Skip to content
PlainID
← Back to all integrations
Auth0 logo

Auth0

Use Auth0 identity context and enrich its tokens to drive fine-grained access decisions.

About PlainID + Auth0

The integration of PlainID with Auth0 allows organizations to implement a seamless Authentication-Authorization process. Auth0, being an IdP (Identity Provider), primarily handles the Authentication process using established protocols like OIDC and SAML, resulting in an authentication token. The PlainID Auth0 Authorizer complements Auth0's authentication process by calculating and generating a dynamic list of claims and groups based on PlainID's policies. These claims and groups enrich the token generated by Auth0, providing the user with adaptive access they are entitled to.
The token enrichment flow is aimed at contextually and dynamically calculating and providing a list of Authorizations (claims) to Auth0 during the login process. The outcome is a continuous and adaptive Authorization process that grants users access based on their changing roles and responsibilities within an organization. The PlainID Auth0 Authorizer bridges the gap between Authentication and Authorization, providing a comprehensive solution for organizations to manage user access

Technical Information

The PlainID Auth0 Authorizer allows enriching Auth0's JWT as part of the login process. This is done by utilizing Auth0’s webhook to obtain the relevant claims for the authenticating user from PlainID’s PDP. The PlainID Cloud-Based PDP, and the Hybrid, customer-hosted PlainID Policy Authorization Agent support the Token Enrichment functionality.

Architectures

  1. User logins to the application.
  2. The app initiates an authentication process (SSO) with Auth0.
  3. As part of the authentication process, Auth0 sends a request to PlainID Authorizer via a webhook interface for authorization claims.
  4. The PDP dynamically calculates the access decision.
    If needed the Policy Information Point (PIP) pulls additional user or asset attributes from various data sources to calculate the access decision.PlainID Authorizer returns the access decisions containing claims to be used for enriching the access token minted by Auth0.
  5. Auth0 provides the app with an access token containing the dynamically calculated access decision.

Technology

  • Identity Providers

Capabilities

  • Manage
  • Enforce

Auth Patterns

  • Token Enrichment
  • Policy information point (PIP)

Need help integrating?

Our experts can help you architect the perfect authorization strategy for your stack.

Contact Support

Better Together

Connect Context. Centralize Policy. Enforce Everywhere.