Who Auth0 is
Auth0 is a customer identity platform founded in 2013 and part of Okta since 2021, where it is sold as the Auth0 Platform. It gives web and mobile apps sign-up and sign-in with passwords, social accounts, passwordless codes and enterprise connections, multi-factor authentication, and protection against attacks on login.
Teams building apps for consumers and businesses use it to get sign-in right without building it themselves, and it ships an official Flutter SDK, the toolkit our mobile apps are built with. That is why it is one of the identity providers our authentication module connects to.
What it does in your platform
Authentication
Runs customer sign-up and sign-in behind the module, on Auth0's Universal Login: passwords, social accounts, passwordless codes and multi-factor. Auth0 decides who the customer is; the module keeps their trusted devices, sessions and the second factor on payments.
How the connection works
The module talks to Auth0 over OpenID Connect, and our Flutter apps open Auth0's sign-in through its official Flutter SDK. Auth0 holds the customer accounts, so the platform stores no passwords.
A customer signs up
The app opens Auth0's Universal Login, in your brand, with the sign-in methods you chose for that market.
Auth0 checks the attempt
Attack protection watches every login: bot detection, brute-force protection, suspicious IP throttling and breached password detection.
Tokens reach the app
Auth0 returns signed tokens through the SDK. The module checks them and opens a session tied to the customer's device.
A payment asks for more
Confirming a transfer or a card payment asks for the second factor strong customer authentication requires, on top of the Auth0 session.
Logs stream back
An Auth0 log stream posts login events to the platform, so failed attempts and blocked logins show up in the backoffice next to the customer.
Next to other providers
Auth0 can sign in your customers while staff use your company directory, such as Okta, Microsoft Entra ID or Google Workspace, through the backoffice's single sign-on. Each side keeps its provider, and roles, sessions and the audit log stay on the platform.
Because the module speaks OpenID Connect rather than Auth0's own interfaces, moving to another provider later does not change your apps. Your customers' sessions, devices and sign-in history stay in the platform.
When Auth0 fits best
A strong fit when
- You want customer sign-in as a managed service, with no identity server of your own to run.
- You need passwords, social accounts, passwordless codes and multi-factor for customers in one place.
- You want Auth0's attack protection in front of every login.
Also worth a look
- AWS Cognito or Firebase Authentication, when the rest of your stack already runs on AWS or Google.
- Keycloak, when customer identity has to stay on your own infrastructure.
How we get you live
The contract
We help you get your Auth0 account and contract in place, set up for your markets and your apps.
The sign-in
We set up Universal Login with you: your brand, the sign-in methods per market, the multi-factor rules and attack protection.
The keys
Client secrets and the log stream token go into your platform's secrets and nowhere else. The apps only carry their public client identifiers.
A full test run
We test sign-up, sign-in, a blocked attack and a confirmed payment in a separate Auth0 tenant before your first real customer.
