughs. ### 2. Automated grading Every response is scored across multiple dimensions: correct SDK usage, proper configuration, security best practices, and more. Grading is deterministic and reproducible. ### 3. Tool comparison Each model runs twice: once with just its training knowledge (baseline), and once with Auth0's MCP Server and Agent Skills enabled. The delta measures the real-world impact of Auth0's developer platform. ## Developer Tools ### Auth0 MCP Server Connect AI agents directly to Auth0 for real-time tenant management. [Documentation](https://auth0.com/docs/get-started/build-with-ai-tools#auth0-docs-mcp-server) ### Auth0 Agent Skills Pre-built implementation knowledge for AI coding agents. [GitHub Repository](https://github.com/auth0/agent-skills) ## Grade Scale - **A** (90-100%): Production-ready implementation - **B** (75-89%): Good with minor issues - **C** (60-74%): Functional but needs review - **D** (<60%): Significant issues *Last updated: July 2026* --- ## Access Management Platform > Access Management # Developer-friendly access management Seamlessly define access roles for your apps and APIs, and tap into advanced authorization mechanics for more flexible access control. - [Get started](https://auth0.com/signup?type=button&place=platform-hero&text=get%20started) - [Contact us](https://auth0.com/contact-us?type=button&place=platform-hero&text=contact%20us) **API AUTHORIZATION** ## Easily support different authorization flows Elevate your projects in the API ecosystem. Handle authorization using scopes and granular permissions, whether it's for first-party apps, third-party integrations, or Machine-to-Machine communications. ## For developers, by developers Experience a smarter way to manage access. - [Get started](https://auth0.com/signup?type=button&place=platform-cta&text=get%20started) - [Contact us](https://auth0.com/contact-us?type=button&place=platform-cta&text=contact%20us) ## Resources - [Docs: Role-Based Access Control](https://auth0.com/docs/manage-users/access-control/rbac) - [Video: Auth0 Platform Overview](https://auth0.com/resources/videos/platform-introduction-video-2020) - [Introduction: What is OAuth 2.0?](https://auth0.com/intro-to-iam/what-is-oauth-2) ## Frequently asked questions ### Can I manage API permissions in Auth0? Yes, Auth0 allows you to define granular scopes for your APIs, helps ensure that client applications only have the permissions they need. By centralizing API [access management](https://auth0.com/platform/access-management) in Auth0, you can enforce consistent security policies across all your microservices and third-party integrations, simplifying the audit process and reducing the risk of unauthorized data exposure. ### Can I use Auth0 for attribute-based access control (ABAC)? Yes. Auth0’s extensible [platform](https://auth0.com/platform) enables Attribute-Based Access Control (ABAC) through [Auth0 Actions](https://auth0.com/docs/customize/actions/actions-overview), providing the dynamic 'guardrails' needed for autonomous agents. You can write custom logic that evaluates real-time attributes, such as an agent's specific clearance level, the sensitivity of the data being requested via RAG, or whether a 'Human-in-the-Loop' (CIBA) approval has been granted. This moves beyond static roles to provide a context-aware security model that blocks unauthorized agent actions as they happen, effectively bypassing the security bottleneck for high-stakes production environments. ### Does Auth0 support RBAC out of the box? Yes. Auth0 provides native, out-of-the-box support for Role-Based Access Control (RBAC), which serves as the foundational security layer for both human users and the AI applications that act on their behalf. By centralizing RBAC at the Identity Layer, you eliminate the 'Identity Plumbing' tax—the weeks of manual, 'hardcoded' authorization code typically required for agentic workflows. This allows your developers to quickly assign granular API permissions to the client applications powering your agents, helping ensureing they follow the Principle of Least Privilege. By providing this 'Standardized Handshake' out of the box, Auth0 helps you bypass the security bottlenecks that typically stall AI projects in the sandbox, accelerating your move to production. ### Does Auth0 support Role-Based Access Control (RBAC)? Auth0 provides native support for Role-Based Access Control (RBAC), allowing you to easily assign roles (like 'Editor' or 'Admin') to users and map those roles to specific permissions. This logic is managed at the identity layer, which means you don't have to build complex authorization code into your frontend or backend apps, accelerating your development cycle. ### How does Auth0 handle cross-app authorization? Yes. Auth0 enables a connected agent experience by providing a standardized identity 'handshake' across your entire digital portfolio. Instead of writing custom code for every new integration, Auth0 issues help secure digital 'badges' (JWTs) that allow an AI agent to represent a user across different apps, from a chatbot to a checkout page, without hitting authentication walls. By using the [Token Vault](https://auth0.com/features/token-vault) to help securely manage these connections, you eliminate the manual 'identity plumbing' for your developers and provide a clear audit trail for every action the agent takes. ### What is Auth0 Access Management? Yes. Auth0 Access Management is the central identity control plane that allows you to orchestrate the trusted journey of both human users and AI agents. By providing native support for both Role-Based Access Control (RBAC) (the security floor) and Fine-Grained Authorization (FGA) (the document-level ceiling for RAG), we eliminate the manual 'identity plumbing' that typically stalls AI projects. This allows your developers to move your agentic workflows from the sandbox to production faster by providing a clear audit trail and 'human-in-the-loop' safeguards for every high-stakes action. ### How does Auth0 help me get my AI agents past security and compliance reviews faster? By providing an off-the-shelf identity control plane (A4AA), we bypass the security bottleneck. Instead of building custom auth hacks, your developers use our secure-by-design SDKs and Token Vault, which satisfy compliance requirements out of the box ### My developers are already building auth for our agents in LangChain/Vercel. Why do they need Auth0? LangChain and Vercel are world-class frameworks for building and deploying AI logic, but they were not built to be Enterprise Identity Control Planes. By offloading your Identity Orchestration to Auth0, you help ensure that every agentic action is governed by a central, secure-by-design layer. This allows your developers to focus 100% of their sprints on improving the 'AI Brain' while Auth0 handles the complex 'Identity Plumbing' (like FGA and CIBA) that enterprises require for production. ### How do I ensure my AI agent doesn't leak confidential data when it performs a RAG search? By moving security from the ‘AI Brain' to the 'Identity layer' using Auth0 Fine-Grained Authorization (FGA). Traditional security (RBAC) only tells you who a user is, but it isn't granular enough for RAG (Retrieval-Augmented Generation). Auth0 FGA allows you to apply relationship-based access at the individual document level. This helps ensures that when an AI agent performs a search, it only 'sees' and retrieves the specific records that the requesting user is authorized to view at that exact moment. By using Auth0 as your identity anchor, you prevent data leakage and bypass the security bottlenecks that typically stall RAG projects in the sandbox. ### How do I stop an autonomous agent from making a $1M mistake (e.g., an unauthorized bank transfer) \- content this title simply but effectively? By establishing a 'Human-in-the-Loop' safeguard through Auth0 CIBA (Client Initiated Backchannel Authentication). For high-stakes or irreversible actions, such as a $1M bank transfer, your agent shouldn't act alone. With Auth0, you can set a policy that requires explicit human consent before the agent is authorized to execute. The agent 'requests' the action, which triggers a real-time push notification to a verified human's device. No such transaction gets processed without human approval. This moves your AI project from simple 'chat' to 'high-value commerce' by providing the 'kill switch' and verified trust required to move into production safely. --- ## Authentication Platform > Authentication # Customizable authentication for developers Build an authentication experience that meets the needs of their business and resonates with users. - [Get started](https://auth0.com/signup?type=button&place=platform-hero&text=get%20started) - [Contact us](https://auth0.com/contact-us?type=button&place=platform-hero&text=contact%20us) ## Seamless user onboarding Guide users effortlessly across your suite of apps and brands. Customize an intuitive login journey tailored to your audience. ## Single sign-on One login to rule all your apps. Simplify access to your apps and improve security with an SSO solution that’s easy to implement. ## Elevate your authentication game Transform mundane logins into memorable user experiences. - [Try for free](https://auth0.com/signup?type=button&place=platform-cta&text=dive%20in%20now) - [Connect with us](https://auth0.com/contact-us?type=button&place=platform-cta&text=lets%20connect) ## Resources - [Whitepaper: Identity is the perimeter](https://auth0.com/resources/whitepapers/identity-perimeter) - [Blog: Auth0’s Journey Towards a Customizable & Accessible Login Experience](https://auth0.com/blog/auth0s-journey-towards-a-customizable-and-accessible-login-experience/) - [Video: Auth0 Platform Overview](https://auth0.com/resources/videos/platform-introduction-video-2020) ## Frequently asked questions ### What is Auth0 Authentication? Auth0 [Authentication](https://auth0.com/platform/authentication) is a flexible, developer-centric service that [supports a wide range of login methods](https://auth0.com/docs/authenticate/login), including username/password, social IDs, enterprise SSO, email/sms passwordless, biometrics via WebAuthN, and Passkeys. By using the Auth0 Universal Login, some developers can implement secure authentication in minutes, helping ensure that user identity is verified against industry-standard protocols like OpenID Connect and SAML 2.0. ### What is 'Step-up' authentication in Auth0? Step-up authentication is a security pattern where Auth0 challenges a user for an additional factor (like [MFA](https://auth0.com/features/multifactor-authentication)) only when they attempt a sensitive action, such as changing a password or making a large purchase. This helps ensure high-value resources are protected without requiring MFA for every low-risk login, balancing security with user convenience. ### How does Auth0 handle cross-platform login? Auth0 provides a unified authentication experience across web, mobile, and desktop applications. By using standardized JWTs (JSON Web Tokens), Auth0 verifies that a user's identity is recognized seamlessly as they move between different [platforms](https://auth0.com/platform) in your ecosystem, maintaining a secure session and a consistent branded experience throughout. Additionally, Auth0 also supports Native to Web SSO, allowing a seamless user experience transitioning authenticated users from your native app to your web app. ### Can I customize the Auth0 authentication pipeline? Yes, the Auth0 authentication pipeline is highly extensible via Auth0 Actions. Developers can write serverless functions to trigger custom logic—such as verifying a user's age, checking a legacy database, or calling a fraud detection API—during the login process, allowing for a fully tailored security and user experience. Complementary to Actions, [Auth0 Forms](https://auth0.com/docs/customize/forms) enables developers to use a visual editor to build customizable [forms](https://auth0.com/features/forms/) for use cases such as progressive profiling, step-up authentication, and identity verification. ### Does Auth0 support biometric authentication? Yes, Auth0 supports biometric authentication through WebAuthn and Passkeys. This allows users to log into applications using FaceID, TouchID, or Windows Hello. Biometrics provide a phishing-resistant, passwordless experience that is significantly more secure than traditional credentials and offers a frictionless journey for modern mobile and web users. --- ## Extensibility Platform > Extensibility # Unlock deep customization for your identity solution Extend and tailor authentication to fit your business with pro-code to no-code tools that go beyond the out-of-the-box experience. - [Get started](https://auth0.com/signup?type=button&place=platform-hero&text=get%20started) - [Contact us](https://auth0.com/contact-us?type=button&place=platform-hero&text=contact%20us) **ACTIONS** ## Discover the power of Actions Actions are a more secure, tenant-specific, versioned Node.js functions that let you customize your login and identity flows. Use low-code for speed or pro-code for full control. Leverage a drag-and-drop interface, a versatile code environment, built-in version control, robust debugging, and access to over a million npm modules. ## Want to learn more? - [Whitepaper: Identity in the Real World: the Tao of Extensibility](https://auth0.com/resources/whitepapers/tao-of-extensibility) - [Blog: Auth0 Forms Is Now Generally Available!](https://auth0.com/blog/auth0-forms-go-ga/) - [Blog: Supercharge Your B2B Apps with Real-Time Organization Events](https://auth0.com/blog/supercharge-your-b2b-apps-with-real-time-organization-events/) ## Frequently asked questions ### Can I integrate third-party security tools with Auth0? Yes, Auth0 has a series of features that allow the integration with third-party security tools, including fraud detection engines, CRM systems, and analytics platforms. Through Auth0 Actions, Auth0 Marketplace Integrations, Log Streams, and Event Streams, developers can easily connect identity events to specific services like Splunk, Datadog, or custom services, creating a unified identity ecosystem. ### Can I use the Auth0 Marketplace for integrations? Yes, the Auth0 Marketplace offers a wide range of pre-built integrations for the Auth0 [platform](https://auth0.com/platform). These include connectors for identity verification, MFA, consent management, and analytics. By using these verified integrations, developers can add sophisticated features to their login flows in minutes, helping ensure they follow security best practices while reducing custom engineering effort. ### Does Auth0 support custom UI branding? Yes, Auth0 is highly extensible at the UI layer through [Universal Login](https://auth0.com/features/universal-login). Developers can fully customize the look and feel of the login page—including CSS, HTML, and custom domains—to help ensure that the [authentication](https://auth0.com/platform/authentication) experience is a native, branded part of the customer journey, maintaining trust and brand consistency from start to finish. ### How does extensibility help with custom migrations? Auth0’s [extensibility](https://auth0.com/platform/extensibility) is a core advantage for custom user migrations. Using 'Custom Database' scripts, you can more securely migrate users from a legacy system to Auth0 in real-time, without requiring them to reset their passwords. This 'trickle migration' helps ensure a seamless transition for the user while allowing you to modernize your identity infrastructure at your own pace. ### What is the Auth0 Marketplace? The Auth0 Marketplace is a hub for pre-built integrations and serverless functions created by Auth0 and its partners. It allows developers to quickly add sophisticated features—like identity verification, [MFA](https://auth0.com/features/multifactor-authentication), and consent management—to their login flow with minimal coding. This speeds up development and helps ensure that customizations follow industry best practices for security. ### What is the difference between Auth0 Actions and Rules? Auth0 Actions are the modern, serverless evolution of legacy Rules. While Rules were simple JavaScript functions, Actions offer a more robust developer experience with an integrated IDE, version control, and support for the full Node.js ecosystem. Actions are more performant and easier to maintain, making them the recommended way to extend the Auth0 platform. ### What makes the Auth0 platform extensible? The Auth0 platform is highly extensible so customers can customize and set up authentication specific to their unique business requirements. Auth0’s Extensibility provides pro-code to no-code capabilities including Actions, Forms, Event Streams, and Auth0 Marketplace. Actions helps customers build the authentication pipeline and Identity flows using code for use cases like Access Control, API Authorization and more… Forms provides a visual editor for customer identity orchestration, and helps customers build and personalize signup and login flows with no-code editor, used for use cases like custom signup steps, account linking and progressive profiling. Event Streams enables developers to subscribe to completed changes and route those events to a destination of your choice using Webhooks, Amazon EventBridge, or Auth0 Actions, in order to keep data in sync across internal and external systems and trigger business workflows in downstream applications. And Auth0 Marketplace has pre-built partner integrations for customers to leverage no-code templates and integrations for third party integrations. ## Elevate your extensibility game today Kickstart with Actions and redefine your extensibility narrative. - [Get started](https://auth0.com/signup?place=bottom-banner&type=button&text=Get%20started) - [Contact us](https://auth0.com/contact-us?place=bottom-banner&type=button&text=Contact%20us) --- ## Move to Actions Move to Actions # Move to Actions Reduce the amount of custom code and time to build and maintain solutions, by upgrading from Rules and Hooks to Auth0 Actions. - [Migrate from Rules](https://auth0.com/docs/customize/actions/migrate/migrate-from-rules-to-actions) - [Migrate from Hooks](https://auth0.com/docs/customize/actions/migrate/migrate-from-hooks-to-actions) ## Simplify your development experience Auth0 Actions is our next-generation [extensibility](https://auth0.com/platform/extensibility) [platform](https://auth0.com/platform). It offers a more powerful, unified development environment than Rule and Hooks – empowering you to use both pro and no-code options to easily extend and customize Auth0. ### Improved developer experience Actions provides you with integrated version control, debugging, caching, Node18 support, and 2,000,000+ npm modules. [Write Your First Action](https://auth0.com/docs/customize/actions/write-your-first-action) ### Support for multiple flows Actions let you handle multiple flows: [authentication](https://auth0.com/platform/authentication), pre and post user registration, password change, client credential exchange, and phone message sending. [How Auth0 Actions Work](https://auth0.com/docs/customize/actions/actions-overview) ### Options for no-code integrations Actions enables you to leverage no-code integrations directly from the Marketplace, or to build your own integrations with code. [Marketplace](https://marketplace.auth0.com/) ## Feature comparison Deep dive into Auth0's serverless extensibility [features](https://auth0.com/features), and see how Actions improves upon Rules and Hooks with a unified FaaS developer experience. ## Ready to make the move? - [Docs: Migrate from Rules to Actions](https://auth0.com/docs/customize/actions/migrate/migrate-from-rules-to-actions) - [Docs: Migrate from Hooks to Actions](https://auth0.com/docs/customize/actions/migrate/migrate-from-hooks-to-actions) ## Additional resources ### Migrating Auth0 Rules to Auth0 Actions Read our guidelines on how to migrate your existing Auth0 Rules to Auth0 Actions successfully. [Learn more](https://auth0.com/blog/migrating-auth0-rules-to-auth0-actions/) ### Migrating Auth0 Hooks to Auth0 Actions Learn how to migrate your existing Auth0 Hooks to Auth0 Actions successfully. [Learn more](https://auth0.com/blog/migrating-auth0-hooks-to-auth0-actions/) --- ## User Management Platform > User Management # Smooth user management means happy end users From the onboarding to transaction completion, ensure a seamless flow for your end users. - [Get started](https://auth0.com/signup?type=button&place=platform-hero&text=get%20started) - [Talk to us](https://auth0.com/contact-us?type=button&place=platform-hero&text=talk%20to%20us) ## Painless user migration Transferring user databases can be a developer's nightmare. We've simplified the process so you can either do a bulk import or gradually migrate users as they login. ## Enrich user data with progressive profiling Enhance trust, gather data securely, and refine the user journey by gradually getting to know your users on subsequent logins. - [Get started](https://auth0.com/signup?type=button&place=platform-SectionWithCenteredContentAndAsset&text=get%20started) ## Elevate user experiences Hop on for hassle-free user management, and enrich your users experience. - [Get started](https://auth0.com/signup?type=button&place=platform-cta&text=get%20started) - [Contact us](https://auth0.com/contact-us?type=button&place=platform-cta&text=contact%20us) ## Resources - [Whitepaper: User Migration Your Way](https://auth0.com/resources/whitepapers/user-migration-your-way) - [Blog: How To Migrate Users From One Identity System To Another](https://auth0.com/blog/how-to-migrate-users-from-one-identity-system-to-another/) - [Video: Auth0 Platform Overview](https://auth0.com/resources/videos/platform-introduction-video-2020) ## Frequently asked questions ### Can I customize Auth0 user profiles? Yes, Auth0 allows you to store custom [metadata](https://auth0.com/docs/manage-users/user-accounts/metadata) for every user, including 'user\_metadata' for preferences and 'app\_metadata' for security-related data. This flexibility allows you to build personalized user experiences and enforce granular authorization logic based on specific user attributes without needing a separate database. ### Can I search for users via the Auth0 API? Auth0 provides a powerful [User Search](https://auth0.com/docs/manage-users/user-search/user-search-query-syntax) API (v3) that allows you to find users based on email, name, metadata, or last login date. This is essential for helpdesk teams and developers who need to manage users at scale, conduct security audits, or build custom administrative dashboards to support their application's user base. ### Can I store custom metadata in Auth0 user profiles? Yes, Auth0 allows you to store [custom information](https://auth0.com/docs/manage-users/user-accounts/metadata) in 'user\_metadata' (for user-editable preferences) and 'app\_metadata' (for admin-only security data). This eliminates the need for a separate database for basic user settings or roles, allowing you to drive application logic and personalized experiences directly from the identity layer with minimal latency. ### Does Auth0 support bulk user imports? Yes, Auth0 provides robust tools and APIs for [bulk user imports](https://auth0.com/docs/manage-users/user-migration/bulk-user-imports) and migrations. Whether you are moving users from a legacy database or consolidating multiple user stores, Auth0 ensures a secure transition with [features](https://auth0.com/features) like 'trickle migration' that allow users to move over as they log in, preventing the need for a forced password reset. ### Does Auth0 support user account linking? Yes, Auth0 allows you to [link multiple identities](https://auth0.com/docs/manage-users/user-accounts/user-account-linking) to a single user profile. For example, if a user logs in with an email address and later uses Google, Auth0 can link these accounts so they share the same 'user\_id' and metadata. This provides a unified view of the customer across different [authentication](https://auth0.com/platform/authentication) methods, enhancing both security and personalization. ### How do I migrate existing users to Auth0? Auth0 supports '[Trickle Migration](https://auth0.com/docs/manage-users/user-migration/configure-automatic-migration-from-your-database),' which allows you to move users from a legacy database to Auth0 as they log in. This 'lazy migration' method ensures a seamless transition without requiring a bulk password reset. For larger datasets, Auth0 also provides a Bulk User Import API and tools like the 'User Import/Export' extension for high-velocity migrations. ### How does Auth0 handle user search? Auth0 provides a powerful [User Search](https://auth0.com/docs/manage-users/user-search) API that allows developers to find users based on specific criteria, such as email, name, or custom metadata. This is essential for helpdesk teams and administrators who need to quickly locate and manage specific accounts to provide support or conduct security audits. ### Is Auth0 User Management secure? Auth0 User Management is built on a [highly secure, encrypted infrastructure](https://auth0.com/docs/secure/data-privacy-and-compliance) that meets SOC2 and ISO 27001 standards. Every administrative action is logged, and sensitive data is protected by industry-leading encryption. Auth0 also provides '[Dashboard Access' roles](https://auth0.com/docs/get-started/manage-dashboard-access/feature-access-by-role), ensuring that only authorized staff can manage your user data. ### What are the benefits of the Auth0 Normalized User Profile? The [Auth0 Normalized User Profile](https://auth0.com/docs/manage-users/user-accounts/user-profiles/normalized-user-profiles) provides a consistent structure for user data, regardless of the identity provider (Google, GitHub, or Enterprise [SSO](https://auth0.com/features/single-sign-on)) used to log in. This allows developers to write consistent code for personalization and authorization without worrying about the varying data formats returned by different social or enterprise identity sources. ### What is Auth0 User Management? Auth0 [User Management](https://auth0.com/platform/user-management) provides a [centralized dashboard](https://auth0.com/docs/manage-users/user-accounts/manage-users-using-the-dashboard) and API for managing every aspect of the user lifecycle. Developers can easily create, search, and update user profiles, manage roles and permissions, and handle password resets. This 'Identity-as-a-Service' model offloads the administrative burden of user management, allowing teams to focus on core product innovation. --- ## Cloud Deployment Platform > Cloud Deployment # Deploy on private or public cloud Choose a neutral, independent CIAM solution for customizable cloud deployment aligned with your growth strategy. - [AWS](https://auth0.com/platform/cloud-deployment/aws) - [Azure](https://auth0.com/platform/cloud-deployment/azure) ## 99.99% uptime, so you don’t have to stay up worrying Whether it’s a public or [private deployment](https://auth0.com/docs/deploy-monitor/deploy-private-cloud), Auth0 ensures your customers can authenticate into your application with a highly reliable and resilient identity [platform](https://auth0.com/platform). ## Sometimes you want to keep your cloud private The power of Auth0, with the benefits of a managed private instance — deployable on Microsoft Azure or Amazon Web Services. | | Public Cloud Deployment | Private Cloud Deployment | | --- | --- | --- | | Description | Our standard multi-tenant deployment model, used by thousands of customers around the world. | A dedicated instance of Auth0 for enhanced performance, control, and compliance. | | Plan availability | Self Service and Enterprise | Enterprise, with optional add-ons: Geo-Failover PCI Compliance | | Cloud provider | AWS shared tenant | AWS or Microsoft Azure single-tenant | | Deployment regions | United States, United Kingdom, Europe, Australia, Japan, and Canada | Over 60 regions around the world including Canada, UAE, and Singapore | | Environment management | Continuous feature releases and patches automatically applied to customers tenants | Customer controlled, pre-scheduled updates with version control | | Recommended industries | B2B SaaS and Retail | Financial Services, Healthcare, and Public Sector | ## Elevate user experiences Sign up free today. Choose the cloud service provider and deployment option that fits your long-term growth strategy. - [Get started](https://auth0.com/signup?type=button&place=platform-cta&text=get%20started) - [Let’s connect](https://auth0.com/contact-us?type=button&place=platform-cta&text=lets%20connect) ## Resources - [Whitepaper: Auth0 Identity Platform: Private Cloud Deployment](https://auth0.com/resources/whitepapers/private-cloud-deployment) - [Blog: Auth0 guarantees 99.99% availability on Public Cloud](https://auth0.com/blog/auth0-guarantees-99-99-availability-on-public-cloud/) - [Docs: Deploy and Monitor](https://auth0.com/docs/deploy-monitor/deployment-options) --- ## Cloud Deployment - AWS Platform > Cloud Deployment > AWS # The Auth0 Platform on AWS Deploy Auth0's complete customer identity and access management (CIAM) solution on AWS using either public or private cloud. ## Public Cloud Access the Auth0 [Platform](https://auth0.com/platform) as-a-service, backed by a 99.99% uptime SLA, with standard [authentication](https://auth0.com/platform/authentication), personalization, and [user management](https://auth0.com/platform/user-management) [features](https://auth0.com/features). Public Cloud includes a 100 RPS option and supports a time-limited higher capacity burst option, available in the US, UK, EU, Japan, Australia, and Canada. ## Private Cloud Private cloud deployments on AWS deliver complete control over performance, with 10,000 RPS capacity and flexible burst options for time-limited needs. They also have more available regions to deploy to than our Public Cloud offering and are backed by a 99.99% SLA. The higher-performance Private Cloud offerings come with support for non-production environments. ## Resources - [Ebook: Why AWS + Auth0?](https://auth0.com/resources/ebooks/aws-auth0-ebook) - [customers: Explore case studies](https://auth0.com/customers) - [Docs: Deploy and Monitor](https://auth0.com/docs/deploy-monitor) --- ## Cloud Deployment - Azure Platform > Cloud Deployment > Azure # Auth0 Identity Platform on Azure Choose Auth0’s comprehensive CIAM solution with private cloud deployment available across various Azure regions. ## Meet your data residency, compliance and resiliency needs around the world Choose among Azure's 60+ regions to store customer data, and meet your data residency requirements. All service components are deployed in a highly-available, three availability zone (AZ) configuration. ## Resources - [Whitepaper: Unlock long-term growth with Auth0 Identity Platform on Azure](https://auth0.com/resources/whitepapers/unlock-long-term-growth-with-auth0-identity-platform-on-azure) - [Blog: Auth0 Identity Platform Is Now Available on Microsoft Azure](https://auth0.com/blog/auth0-on-microsoft-azure-as-a-private-cloud-deployment-option/) - [Docs: Private Cloud on Azure](https://auth0.com/docs/deploy-monitor/deploy-private-cloud/private-cloud-on-azure) --- ## Actions Features > Actions # Building custom Identity experiences Explore our suite of serverless developer tools to seamlessly extend and enhance your Identity ecosystem. - [Get started](https://auth0.com/signup?type=button&place=features-hero&text=get%20started) - [Read our docs](https://auth0.com/docs/customize/actions) ## Identity is not one-size-fits-all In today's dynamic digital landscape, generic solutions don't make the cut. With Actions, developers get an [extensibility platform](https://auth0.com/platform/extensibility) engineered for flexibility, allowing for adaptation to complex Identity challenges. ## Embrace serverless Say goodbye to the burdens of hosting, performance concerns, and security woes. Rely on our robust infrastructure for storing and executing your code with optimal efficiency and security. ## Forms Build custom signup and login flows to prompt users for additional information and store it as metadata on the Auth0 user profile. ## Ready to dive in? Implement Auth0 Actions to enhance your application's authentication process. - [Try for free](https://auth0.com/signup?type=button&place=features-cta&text=try%20auth0%20today) - [Connect with us](https://auth0.com/contact-us) ## Resources - [Blog: Introducing Auth0 Actions](https://auth0.com/blog/introducing-auth0-actions/) - [Resources: Move to Actions](https://auth0.com/platform/extensibility/movetoactions) - [Blog: Migrating Auth0 Rules to Auth0 Actions](https://auth0.com/blog/migrating-auth0-rules-to-auth0-actions/) ## Frequently asked questions ### Are Auth0 Actions developer-friendly? Auth0 Actions are highly developer-friendly, featuring an in-browser IDE, version control, and support for the full Node.js ecosystem. Developers can test their custom logic in a sandbox environment before deploying it to production, helping ensure that identity customizations are reliable, maintainable, and highly performant for millions of users. Auth0 provides [Actions Types NPM](https://www.npmjs.com/package/@auth0/actions) which allows coding with Actions TypeScript definitions in external IDEs. This in combination with CLI, CI/CD, or API tooling can be used to develop Actions outside of the Auth0 Dashboard. Actions Types NPM also helps AI Agents to understand how Actions objects and interfaces are defined, improving the accuracy of the generated code. [https://auth0.com/docs/customize/actions/actions-overview](https://auth0.com/docs/customize/actions/actions-overview) [https://auth0.com/docs/customize/actions/actions-npm](https://auth0.com/docs/customize/actions/actions-npm) ### Can Auth0 Actions integrate with third-party integrations? Yes, Auth0 Actions supports custom Actions that can be used to integrate with 3rd Party applications or services. In addition, there is also Auth0 Marketplace which provides a series of pre-built integrations with tools like Slack, Segment, and Salesforce. This allows developers to easily connect identity events to the rest of their tech stack, automating security responses and data synchronization without writing custom API integration code from scratch, accelerating time-to-market. [https://auth0.com/docs/customize/actions/use-cases](https://auth0.com/docs/customize/actions/use-cases) ### Can I use Auth0 Actions for fraud detection? Yes, Auth0 Actions can be used to integrate third-party risk engines and fraud detection tools directly into the authentication pipeline. For example, you can write an Action that calls an external service to check a user's IP reputation or verify their identity against a global database, automatically blocking high-risk attempts before the login is completed. [https://auth0.com/docs/customize/actions/use-cases](https://auth0.com/docs/customize/actions/use-cases) ### Do Auth0 Actions support public and private npm packages? Auth0 Actions supports Public NPM packages, but it doesn’t support using Private NPM packages. It also supports Actions Modules which is a way to code, share, and reuse functions between different Actions. [https://auth0.com/docs/customize/actions/manage-dependencies](https://auth0.com/docs/customize/actions/manage-dependencies) [https://auth0.com/docs/customize/actions/modules/actions-modules-overview](https://auth0.com/docs/customize/actions/modules/actions-modules-overview) ### How do Auth0 Actions improve extensibility? Auth0 Actions improve extensibility as a pro-code solution. Users can use custom code to allow variations of workflows outcome based on contextual information. [https://auth0.com/docs/customize/actions/actions-overview](https://auth0.com/docs/customize/actions/actions-overview) [https://auth0.com/docs/customize/actions/use-cases](https://auth0.com/docs/customize/actions/use-cases) ### How do I migrate from Auth0 Rules and Hooks to Actions? Migrating from Rules and Hooks to Actions involves identifying your existing logic and refactoring it into the Actions trigger-based system. Auth0 provides dedicated migration guides and a visual editor to help developers transition their code. [https://auth0.com/docs/customize/actions/migrate](https://auth0.com/docs/customize/actions/migrate) ### What are Auth0 Actions? Auth0 Actions are serverless functions that allow developers to customize and extend the Auth0 platform during the authentication and authorization process. Developers can build custom logic—such as real-time fraud checks, progressive profiling, and step up authentication—directly into the login flow. [https://auth0.com/docs/customize/actions/actions-overview](https://auth0.com/docs/customize/actions/actions-overview) ### How do Auth0 Actions replace legacy Rules and Hooks? Auth0 Actions serve as the modern, Node.js-based successor to legacy Rules and Hooks, offering a more robust and maintainable extensibility model. Actions enable teams to implement complex user data enrichment and security policies with higher performance and easier debugging throughout the identity lifecycle. [https://auth0.com/docs/customize/actions/actions-overview](https://auth0.com/docs/customize/actions/actions-overview) [https://auth0.com/docs/customize/actions/migrate](https://auth0.com/docs/customize/actions/migrate) --- ## Breached Passwords Features > Breached Passwords # Safeguard your user’s digital identities Protect your users' credentials with rigorous checks, proactive alerts, and unmatched security. - [Get started](https://auth0.com/signup?type=button&place=features-hero&text=get%20started) - [Read our docs](https://auth0.com/docs/secure/attack-protection) ## Third-party breaches cast a shadow Data breaches are an everyday reality. Traditional recovery steps spring into action only when the breach surfaces in the public domain. By then, the damage is done. With Auth0, transition from a reactive stance to proactive defense. [Breached Password Detection docs](https://auth0.com/docs/secure/attack-protection/breached-password-detection) ## How Auth0 shields your user’s identities Auth0 helps eliminate the costs associated with account takeovers and protect your users with three simple steps: ## Elevate your security with Credential Guard Harness our extensive database of compromised assets to fortify your defense against large-scale account takeover threats. | | Breached Password Detection | Credential Guard | | --- | --- | --- | | Description | Keep users safe from account hackers using stolen passwords from published security breaches. | Protect high value accounts from takeover attempts by detecting and resetting stolen passwords as soon as possible based on data received from the dark web. | | Plans included | B2B / B2C Professional and Enterprise | Part of Attack Protection add-on in Enterprise plan | | Data collection method | Web scanners and scrapers search for user credentials in published security breaches | Dedicated security team to infiltrate criminal communities and gain access to breach data that isn’t available otherwise | | Typical detection time | Up to 7 - 13 months | 12 - 36 hours | | Recommended use | Self-service accounts, testing scenarios | Enterprise, production environments, high value accounts | | Coverage | English only | 200+ countries and territories | ## Ready to dive in? Protect your users and your business from third-party breach risks with Breached Password Detection and Credential Guard. - [Get started](https://auth0.com/signup?place=header&type=button&text=sign%20up) - [Connect with us](https://auth0.com/contact-us) ## Resources - [Docs: Breached Password Detection](https://auth0.com/docs/secure/attack-protection/breached-password-detection) - [Docs: Attack Protection](https://auth0.com/docs/secure/attack-protection) - [Blog: Auth0 Credential Guard Detects Breached Passwords Faster to Prevent Account Takeover](https://auth0.com/blog/auth0-credential-guard-detects-breached-passwords-faster-to-prevent-account-takeover/) --- ## Forms Features > Forms # Customize signup and login experiences without code Quickly tailor the UI and business logic of your identity flows using a no-code editor. Reduce dev time, improve user onboarding, and launch faster. - [Get started](https://auth0.com/signup?type=button&place=features-hero&text=get%20started) - [Talk to us](https://auth0.com/contact-us?type=button&place=features-hero&text=talk%20to%20us) ## Unlock greater control of your user journeys ## Orchestrate customer experiences Create custom signup and login flows with flexibility and control using a no-code visual editor. ## Simplify user data collection Define business logic to collect user information with ease and enrich user profiles over time with progressive profiling. ## Accelerate time to market Design, adjust, and deploy forms quickly with pre-built templates, debugger mode, and more—without the hassle of coding and maintenance. > "Forms no-code functionality has made building customized user experiences easier, faster and more secure for our teams, and more importantly, helped provide an integrated frictionless experience for our customers." > — Kaitlin Sawyer, Software Engineer, Product Delivery ## Want to learn more? - [Docs: Forms documentation](https://auth0.com/docs/customize/forms) - [Whitepaper: Solve Key Identity Challenges with Extensible CIAM Orchestration](https://auth0.com/resources/whitepapers/solve-key-identity-challenges-with-extensible-ciam-orchestration) - [Demo: Forms end user experience](https://forms.auth0.dev) ## Start your journey with Auth0 Get best-in-class customer identity, with security built in️. - [Try Auth0 for free](https://auth0.com/signup?type=button&place=features-cta&text=Try%20Auth0%20for%20free) - [Talk to sales](https://auth0.com/contact-us?type=button&place=features-cta&text=talk%20to%20sales) --- ## Highly Regulated Identity Features > Highly Regulated Identity # Secure sensitive customer operations Elevate security, privacy, and user experience beyond the login box. Secure your most sensitive customer operations while maintaining compliance and intuitive user experiences. - [Get started](https://auth0.com/signup?type=button&place=highly-regulated-identity-hero&text=get%20started) - [Read our docs](https://auth0.com/docs/secure/highly-regulated-identity) ## Here's how it helps you ## How Highly Regulated Identity can be used Safeguard APIs for sensitive customer operations such as updating account information, admin or security settings, accessing sensitive data or apps, sending money, making an open banking payment, and more. ## Strong Customer Authentication Strong Customer Authentication (SCA) lets users review and approve sensitive operations in real time. Dynamic Linking ties transaction details to the SCA approval confirmation to help prevent transaction tampering. ## Financial grade API protocols A certified FAPI 1 Advanced security profile implementation to ensure data privacy and app security. FAPI protects the end-to-end flow against cyber and fraud risks like transaction tampering. (FAPI is the Financial Grade API working group at the OpenID Foundation). ## Customizable user journeys Here’s when the magic of the Customer Identity Cloud kicks in: customizing is easy. Simply use Actions to run custom policy and adopt new UX templates for the [MFA](https://auth0.com/features/multifactor-authentication) waiting screen and custom consent screen. Easy, right? ## CIBA (Client Initiated Back-channel Authentication) Allows user [authentication](https://auth0.com/platform/authentication) to be initiated by a back-end application instead of the user device. This way, for call center, in-person, online and even IoT-initiated interactions, you can skip the often-forgotten, less secure verification questions. With CIBA, call center agents, for example, can send an authentication request right to your phone, allowing customers to authenticate and authorize the agent to perform an action with just a single tap. ## Customer Managed Keys Some organizations have stricter compliance and audit policies that require them to have complete control over their encryption keys. Customer Managed Keys is our way of tackling this. You can import self-generated keys for encryption and rotate and rekey tenant keys. ## Easy & secure customer interactions See how Highly Regulated Identity simplifies the process for everyone involved. - [Read the datasheet ↗](https://www.okta.com/resources/datasheet-highly-regulated-identity-for-sensitive-operations/) ## Ready to dive in? Implement Auth0 Actions to enhance your application's authentication process. - [Try for free](https://auth0.com/signup?type=button&place=highly-regulated-identity-cta&text=try%20for%20free) - [Connect with us](https://auth0.com/contact-us?type=button&place=highly-regulated-identity-cta&text=connect%20with%20us) --- ## Machine to Machine Features > Machine-to-Machine # Simplify APIs and trusted services communication Bridge the gap between devices and services through secure, automated exchanges. Whether it's IoT or background processes, ensure the integrity of data. - [Get started](https://auth0.com/signup?type=button&place=features-hero&text=get%20started) - [Read our docs](https://auth0.com/docs/customize/actions/flows-and-triggers/machine-to-machine-flow) ## Forge trustworthy bridges for both internal and external APIs Empower your APIs to communicate securely with non-interactive third-party applications. Keep it simple: • Applications authenticate themselves to Auth0 via their Client Id and Client Secret. • Auth0 verifies the information and responds with an Access Token. • Armed with the Access Token, applications can confidently call the API. ## Go beyond human identities with IoT When machines talk, make sure it's secure. Leverage the unique Identity of each IoT device for a streamlined, impenetrable communication setup. ## Seamless API onboarding for non-interactive apps Integrate non-interactive applications like servers, CLIs, daemons, and more into your ecosystem. They might operate in the background, but their security takes the front seat. ## Scopes and granular permissions Chart the course for every client's journey in your API landscape. Grant or restrict access based on granular permissions: • Application Backends • Command line interfaces • Miscellaneous processes ## Security backed by standards Sleep better knowing every byte of data exchanged adheres to globally accepted standards. Dive into the OAuth2 Client Credentials Grant flow, and witness security in motion. ## Frequently asked questions ### Can I limit the scope of M2M tokens in Auth0? Yes, Auth0 allows you to define [coarse-grained scopes](https://auth0.com/docs/get-started/apis/scopes) for every M2M client. Following the principle of least privilege, you can ensure a service only has access to the specific API endpoints it needs (e.g., 'read:reports'). This minimizes the potential impact of a compromised machine identity by limiting what it can do within your ecosystem. ### Does Auth0 support M2M for IoT devices? Yes, Auth0 [M2M authentication](https://auth0.com/docs/get-started/onboarding/self-service-m2m#use-cases) is ideal for securing IoT devices and sensors that need to communicate with back-end APIs. By treating each device as a secure client, Auth0 ensures that data transmitted from the field is authenticated at the source, preventing unauthorized data injection and protecting the integrity of your IoT network and data analytics. ### How does Auth0 manage M2M client secrets? Auth0 manages M2M security by allowing developers to easily [rotate client secrets](https://auth0.com/docs/get-started/applications/rotate-client-secret) and support asymmetric keys for [authentication](https://auth0.com/platform/authentication). This allows security teams to maintain a high security posture without disrupting automated workflows. Auth0 also provides detailed audit logs for every M2M token request, ensuring full visibility into machine-level access and activity. ### What is Auth0 Machine-to-Machine (M2M) authentication? Auth0 [Machine-to-Machine (M2M)](https://auth0.com/docs/get-started/onboarding/self-service-m2m) authentication enables secure communication between non-human identities, such as back-end services, APIs, and CLI tools. By using the OAuth 2.0 Client Credentials flow, Auth0 issues secure, time-bound JWT tokens that allow automated systems to authorize with each other securely, eliminating the need for hard-coded passwords or long-lived secrets. ### Why is M2M security critical for microservices? In a [microservices architecture](https://auth0.com/docs/get-started/architecture-scenarios/server-application-api), M2M security ensures that service-to-service communication is verified and follows least-privilege principles. Auth0 prevents unauthorized lateral movement within your cloud infrastructure by requiring every internal request to present a valid, scoped token, ensuring that even if one service is compromised, the rest of your system remains protected. ### How else can a confidential M2M client authenticate? [Client Secrets](https://auth0.com/docs/secure/application-credentials#client-secret-authentication) are the default way, supported as a symmetrical authentication method. Two additional asymmetric authentication methods include: [Private Key JWT](https://auth0.com/docs/get-started/authentication-and-authorization-flow/authenticate-with-private-key-jwt), use of a pair of public and private keys as credentials, and [mTLS for OAuth](https://auth0.com/docs/get-started/authentication-and-authorization-flow/authenticate-with-mtls), leveraging a standard X.509 client certificate that is registered with Auth0 that is also paired with a corresponding private key. ## Ready to dive in? Unlock the potential of seamless machine-to-machine communications. - [Get started](https://auth0.com/signup?place=header&type=button&text=sign%20up) ## Resources - [Docs: Register Machine-to-Machine Applications](https://auth0.com/docs/get-started/auth0-overview/create-applications/machine-to-machine-apps) - [Developers: Developer Center](https://developer.auth0.com) - [Community: Community Support](https://community.auth0.com) --- ## Multi-Factor Authentication Features > Multi-Factor Authentication (MFA) # Multi-factor auth, without the hassle MFA shouldn’t be a pain. Implement a flexible MFA experience that optimizes security without compromising user experience. - [Get started](https://auth0.com/signup?type=button&place=features-hero&text=get%20started) - [Read our docs](https://auth0.com/docs/secure/multi-factor-authentication) ## Balancing user experience with Adaptive MFA MFA is a proven deterrent against 99.9% of hacking attempts, as [reported by Microsoft](https://www.microsoft.com/en-us/security/blog/2019/08/20/one-simple-action-you-can-take-to-prevent-99-9-percent-of-account-attacks/). However, traditional MFA can be an overkill. Enter Adaptive MFA: Only prompt users when a login seems risky, keeping security robust yet user-friendly. ## Want to learn more? - [Whitepaper: Secure and Seamless User Experience with Auth0’s Adaptive MFA](https://auth0.com/resources/whitepapers/secure-user-experience-adaptive-mfa) - [Docs: Enable Multi-Factor Authentication](https://auth0.com/docs/secure/multi-factor-authentication/enable-mfa) - [Resources: Enable SMS for MFA Using Auth0 and Twilio](https://developer.auth0.com/resources/labs/authentication/enable-mfa-with-sms#introduction) ## Frequently asked questions ### What is Auth0 Multi-Factor Authentication (MFA)? Auth0 MFA is a security layer that requires users to provide two or more verification factors to gain access. It supports various factors including push notifications via Auth0 Guardian, SMS, voice, email, and hardware security keys like YubiKeys, providing a strong defense against stolen credentials. ### Does Auth0 support FIDO2 and Passkeys? Yes, Auth0 MFA supports FIDO2-certified WebAuthn, enabling the use of Passkeys, FaceID, and TouchID. These phishing-resistant methods offer the highest level of security available today while providing a modern, passwordless login experience. ### How does MFA help with regulatory compliance? Auth0 MFA helps organizations satisfy the "Strong Customer [Authentication](https://auth0.com/platform/authentication)" (SCA) requirements of PSD2, as well as HIPAA and CJIS mandates. By enforcing multi-factor security, organizations demonstrate a high standard of data protection, reducing legal and financial risk. ### What is Adaptive MFA in Auth0? Adaptive MFA uses machine learning to analyze the risk of every login attempt based on context (location, device, IP). If a login appears suspicious, Auth0 automatically triggers an MFA challenge; for low-risk, recognized logins, it stays out of the user's way to minimize friction. ## Start your journey with Auth0 Get best-in-class customer identity, with security built in️. - [Try Auth0 for free](https://auth0.com/signup?type=button&place=features-cta&text=get%20started) - [Talk to sales](https://auth0.com/contact-us?place=hero&type=button&text=talk%20to%20sales) --- ## Passwordless Features > Passwordless # Passwordless Authentication = one of the fastest ways to login Go passwordless and give users a faster, more secure way to log in. Your security teams will thank you. - [Get started](https://auth0.com/signup?type=button&place=features-hero&text=get%20started) - [Read our docs](https://auth0.com/docs/authenticate/passwordless) ## The best password is no password More than two-thirds of users still recycle passwords across accounts. Free your users from post-it note passwords by giving them a more secure, easy way to login. ## Embrace a passwordless world with passkeys No more forgotten passwords or reset loops. Devices and apps can easily spot if a passkey exists for seamless [authentication](https://auth0.com/platform/authentication). With passkeys, your credentials are securely stored and synced in the cloud, ensuring you can easily move between devices. ## Meet users where they are with Social Login No need to create new accounts. Let users sign in with social credentials for a frictionless user experience. - [Explore Social Login](https://auth0.com/docs/authenticate/passwordless#social-login) ## Make your login flow seamless with Passwordless Elevate user experience with passwordless. Why force users to remember complex passwords? Offer them an authentication journey that’s both secure and password-free. - [Try it now ↗](https://auth0.com/signup) ## Go passwordless today Get hands-on with tools and guides crafted for developers, helping you maximize the potential of passwordless authentication. - [Try for free](https://auth0.com/signup?type=button&place=features-cta&text=get%20started) - [Connect with us](https://auth0.com/contact-us) ## Resources - [Blog: What is Passwordless Authentication](https://auth0.com/blog/what-is-passwordless-authentication/) - [Whitepaper: 7 Things You Need to Know About Passwordless Authentication](https://auth0.com/resources/whitepapers/passwordless-authentication) - [Tool: WebAuthn.me](https://webauthn.me/) ## Frequently asked questions ### What is Auth0 Passwordless authentication? Auth0 [Passwordless authentication](https://auth0.com/docs/authenticate/passwordless) is one of the fastest ways to login. Passwordless authentication provides users with a seamless and more secure login experience. As technology advances, traditional methods of authentication, such as usernames and passwords, become more prone to cyber attacks (like phishing or keylogging) and potential breaches. With passwordless authentication, users no longer need to remember or manually enter a password to access an application. Instead, they can use a variety of authentication methods that rely on time-based access links and tokens, stored passkeys, biometrics, or social accounts. ### What are the types of Passwordless Authentication? [Types of Passwordless Authentication:](https://auth0.com/blog/what-is-passwordless-authentication/) **Biometrics:** Biometric authentication uses unique physical traits to verify if a person is who they say they are, without requesting a password. **Magic Links:** This form of passwordless authentication asks a user to enter their email address into the login box. An email is then sent to them, with a link they can click to log in. This process is repeated each time the user logs in. **One-Time Passwords/Codes:** One-time passwords (OTP) or one-time codes (OTC) require users to input a code that you send them (via email or to their mobile device via SMS) instead of clicking a link. This process is repeated each time a user logs in. **Push Notifications:** Users receive a push notification on their mobile devices through a dedicated authenticator app (for example, Google Authenticator) and open the app through a push notification to verify their identity. ### Does Auth0 support Passkeys? Yes, [Auth0 Passkeys](https://auth0.com/docs/authenticate/database-connections/passkeys) are a phishing-resistant alternative to traditional authentication factors (such as identifier/password) that offer an easier and more secure login experience to users. Passkeys are modeled from FIDO® W3C Web Authentication (WebAuthn) and Client to Authenticator Protocol (CTAP) [specifications](https://fidoalliance.org/specs/fido-v2.1-ps-20210615/fido-client-to-authenticator-protocol-v2.1-ps-errata-20220621.html#intro). ### How does Passwordless improve security? Passwordless authentication improves security by eliminating the most common point of failure: the user-created password. By eliminating the reliance on passwords and other memorized codes, you can provide users with a more convenient way of accessing applications while also reducing the likelihood of data breaches due to stolen or weak passwords. Auth0 helps ensure that authentication is tied to a verified device or communication channel, providing high-assurance identity verification. ### Is Passwordless login better for user conversion? Passwordless authentication can significantly boost user conversion and retention by delivering a smoother, more secure login experience with less friction. By eliminating traditional passwords and letting users sign in via a simple link, code, or biometric method, you reduce common login obstacles like forgotten passwords and “login fatigue.” This results in a more seamless onboarding process that’s especially beneficial for mobile and consumer‑focused applications. ### What are the benefits of Passwordless? **Reduce friction and improve user experience:** Passwords are a point of friction for consumers. Using Passwordless Authentication increases conversion rates. **Reduce security breaches:** Passwords are the most common cause of security breaches.Passwordless authentication improves an organization's security posture. **Reduce overhead:** Going passwordless removes the need for manual password resets by IT and support teams saving time, resources and money. ### What is the business value of Passwordless Authentication? The average person has 100 passwords to remember and spends 12.6 minutes of every week resetting them (often through a call to a help desk). This ends up costing your organization more money in password resets and customer service time than you think. For example, although the industry standard is $70 per reset, Auth0 customers report up to $120 per reset, even before they’ve called the helpdesk. Implementing passwordless authentication, however, can help reduce or eliminate those costs since your users will be able to log in without a password. This also eliminates the need to store and maintain those password databases. https://auth0.com/blog/what-is-passwordless-authentication/ ### Can I use Passwordless and traditional login together? Yes, Auth0 allows you to offer Passwordless as an option alongside traditional username and password login. This 'hybrid' approach allows you to transition your user base toward a more secure passwordless future at your own pace, providing flexibility for users who prefer different authentication methods while still increasing your overall security posture. --- ## Single Sign-On Features > Single Sign-On # Streamline access with SSO Enable users to access all your applications and services with SSO, while delivering a fast, seamless experience. - [Get started](https://auth0.com/signup?type=button&place=features-hero&text=get%20started) - [Read our docs](https://auth0.com/docs/authenticate/single-sign-on) ## One secure login, across every app Our developer-friendly SSO platform makes it easy to connect users across enterprise, social, and custom apps. ## Implement and launch faster In-house-built SSO slows you down. Auth0 helps organizations integrate SSO in a matter of days. ## SSO for B2B and B2C applications ## Unlock growth: SSO for enterprises Trusted by some of the world's largest enterprises, our SSO seamlessly integrates with your AD/LDAP directories to simplify access and accelerate productivity. ## Make it seamless for your customers A clunky login can be a customer's first and last impression. Use SSO to create a single, satisfying journey across all your apps that delights users from the very start. ## Want to learn more? - [Docs: Auth0 Documentation](https://auth0.com/docs/authenticate/single-sign-on) - [Report: Customer Identity Trends Report 2025](https://auth0.com/customer-identity-trends-report) - [WHITEPAPER: The developer’s guide to single sign-on (SSO)](https://auth0.com/resources/whitepapers/auth0-guide-to-single-sign-on-sso) ## Frequently asked questions ### Can I implement SSO between different domains? Yes, Auth0 supports [SSO](https://auth0.com/features/single-sign-on) between multiple apps with different domains by using its centralized [authentication](https://auth0.com/platform/authentication) experience, the [Universal Login](https://auth0.com/features/universal-login/), to handle the entire login flow for your applications. When a user logs in on one application with a unique domain, Auth0 establishes a single session that can be recognized by apps on other domains. This is ideal for companies with multiple sub-brands or a suite of products hosted on various top-level domains. ### Does Auth0 support SSO for mobile apps? Yes, Auth0 provides SDKs for iOS and Android that support SSO through a more secure browser-based authentication. By sharing the session cookie between the system browser and your native applications, users can enjoy a seamless 'one-tap' login experience across your entire mobile and web presence, maintaining brand consistency and high security across platforms. ### Does Auth0 support Native to Web SSO? Yes, Auth0 supports this [feature](https://auth0.com/docs/authenticate/single-sign-on/native-to-web) natively in the [platform](https://auth0.com/platform). It offers end users a seamless experience that transitions authenticated users from your native application to your web application. ### How does SSO improve security? SSO improves security by reducing the 'attack surface' for credentials. Since users only need to remember one set of credentials, they are less likely to use weak passwords or write them down. Furthermore, SSO makes it easier for IT teams to enforce strong [Multi-Factor Authentication (MFA)](https://auth0.com/features/multifactor-authentication) at a single central point, ensuring that all connected applications are protected by the same high-assurance standard. ### What is Auth0 Single Sign-On (SSO)? Auth0 Single Sign-On (SSO) allows a user to authenticate once and gain access to multiple applications within your ecosystem without being prompted for credentials again. By setting a secure cookie at the central Auth0 domain, the platform can 'silently' authenticate the user as they move between your web, mobile, and legacy apps, significantly reducing login friction and password fatigue. ### What is Single Logout (SLO) in Auth0? Single Logout (SLO) helps ensure that when a user logs out of one application, their session is terminated across all other applications in the SSO circle. Auth0 handles this by clearing the central session cookie and notifying connected apps to invalidate their local sessions. This is a critical security feature for shared computers or highly sensitive enterprise environments.URL ## Start your journey with Auth0 Get best-in-class customer identity, with security built in️. - [Get started](https://auth0.com/signup?type=button&place=features-cta&text=get%20started) - [Talk to sales](https://auth0.com/contact-us?place=features-cta&type=button&text=talk%20to%20sales) --- ## Token Vault Token Vault # Connect AI agents to apps and APIs Token Vault integrates your apps and AI agents with third-party tools. It handles access and refresh tokens automatically, so you don’t have to. - [Get started](https://auth0.com/signup?onboard_app=auth_for_aa&ocid=701KZ000000cXXxYAM-aPA4z0000008OZeGAM) - [Read our docs](https://auth0.com/ai/docs/intro/overview) ## AI agents, meet external tools Build an AI agent that can book flights, respond to emails, and get stuff done. ## Integrations Empower agents to search your Gmail inbox, create a GitHub pull request, build a Spotify playlist, or leverage one of our 30+ integrations to do even more. - [Explore all integrations](https://auth0.com/ai/docs/integrations/overview) ## Start building with your favorite framework - LangChain - LlamaIndex - Cloudflare Agents - AI SDK by Vercel - Firebase Genkit ## Trusted by developers > "Removing sensitive values (like keys/secrets) from code is essential. The next-level unlock is then being able to dynamically exchange an inert variable for the real key. The ability for Token Vault to handle this with such a seamless DX makes it a no brainer for those building AI Agents that talk to authorized integrations. Really incredible work by the Auth0 team." > — Sean Roberts, VP of Applied AI > "When building agentic applications with LlamaIndex, building a capable agent is only the first step: you have to make sure it's safe and secure before you can ship it. Auth0 is the industry leader in tackling this problem and we're delighted to integrate with them." > — Murtaza Khomusi, Head of Product Marketing ## See it in action Watch the demo to see how Token Vault works in practice. Want more details? - [Check out the code](https://github.com/auth0-samples/auth0-assistant0) ## Frequently asked questions ### What is the Auth0 Token Vault? The [Auth0 Token Vault](https://auth0.com/docs/secure/call-apis-on-users-behalf/token-vault) is a security feature that manages and protects third-party API tokens used by AI agents on behalf of users. It stores, retrieves, and automatically refreshes OAuth 2.0 tokens for external services (such as Google, GitHub, Salesforce, etc.), verifying that sensitive credentials are not exposed to AI agents or client-side code. This significantly reduces the risk of token theft and unauthorized API access in modern agentic architectures. ### What problem does Token Vault solve for AI agents? AI agents often need to perform actions across multiple third-party services on a user's behalf, such as reading emails, creating calendar events, or updating CRM records. Without Token Vault, developers would need to manage token storage, refresh logic, and secure access themselves, risking token leakage to the agent or insecure storage. Token Vault solves this by providing a dedicated, secure layer that manages the full token lifecycle, allowing agents to [request API access](https://auth0.com/docs/secure/call-apis-on-users-behalf/token-vault/access-token-exchange-with-token-vault) at runtime without possessing or seeing raw user credentials. ### How does the user workflow for connecting a third-party service or application work? [AI agent applications direct the user to Auth0 to authenticate with a third-party service](https://auth0.com/docs/secure/call-apis-on-users-behalf/token-vault/connected-accounts-for-token-vault) (e.g., Google) via a standard OAuth 2.0 consent flow. Once the user grants consent, Auth0 stores the resulting refresh token in Token Vault. When an AI agent or application needs to call that third-party API on the user's behalf, it requests a valid access token from Token Vault using a more secure, scoped API call. Token Vault uses the refresh token to request a short-lived access token and returns it to the agent to make the API call. The user only authenticates once, and Token Vault manages ongoing access. ### What are Integrations in the context of Token Vault? Integrations are pre-configured connections to third-party services (such as Google, GitHub, Slack, Salesforce, and LinkedIn) that define how Auth0 [authenticates](https://auth0.com/platform/authentication) with those services on behalf of a user. Each integration specifies the OAuth 2.0 provider details, required scopes, and credentials. Auth0 provides a catalog of [supported integrations](https://auth0.com/ai/docs/integrations/overview) that can be set up through the Auth0 dashboard, making it straightforward to connect new external services to your application or agent without writing custom OAuth plumbing. ### How does Token Vault secure AI agents? Auth0 Token Vault helps secure AI agents by acting as a 'broker' for API calls. Instead of the AI agent holding a long-lived secret, it requests a short-lived token from the vault to perform specific tasks. This limits the blast radius if an agent is compromised and provides a clear audit trail of which agent accessed which external service and when. ### Can I audit token usage in the Vault? The Auth0 Token Vault provides comprehensive logging and auditing for every token retrieval event. Security teams can monitor which applications or agents are calling specific APIs, identifying unusual patterns that might indicate a breach or misuse. This visibility is essential for maintaining compliance in highly regulated AI and data-driven environments. ### Is Token Vault compatible with any service or application? Auth0 Token Vault is designed to be highly flexible, supporting any third-party service that uses standard OAuth 2.0 authentication flows. Auth0 provides a growing catalog of pre-built integrations for popular services and allows configuring [custom integrations for other OAuth 2.0-compatible providers](https://auth0.com/ai/docs/integrations/oauth2). This allows developers to secure a wide range of integrations under a single, unified security and identity framework managed by Auth0. ## Auth0 for AI Agents Enable AI agents to more securely access tools, workflows, and data with fine-grained control and just a few lines of code. - [Get started](https://auth0.com/signup?onboard_app=auth_for_aa&ocid=701KZ000000cXXxYAM-aPA4z0000008OZeGAM) - [Read our docs](https://auth0.com/ai/docs/intro/overview)