{
    "componentChunkName": "component---src-pages-blog-markdown-remark-fields-slug-js",
    "path": "/blog/auth0-sso",
    "result": {"data":{"markdownRemark":{"html":"<p>Authentication is a critical component of modern applications, and <a href=\"https://www.codecontent.net/blog/what-is-sso\" target=\"_blank\" rel=\"nofollow\">Single Sign-On(SSO)</a> has\nbecome an essential feature for businesses looking to streamline user access across multiple applications. <a href=\"https://auth0.com/\" target=\"_blank\" rel=\"nofollow\">Auth0</a>, a widely adopted authentication platform, offers robust SSO capabilities—but is it the right solution for your specific needs?</p>\n<p>This guide walks you through implementing Auth0 SSO, highlights its limitations, and introduces SuperTokens as a flexible alternative that\ngives developers more control over their authentication flows.</p>\n<h2 id=\"what-is-auth0-sso-and-how-does-it-work\" style=\"position:relative;\"><a href=\"#what-is-auth0-sso-and-how-does-it-work\" aria-label=\"what is auth0 sso and how does it work permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a><strong>What Is Auth0 SSO and How Does It Work?</strong></h2>\n<p>Single Sign-On (SSO) allows users to authenticate once and access multiple applications, instead of having to log in separately for each one. Auth0 provides SSO functionality through its centralized identity platform, serving as a broker between your applications and various identity providers.</p>\n<p><span\n      class=\"gatsby-resp-image-wrapper\"\n      style=\"position: relative; display: block; margin-left: auto; margin-right: auto; max-width: 630px; \"\n    >\n      <a\n    class=\"gatsby-resp-image-link\"\n    href=\"/static/e6f78b05ed44ea68ed658211597b562e/2aa89/What-Is-Auth0-SSO.png\"\n    style=\"display: block\"\n    target=\"_blank\"\n    rel=\"noopener\"\n  >\n    <span\n    class=\"gatsby-resp-image-background-image\"\n    style=\"padding-bottom: 47.46835443037975%; position: relative; bottom: 0; left: 0; background-image: url('data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAJCAYAAAAywQxIAAAACXBIWXMAAAsTAAALEwEAmpwYAAABcklEQVQoz62PS27jMBBEfQJb/FMUKZIiLVuy5EmASXL/i1UHFJDNwIPZzKLQvXh43XViRhEPPVQN6JeEsGZMa8JtjdgfCe/biN9bwNc24Gvt8XHTeM8ce7hg8xc8fIf7wFAdQ7SMTkwKMKublER0VN9W2j7faP94UpxHinWgqQ5USk8lG8pe0OMa6PPXnW7JkVcX8pqR04ysZDh1nFGTKtdDewc/JaRbQZoLXBzgRgfrDYxT8N7C9RoxOJQ8IjgLqyV6oyAFB2cdnbquIy44lNYw1kJHj2V7INSMdC2IKUJqBakkjNawxkBLCSUE7DiglILBOXDO0Vwnxhidz2cs9wVTmSBGh+fzechCTgghQErZYOzbhnFKmOaCaa4wOSDnDPdKuC4r6vUKMfbY/yJsh2KZUO8z6jK/Fh6VOYdSCrrVjh7bviHWCSFHBB8ghDjSGKMNtNLQSsFGj/RKyBg74D/TPmuzwY3R/2B+Kh/L/0hzfQOV3uk/c0+q0gAAAABJRU5ErkJggg=='); background-size: cover; display: block;\"\n  ></span>\n  <img\n        class=\"gatsby-resp-image-image\"\n        alt=\"What Is Auth0 SSO\"\n        title=\"What Is Auth0 SSO\"\n        src=\"/static/e6f78b05ed44ea68ed658211597b562e/f058b/What-Is-Auth0-SSO.png\"\n        srcset=\"/static/e6f78b05ed44ea68ed658211597b562e/c26ae/What-Is-Auth0-SSO.png 158w,\n/static/e6f78b05ed44ea68ed658211597b562e/6bdcf/What-Is-Auth0-SSO.png 315w,\n/static/e6f78b05ed44ea68ed658211597b562e/f058b/What-Is-Auth0-SSO.png 630w,\n/static/e6f78b05ed44ea68ed658211597b562e/40601/What-Is-Auth0-SSO.png 945w,\n/static/e6f78b05ed44ea68ed658211597b562e/78612/What-Is-Auth0-SSO.png 1260w,\n/static/e6f78b05ed44ea68ed658211597b562e/2aa89/What-Is-Auth0-SSO.png 1698w\"\n        sizes=\"(max-width: 630px) 100vw, 630px\"\n        style=\"width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0;\"\n        loading=\"lazy\"\n        decoding=\"async\"\n      />\n  </a>\n    </span></p>\n<h3 id=\"definition\" style=\"position:relative;\"><a href=\"#definition\" aria-label=\"definition permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a><strong>Definition</strong></h3>\n<p><a href=\"https://auth0.com/docs/authenticate/single-sign-on\" target=\"_blank\" rel=\"nofollow\">Auth0 SSO</a> works by centralizing user authentication across multiple applications.\nWhen a user logs into one application, Auth0 establishes a session that other connected applications can recognize, thus eliminating the need for repeated logins. This improves user experience while maintaining robust security standards.</p>\n<h3 id=\"supported-protocols\" style=\"position:relative;\"><a href=\"#supported-protocols\" aria-label=\"supported protocols permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a><strong>Supported Protocols</strong></h3>\n<p>Auth0 supports all major SSO protocols, giving you flexibility in how you implement authentication:</p>\n<ul>\n<li>\n<p><strong>SAML (Security Assertion Markup Language)</strong>: An XML-based protocol commonly used in enterprise environments, SAML allows secure exchange of authentication and authorization data between an identity provider and a service provider.</p>\n</li>\n<li>\n<p><strong>OpenID Connect (OIDC)</strong>: Built on top of OAuth 2.0, OIDC adds an identity layer that allows clients to verify the identity of end-users and obtain basic profile information.</p>\n</li>\n<li>\n<p><strong>OAuth 2.0</strong>: While not strictly an SSO protocol, OAuth 2.0 serves as the foundation for modern authentication flows, to enable secure delegation of access without sharing credentials.</p>\n</li>\n</ul>\n<h3 id=\"identity-provider-idp-setup\" style=\"position:relative;\"><a href=\"#identity-provider-idp-setup\" aria-label=\"identity provider idp setup permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a><strong>Identity Provider (IdP) Setup</strong></h3>\n<p>Auth0 functions as an identity broker that can connect to various enterprise identity providers:</p>\n<ul>\n<li>\n<p><a href=\"https://www.okta.com/\" target=\"_blank\" rel=\"nofollow\">Okta</a>: Auth0 can delegate authentication to Okta, allowing users with Okta accounts to access your applications.</p>\n</li>\n<li>\n<p><a href=\"https://www.microsoft.com/en-in/security/business/identity-access/microsoft-entra-id\" target=\"_blank\" rel=\"nofollow\">Azure Active Directory</a>: Enables SSO for organizations using Microsoft’s directory service.</p>\n</li>\n<li>\n<p><a href=\"https://workspace.google.com/intl/en_in/lp/business/?utm_source=google&#x26;utm_medium=cpc&#x26;utm_campaign=1710070-Workspace-APAC-IN-en-BKWS-EXA-HV-Hybrid&#x26;utm_content=text-ad-none-none-DEV_c-CRE_608675944021-ADGP_Hybrid+%7C+BKWS+-+EXA+%7C+Txt-Workspace-N/A-KWID_43700079340244364-kwd-346911454270&#x26;userloc_1007820-network_g&#x26;utm_term=KW_google%20workspace&#x26;gad_source=1&#x26;gad_campaignid=17662087385&#x26;gclid=CjwKCAjwiezABhBZEiwAEbTPGB8PRCSkX6V4UZ2hDrZLyHq7C4KLkCnnLVTc5HY4udmgH5NBeBuacBoCjG8QAvD_BwE&#x26;gclsrc=aw.ds\" target=\"_blank\" rel=\"nofollow\">Google Workspace</a>: Allows users to log in by using their Google Workspace (formerly G Suite) credentials.</p>\n</li>\n<li>\n<p><a href=\"https://auth0.com/docs/authenticate/protocols/saml/saml-configuration\" target=\"_blank\" rel=\"nofollow\">Custom SAML Providers</a>: Auth0 can integrate with any SAML-compliant identity provider, such as OneLogin, Ping Identity, or in-house solutions.</p>\n</li>\n</ul>\n<p>The integration process involves exchanging metadata between Auth0 and the identity provider, establishing trust relationships that enable\nsecure authentication flows.</p>\n<h3 id=\"session-management\" style=\"position:relative;\"><a href=\"#session-management\" aria-label=\"session management permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a><strong>Session Management</strong></h3>\n<p>Auth0 handles user sessions through a combination of:</p>\n<ul>\n<li>\n<p><strong>Access Tokens</strong>: Short-lived credentials that applications use to access protected resources on behalf of the user.</p>\n</li>\n<li>\n<p><strong>Refresh Tokens</strong>: Longer-lived tokens that can obtain new access tokens, without requiring the user to log in again.</p>\n</li>\n<li>\n<p><strong>ID Tokens</strong>: Contains user identity information and is used by the client application to understand who the user is.</p>\n</li>\n</ul>\n<p>Auth0 allows configuration of session durations, idle timeouts, and token lifetimes, though with some limitations we’ll discuss later.</p>\n<h2 id=\"steps-to-implement-sso-with-auth0\" style=\"position:relative;\"><a href=\"#steps-to-implement-sso-with-auth0\" aria-label=\"steps to implement sso with auth0 permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a><strong>Steps to Implement SSO with Auth0</strong></h2>\n<p><span\n      class=\"gatsby-resp-image-wrapper\"\n      style=\"position: relative; display: block; margin-left: auto; margin-right: auto; max-width: 630px; \"\n    >\n      <a\n    class=\"gatsby-resp-image-link\"\n    href=\"/static/c0311df84c72f57beeb3540ebca091d4/ae953/Typical-SSO.png\"\n    style=\"display: block\"\n    target=\"_blank\"\n    rel=\"noopener\"\n  >\n    <span\n    class=\"gatsby-resp-image-background-image\"\n    style=\"padding-bottom: 59.49367088607595%; position: relative; bottom: 0; left: 0; background-image: url('data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAMCAYAAABiDJ37AAAACXBIWXMAAAsTAAALEwEAmpwYAAACVklEQVQoz02Ta27bMBCEfYDaIik+RUqk3rIk23FSNECb+x9rtqDcAP2xWAKL+TA7JE/cKCobR3psUK0tpb3HtHe07x1+PW/4fAz4/Wjo6x7wdavwZ3X0OSr6SBxvkdG9YbTWnCbPKTlOJ64kRGVQxop0X8OONaqpprgk3D8+cX/e8P6+08fzRs/bSM8tYesdOlugNQUlw5AsR204VYrjxAQnJksqdEmhvyLOE2wKJIMlUxualgHXdcayzJiGFtOwoIsNUu2obTyC0yRFQVIwlILRSYgSShsoo1CFCd30gWF5Q9NtVNUj5nnCtm/o+hZtm9CEAU19RdfdEZuZgp+glYHKmwqBk1IVpumBZbmR9zOFekRqWzLWggtOshTQUmHsn+hihDGaytIixgHWWvL+imn+iWXZyBiDE2OMjHFomh5dd4X3HmVZoigYZfd1qJBixDSuaFMDo/Ux40LA+QpttyDUEVWI4Fy8gDELphHD0GMcB4QQoVSE0QHrMmPfN+zbiusyw1kHrROcTxjGb82Itu/AOX8BtdbZPqx18D7DFPp+PbrL2VpzlLMaWivM8+3IzPka1lXI8RwR8fxsOEeGFkVBnIucD5WloBA8KSXpUhR0Pp/px/lMl+JCUspjJqWgUthDk7W5GGMvhxnKOcNx48ojDy8XBs5fWeaVns93XC5FzpVyZ4xD63BosvbFeDmkf3U4ldKiaTakNMLaAMYULct6AItCkrURff9AXbeklMO37ptzAL9d5p5tS2mOm+Y8R3FBXlMplc95RShlIfKHYEXW4D8G/QXp3TkLOBxnHgAAAABJRU5ErkJggg=='); background-size: cover; display: block;\"\n  ></span>\n  <img\n        class=\"gatsby-resp-image-image\"\n        alt=\"Typical SSO\"\n        title=\"Typical SSO\"\n        src=\"/static/c0311df84c72f57beeb3540ebca091d4/f058b/Typical-SSO.png\"\n        srcset=\"/static/c0311df84c72f57beeb3540ebca091d4/c26ae/Typical-SSO.png 158w,\n/static/c0311df84c72f57beeb3540ebca091d4/6bdcf/Typical-SSO.png 315w,\n/static/c0311df84c72f57beeb3540ebca091d4/f058b/Typical-SSO.png 630w,\n/static/c0311df84c72f57beeb3540ebca091d4/40601/Typical-SSO.png 945w,\n/static/c0311df84c72f57beeb3540ebca091d4/ae953/Typical-SSO.png 1132w\"\n        sizes=\"(max-width: 630px) 100vw, 630px\"\n        style=\"width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0;\"\n        loading=\"lazy\"\n        decoding=\"async\"\n      />\n  </a>\n    </span></p>\n<p>Implementing SSO with Auth0 requires several configuration steps that bridge your application with identity providers. Let’s walk through the process:</p>\n<h3 id=\"step-1-set-up-auth0-tenant\" style=\"position:relative;\"><a href=\"#step-1-set-up-auth0-tenant\" aria-label=\"step 1 set up auth0 tenant permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a><strong>Step 1: Set Up Auth0 Tenant</strong></h3>\n<p>A tenant in Auth0 represents your organization and serves as a logical isolation unit for your users, applications, and connections.</p>\n<ol>\n<li>\n<p>Sign up for an Auth0 account if you don’t already have one.</p>\n</li>\n<li>\n<p>Navigate to the Auth0 dashboard, and create a new tenant or select an existing one.</p>\n</li>\n<li>\n<p>Choose the region closest to your user base, for optimal performance.</p>\n</li>\n<li>\n<p>Set your tenant domain (e.g., <code class=\"language-text\">yourcompany.auth0.com</code> or a custom domain).</p>\n</li>\n</ol>\n<p>Your tenant settings determine fundamental behavior, such as which identity providers you can connect to and which features are available\nto you.</p>\n<h3 id=\"step-2-configure-an-enterprise-connection\" style=\"position:relative;\"><a href=\"#step-2-configure-an-enterprise-connection\" aria-label=\"step 2 configure an enterprise connection permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a><strong>Step 2: Configure an Enterprise Connection</strong></h3>\n<p>Enterprise connections link Auth0 to external identity providers such as Microsoft Active Directory or Okta.</p>\n<p><strong>For SAML Connections:</strong></p>\n<ol>\n<li>\n<p>In the Auth0 dashboard, go to <strong>Authentication > Enterprise > SAML</strong>.</p>\n</li>\n<li>\n<p>Click <strong>Create Connection,</strong> and then enter a name for your connection.</p>\n</li>\n<li>\n<p>Configure the connection by entering the details obtained from your identity provider:</p>\n<ul>\n<li>\n<p>Sign-in URL (SSO URL)</p>\n</li>\n<li>\n<p>X.509 Signing Certificate</p>\n</li>\n<li>\n<p>SAML Request Binding</p>\n</li>\n<li>\n<p>SAML Response Binding</p>\n</li>\n</ul>\n</li>\n<li>\n<p>Click <strong>Save</strong> to apply the configuration.</p>\n</li>\n<li>\n<p>After saving, download the Auth0 metadata file and provide it to your IdP to complete the trust relationship.</p>\n</li>\n</ol>\n<p><strong>For OIDC Connections:</strong></p>\n<ol>\n<li>\n<p>Go to <strong>Authentication > Enterprise > OpenID Connect</strong>.</p>\n</li>\n<li>\n<p>Click <strong>Create Connection,</strong> and then enter a descriptive name.</p>\n</li>\n<li>\n<p>Enter the required OIDC configuration parameters:</p>\n<ul>\n<li>\n<p>Issuer URL</p>\n</li>\n<li>\n<p>Client ID and secret</p>\n</li>\n<li>\n<p>Scopes to request</p>\n</li>\n</ul>\n</li>\n<li>\n<p>Configure the callback URLs in both Auth0 and your identity provider.</p>\n</li>\n<li>\n<p>Click <strong>Save</strong> to complete the setup.</p>\n</li>\n</ol>\n<h3 id=\"step-3-map-claims-and-roles\" style=\"position:relative;\"><a href=\"#step-3-map-claims-and-roles\" aria-label=\"step 3 map claims and roles permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a><strong>Step 3: Map Claims and Roles</strong></h3>\n<p>Auth0 allows you to map user attributes from your identity provider to standardized claims in Auth0:</p>\n<ol>\n<li>\n<p>In your enterprise connection settings, navigate to the <strong>Mappings</strong> tab.</p>\n</li>\n<li>\n<p>Map the source attributes from your IdP to Auth0 user profile attributes.</p>\n</li>\n</ol>\n<p>Consider setting up rules to transform claims or add additional logic:</p>\n<div\n              class=\"gatsby-code-button-container\"\n              data-toaster-id=\"73496850537516470000\"\n              data-toaster-class=\"gatsby-code-button-toaster\"\n              data-toaster-text-class=\"gatsby-code-button-toaster-text\"\n              data-toaster-text=\"Copied!\"\n              data-toaster-duration=\"3500\"\n              onClick=\"copyToClipboard(`function (user, context, callback) { \n// Map department to role\n  if (user.department === 'Engineering') {\n    context.idToken['https://yourapp.com/roles'] = ['engineer'];\n  }\n  callback(null, user, context);\n}`, `73496850537516470000`)\"\n            >\n              <div\n                class=\"gatsby-code-button\"\n                data-tooltip=\"\"\n              >\n                <svg class=\"gatsby-code-button-icon\" xmlns=\"http://www.w3.org/2000/svg\" width=\"24\" height=\"24\" viewBox=\"0 0 24 24\"><path fill=\"none\" d=\"M0 0h24v24H0V0z\"/><path d=\"M16 1H2v16h2V3h12V1zm-1 4l6 6v12H6V5h9zm-1 7h5.5L14 6.5V12z\"/></svg>\n              </div>\n            </div>\n<div class=\"gatsby-highlight\" data-language=\"js\"><pre class=\"language-js\"><code class=\"language-js\"><span class=\"token keyword\">function</span> <span class=\"token punctuation\">(</span><span class=\"token parameter\">user<span class=\"token punctuation\">,</span> context<span class=\"token punctuation\">,</span> callback</span><span class=\"token punctuation\">)</span> <span class=\"token punctuation\">{</span> \n<span class=\"token comment\">// Map department to role</span>\n  <span class=\"token keyword\">if</span> <span class=\"token punctuation\">(</span>user<span class=\"token punctuation\">.</span>department <span class=\"token operator\">===</span> <span class=\"token string\">'Engineering'</span><span class=\"token punctuation\">)</span> <span class=\"token punctuation\">{</span>\n    context<span class=\"token punctuation\">.</span>idToken<span class=\"token punctuation\">[</span><span class=\"token string\">'https://yourapp.com/roles'</span><span class=\"token punctuation\">]</span> <span class=\"token operator\">=</span> <span class=\"token punctuation\">[</span><span class=\"token string\">'engineer'</span><span class=\"token punctuation\">]</span><span class=\"token punctuation\">;</span>\n  <span class=\"token punctuation\">}</span>\n  <span class=\"token function\">callback</span><span class=\"token punctuation\">(</span><span class=\"token keyword\">null</span><span class=\"token punctuation\">,</span> user<span class=\"token punctuation\">,</span> context<span class=\"token punctuation\">)</span><span class=\"token punctuation\">;</span>\n<span class=\"token punctuation\">}</span></code></pre></div>\n<ol start=\"3\">\n<li>You can also use Auth0 Actions for more complex transformations or validations.</li>\n</ol>\n<h3 id=\"step-4-integrate-sdk-in-your-app\" style=\"position:relative;\"><a href=\"#step-4-integrate-sdk-in-your-app\" aria-label=\"step 4 integrate sdk in your app permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a><strong>Step 4: Integrate SDK in Your App</strong></h3>\n<p>Auth0 provides SDKs for various platforms, to simplify integration:</p>\n<p><strong>Frontend Integration</strong></p>\n<p>For a React application:</p>\n<div\n              class=\"gatsby-code-button-container\"\n              data-toaster-id=\"88842510301132140000\"\n              data-toaster-class=\"gatsby-code-button-toaster\"\n              data-toaster-text-class=\"gatsby-code-button-toaster-text\"\n              data-toaster-text=\"Copied!\"\n              data-toaster-duration=\"3500\"\n              onClick=\"copyToClipboard(`import { Auth0Provider, useAuth0 } from '@auth0/auth0-react';\n\n\nfunction App() {\n  return (\n    <Auth0Provider\n      domain=&quot;your-domain.auth0.com&quot;\n      clientId=&quot;your-client-id&quot;\n      redirectUri={window.location.origin}\n      audience=&quot;your-api-identifier&quot;\n    >\n      <MainApp />\n    </Auth0Provider>\n  );\n}\n\n\nfunction MainApp() {\n  const { isAuthenticated, loginWithRedirect, logout, user } = useAuth0();\n \n  return (\n    <div>\n      {isAuthenticated ? (\n        <>\n          <div>Hello, {user.name}</div>\n          <button onClick={() => logout()}>Logout</button>\n        </>\n      ) : (\n        <button onClick={() => loginWithRedirect()}>Login</button>\n      )}\n    </div>\n  );\n}\n`, `88842510301132140000`)\"\n            >\n              <div\n                class=\"gatsby-code-button\"\n                data-tooltip=\"\"\n              >\n                <svg class=\"gatsby-code-button-icon\" xmlns=\"http://www.w3.org/2000/svg\" width=\"24\" height=\"24\" viewBox=\"0 0 24 24\"><path fill=\"none\" d=\"M0 0h24v24H0V0z\"/><path d=\"M16 1H2v16h2V3h12V1zm-1 4l6 6v12H6V5h9zm-1 7h5.5L14 6.5V12z\"/></svg>\n              </div>\n            </div>\n<div class=\"gatsby-highlight\" data-language=\"js\"><pre class=\"language-js\"><code class=\"language-js\"><span class=\"token keyword\">import</span> <span class=\"token punctuation\">{</span> Auth0Provider<span class=\"token punctuation\">,</span> useAuth0 <span class=\"token punctuation\">}</span> <span class=\"token keyword\">from</span> <span class=\"token string\">'@auth0/auth0-react'</span><span class=\"token punctuation\">;</span>\n\n\n<span class=\"token keyword\">function</span> <span class=\"token function\">App</span><span class=\"token punctuation\">(</span><span class=\"token punctuation\">)</span> <span class=\"token punctuation\">{</span>\n  <span class=\"token keyword\">return</span> <span class=\"token punctuation\">(</span>\n    <span class=\"token operator\">&lt;</span>Auth0Provider\n      domain<span class=\"token operator\">=</span><span class=\"token string\">\"your-domain.auth0.com\"</span>\n      clientId<span class=\"token operator\">=</span><span class=\"token string\">\"your-client-id\"</span>\n      redirectUri<span class=\"token operator\">=</span><span class=\"token punctuation\">{</span>window<span class=\"token punctuation\">.</span>location<span class=\"token punctuation\">.</span>origin<span class=\"token punctuation\">}</span>\n      audience<span class=\"token operator\">=</span><span class=\"token string\">\"your-api-identifier\"</span>\n    <span class=\"token operator\">></span>\n      <span class=\"token operator\">&lt;</span>MainApp <span class=\"token operator\">/</span><span class=\"token operator\">></span>\n    <span class=\"token operator\">&lt;</span><span class=\"token operator\">/</span>Auth0Provider<span class=\"token operator\">></span>\n  <span class=\"token punctuation\">)</span><span class=\"token punctuation\">;</span>\n<span class=\"token punctuation\">}</span>\n\n\n<span class=\"token keyword\">function</span> <span class=\"token function\">MainApp</span><span class=\"token punctuation\">(</span><span class=\"token punctuation\">)</span> <span class=\"token punctuation\">{</span>\n  <span class=\"token keyword\">const</span> <span class=\"token punctuation\">{</span> isAuthenticated<span class=\"token punctuation\">,</span> loginWithRedirect<span class=\"token punctuation\">,</span> logout<span class=\"token punctuation\">,</span> user <span class=\"token punctuation\">}</span> <span class=\"token operator\">=</span> <span class=\"token function\">useAuth0</span><span class=\"token punctuation\">(</span><span class=\"token punctuation\">)</span><span class=\"token punctuation\">;</span>\n \n  <span class=\"token keyword\">return</span> <span class=\"token punctuation\">(</span>\n    <span class=\"token operator\">&lt;</span>div<span class=\"token operator\">></span>\n      <span class=\"token punctuation\">{</span>isAuthenticated <span class=\"token operator\">?</span> <span class=\"token punctuation\">(</span>\n        <span class=\"token operator\">&lt;</span><span class=\"token operator\">></span>\n          <span class=\"token operator\">&lt;</span>div<span class=\"token operator\">></span>Hello<span class=\"token punctuation\">,</span> <span class=\"token punctuation\">{</span>user<span class=\"token punctuation\">.</span>name<span class=\"token punctuation\">}</span><span class=\"token operator\">&lt;</span><span class=\"token operator\">/</span>div<span class=\"token operator\">></span>\n          <span class=\"token operator\">&lt;</span>button onClick<span class=\"token operator\">=</span><span class=\"token punctuation\">{</span><span class=\"token punctuation\">(</span><span class=\"token punctuation\">)</span> <span class=\"token operator\">=></span> <span class=\"token function\">logout</span><span class=\"token punctuation\">(</span><span class=\"token punctuation\">)</span><span class=\"token punctuation\">}</span><span class=\"token operator\">></span>Logout<span class=\"token operator\">&lt;</span><span class=\"token operator\">/</span>button<span class=\"token operator\">></span>\n        <span class=\"token operator\">&lt;</span><span class=\"token operator\">/</span><span class=\"token operator\">></span>\n      <span class=\"token punctuation\">)</span> <span class=\"token operator\">:</span> <span class=\"token punctuation\">(</span>\n        <span class=\"token operator\">&lt;</span>button onClick<span class=\"token operator\">=</span><span class=\"token punctuation\">{</span><span class=\"token punctuation\">(</span><span class=\"token punctuation\">)</span> <span class=\"token operator\">=></span> <span class=\"token function\">loginWithRedirect</span><span class=\"token punctuation\">(</span><span class=\"token punctuation\">)</span><span class=\"token punctuation\">}</span><span class=\"token operator\">></span>Login<span class=\"token operator\">&lt;</span><span class=\"token operator\">/</span>button<span class=\"token operator\">></span>\n      <span class=\"token punctuation\">)</span><span class=\"token punctuation\">}</span>\n    <span class=\"token operator\">&lt;</span><span class=\"token operator\">/</span>div<span class=\"token operator\">></span>\n  <span class=\"token punctuation\">)</span><span class=\"token punctuation\">;</span>\n<span class=\"token punctuation\">}</span>\n</code></pre></div>\n<p><strong>Backend Integration</strong></p>\n<p>For a Node.js API:</p>\n<div\n              class=\"gatsby-code-button-container\"\n              data-toaster-id=\"61385271066031490000\"\n              data-toaster-class=\"gatsby-code-button-toaster\"\n              data-toaster-text-class=\"gatsby-code-button-toaster-text\"\n              data-toaster-text=\"Copied!\"\n              data-toaster-duration=\"3500\"\n              onClick=\"copyToClipboard(`const express = require('express');\nconst { auth } = require('express-oauth2-jwt-bearer');\n\n\nconst app = express();\n\n\n// Authentication middleware\nconst checkJwt = auth({\n  audience: 'your-api-identifier',\n  issuerBaseURL: \\`https://your-domain.auth0.com/\\`,\n});\n\n\n// Protected route\napp.get('/api/protected', checkJwt, (req, res) => {\n  res.json({ message: 'This is a protected endpoint' });\n});\n\n\napp.listen(3000, () => console.log('Server running on port 3000'));\n`, `61385271066031490000`)\"\n            >\n              <div\n                class=\"gatsby-code-button\"\n                data-tooltip=\"\"\n              >\n                <svg class=\"gatsby-code-button-icon\" xmlns=\"http://www.w3.org/2000/svg\" width=\"24\" height=\"24\" viewBox=\"0 0 24 24\"><path fill=\"none\" d=\"M0 0h24v24H0V0z\"/><path d=\"M16 1H2v16h2V3h12V1zm-1 4l6 6v12H6V5h9zm-1 7h5.5L14 6.5V12z\"/></svg>\n              </div>\n            </div>\n<div class=\"gatsby-highlight\" data-language=\"js\"><pre class=\"language-js\"><code class=\"language-js\"><span class=\"token keyword\">const</span> express <span class=\"token operator\">=</span> <span class=\"token function\">require</span><span class=\"token punctuation\">(</span><span class=\"token string\">'express'</span><span class=\"token punctuation\">)</span><span class=\"token punctuation\">;</span>\n<span class=\"token keyword\">const</span> <span class=\"token punctuation\">{</span> auth <span class=\"token punctuation\">}</span> <span class=\"token operator\">=</span> <span class=\"token function\">require</span><span class=\"token punctuation\">(</span><span class=\"token string\">'express-oauth2-jwt-bearer'</span><span class=\"token punctuation\">)</span><span class=\"token punctuation\">;</span>\n\n\n<span class=\"token keyword\">const</span> app <span class=\"token operator\">=</span> <span class=\"token function\">express</span><span class=\"token punctuation\">(</span><span class=\"token punctuation\">)</span><span class=\"token punctuation\">;</span>\n\n\n<span class=\"token comment\">// Authentication middleware</span>\n<span class=\"token keyword\">const</span> checkJwt <span class=\"token operator\">=</span> <span class=\"token function\">auth</span><span class=\"token punctuation\">(</span><span class=\"token punctuation\">{</span>\n  <span class=\"token literal-property property\">audience</span><span class=\"token operator\">:</span> <span class=\"token string\">'your-api-identifier'</span><span class=\"token punctuation\">,</span>\n  <span class=\"token literal-property property\">issuerBaseURL</span><span class=\"token operator\">:</span> <span class=\"token template-string\"><span class=\"token template-punctuation string\">`</span><span class=\"token string\">https://your-domain.auth0.com/</span><span class=\"token template-punctuation string\">`</span></span><span class=\"token punctuation\">,</span>\n<span class=\"token punctuation\">}</span><span class=\"token punctuation\">)</span><span class=\"token punctuation\">;</span>\n\n\n<span class=\"token comment\">// Protected route</span>\napp<span class=\"token punctuation\">.</span><span class=\"token function\">get</span><span class=\"token punctuation\">(</span><span class=\"token string\">'/api/protected'</span><span class=\"token punctuation\">,</span> checkJwt<span class=\"token punctuation\">,</span> <span class=\"token punctuation\">(</span><span class=\"token parameter\">req<span class=\"token punctuation\">,</span> res</span><span class=\"token punctuation\">)</span> <span class=\"token operator\">=></span> <span class=\"token punctuation\">{</span>\n  res<span class=\"token punctuation\">.</span><span class=\"token function\">json</span><span class=\"token punctuation\">(</span><span class=\"token punctuation\">{</span> <span class=\"token literal-property property\">message</span><span class=\"token operator\">:</span> <span class=\"token string\">'This is a protected endpoint'</span> <span class=\"token punctuation\">}</span><span class=\"token punctuation\">)</span><span class=\"token punctuation\">;</span>\n<span class=\"token punctuation\">}</span><span class=\"token punctuation\">)</span><span class=\"token punctuation\">;</span>\n\n\napp<span class=\"token punctuation\">.</span><span class=\"token function\">listen</span><span class=\"token punctuation\">(</span><span class=\"token number\">3000</span><span class=\"token punctuation\">,</span> <span class=\"token punctuation\">(</span><span class=\"token punctuation\">)</span> <span class=\"token operator\">=></span> console<span class=\"token punctuation\">.</span><span class=\"token function\">log</span><span class=\"token punctuation\">(</span><span class=\"token string\">'Server running on port 3000'</span><span class=\"token punctuation\">)</span><span class=\"token punctuation\">)</span><span class=\"token punctuation\">;</span>\n</code></pre></div>\n<h3 id=\"step-5-testing-and-debugging\" style=\"position:relative;\"><a href=\"#step-5-testing-and-debugging\" aria-label=\"step 5 testing and debugging permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a><strong>Step 5: Testing and Debugging</strong></h3>\n<p>Testing your SSO implementation is crucial before going live:</p>\n<ol>\n<li>\n<p><strong>Verify IdP Configuration</strong>: Ensure the metadata exchange between Auth0 and your IdP is correctly configured.</p>\n</li>\n<li>\n<p><strong>Test Login Flow</strong>: Attempt to log in through your IdP and verify the user is correctly redirected back to your application.</p>\n</li>\n<li>\n<p><strong>Inspect Token Contents</strong>: Verify that user claims and roles are properly mapped.</p>\n</li>\n<li>\n<p><strong>Check Session Behavior</strong>: Test session duration and renewal to ensure they match your expectations.</p>\n</li>\n</ol>\n<p><strong>Common Issues and Solutions</strong>:</p>\n<ul>\n<li>\n<p><strong>SAML Response Validation Errors</strong>: Often caused by clock synchronization issues between servers or an incorrect certificate configuration.</p>\n</li>\n<li>\n<p><strong>Redirect Loop</strong>: Can occur when callback URLs are misconfigured or during cookie/session management problems.</p>\n</li>\n<li>\n<p><strong>Missing Claims</strong>: Check your mapping configuration if the expected user attributes aren’t appearing in tokens.</p>\n</li>\n<li>\n<p><strong>Cross-Origin Issues</strong>: Ensure your application’s origins are properly listed in Auth0’s allowed origins.</p>\n</li>\n</ul>\n<h2 id=\"common-limitations-of-auth0-sso\" style=\"position:relative;\"><a href=\"#common-limitations-of-auth0-sso\" aria-label=\"common limitations of auth0 sso permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a><strong>Common Limitations of Auth0 SSO</strong></h2>\n<p>While Auth0 offers robust SSO capabilities, it comes with several limitations that developers should be aware of:</p>\n<h3 id=\"high-pricing-for-enterprise-sso\" style=\"position:relative;\"><a href=\"#high-pricing-for-enterprise-sso\" aria-label=\"high pricing for enterprise sso permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a><strong>High Pricing for Enterprise SSO</strong></h3>\n<p>Auth0’s pricing model can become expensive as your user base grows:</p>\n<ul>\n<li>\n<p>Enterprise SSO features are only available on higher-tier plans.</p>\n</li>\n<li>\n<p>Per-active-user pricing makes costs unpredictable for growing applications.</p>\n</li>\n<li>\n<p>Additional charges for certain features, such as adaptive MFA or SSO integrations.</p>\n</li>\n<li>\n<p>Limited free-tier functionality for testing and development.</p>\n</li>\n</ul>\n<p>For startups and growing businesses, these costs can quickly become prohibitive, especially when SSO is a requirement for enterprise\ncustomers.</p>\n<h3 id=\"opaque-session-management\" style=\"position:relative;\"><a href=\"#opaque-session-management\" aria-label=\"opaque session management permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a><strong>Opaque Session Management</strong></h3>\n<p>Auth0’s session management has several limitations:</p>\n<ul>\n<li>\n<p>Limited control over token lifetime and renewal logic.</p>\n</li>\n<li>\n<p>Refresh token rotation policies can’t be fully customized.</p>\n</li>\n<li>\n<p>Session validation happens on Auth0’s servers, adding latency.</p>\n</li>\n<li>\n<p>Difficult to implement custom session behaviors.</p>\n</li>\n</ul>\n<p>These restrictions can be particularly challenging for applications that require granular control over session security or custom\nvalidation logic.</p>\n<h3 id=\"vendor-lock-in\" style=\"position:relative;\"><a href=\"#vendor-lock-in\" aria-label=\"vendor lock in permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a><strong>Vendor Lock-in</strong></h3>\n<p>Auth0’s proprietary architecture creates significant lock-in:</p>\n<ul>\n<li>\n<p>User data is stored in Auth0’s proprietary database.</p>\n</li>\n<li>\n<p>Custom rules and actions are written in Auth0’s specific formats.</p>\n</li>\n<li>\n<p>Complex migration process to extract user data and authentication logic.</p>\n</li>\n<li>\n<p>Redevelopment required when switching providers.</p>\n</li>\n</ul>\n<p>This lack of portability increases risk and can limit future architectural decisions.</p>\n<h3 id=\"limited-customization\" style=\"position:relative;\"><a href=\"#limited-customization\" aria-label=\"limited customization permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a><strong>Limited Customization</strong></h3>\n<p>Developers often face friction when implementing custom authentication flows:</p>\n<ul>\n<li>\n<p>Universal Login customization is limited without premium plans.</p>\n</li>\n<li>\n<p>Complex workflows require chaining multiple rules or actions.</p>\n</li>\n<li>\n<p>Limited ability to modify core authentication behaviors.</p>\n</li>\n<li>\n<p>Custom databases have performance limitations and restrictions.</p>\n</li>\n</ul>\n<p>Applications requiring unique authentication experiences often struggle with Auth0’s constraints.</p>\n<h3 id=\"compliance-barriers\" style=\"position:relative;\"><a href=\"#compliance-barriers\" aria-label=\"compliance barriers permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a><strong>Compliance Barriers</strong></h3>\n<p>Auth0 can present challenges for organizations with strict compliance\nrequirements:</p>\n<ul>\n<li>\n<p>Data residency and sovereignty may be difficult to guarantee.</p>\n</li>\n<li>\n<p>Full audit trails require premium tiers.</p>\n</li>\n<li>\n<p>Limited control over exactly how user data is stored and processed.</p>\n</li>\n<li>\n<p>Difficult to implement custom encryption or security protocols.</p>\n</li>\n</ul>\n<h2 id=\"how-supertokens-enhances-the-sso-experience\" style=\"position:relative;\"><a href=\"#how-supertokens-enhances-the-sso-experience\" aria-label=\"how supertokens enhances the sso experience permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a><strong>How SuperTokens Enhances the SSO Experience</strong></h2>\n<p><span\n      class=\"gatsby-resp-image-wrapper\"\n      style=\"position: relative; display: block; margin-left: auto; margin-right: auto; max-width: 630px; \"\n    >\n      <a\n    class=\"gatsby-resp-image-link\"\n    href=\"/static/18ecc2d2c11698d5649e18d0a9467fd7/29007/Supertokens.png\"\n    style=\"display: block\"\n    target=\"_blank\"\n    rel=\"noopener\"\n  >\n    <span\n    class=\"gatsby-resp-image-background-image\"\n    style=\"padding-bottom: 50.632911392405056%; position: relative; bottom: 0; left: 0; background-image: url('data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAKCAIAAAA7N+mxAAAACXBIWXMAAAsTAAALEwEAmpwYAAAB6ElEQVQozxXQWXLTMAAAUH9Aau2rZUm2LDmWk5S0TtOydAoTliZNCjMtDAfgcOWgDO8IrwjOXC2am6tpM00xhK6LXRy6tGjiWHej9qmywbngXON9U9e1UmqaNi8vf3e7XSGEqLRurJkHvxrSKg8pDXl5kZabGHOf1zmvo++8qrzUmjGCMEQEEwYhKoRgzujU2DG2y74dU8jz+TRtV5fX54s30+V2s95Mw5gr02vtpZJcI6pKIkpEC06prVRrTXBV39rYuNVi8fT0fDz9uL3bHe6Pj1/vf+7329gNWrfKKGmxbIDwZ0QVFGMtmFHCahlc/e3L58fT6e7jp/3heDp+fzw8/Dqefh/2f56f9h9ug2mkDljHUvczVheMIEGJZLSSwmjZeJtzTinlnMdhvs7zq6F/l/vrPi1866uWVwnoOXJLrENRMaQp5gQxijljjDIluNXSVzLUOtVyqGWveRDMCaWVJzq+ltEO25SnImnSSiwxJAii/5NYlrOa09j4ztq+8bHxHJQWlYJxwg0Q/hVzVbvo0rJYO5oNMRRSBAAAEEKGgeEwaLLq9LKVnUaGlhIDjFCJWEnUDHHSnIs4FduWn1vqOOIIgLKEoBQEeomyo2+X7iab0REvoSAAAlACWCJyNpvx+Xt7sf8HqBFCXw868AkAAAAASUVORK5CYII='); background-size: cover; display: block;\"\n  ></span>\n  <img\n        class=\"gatsby-resp-image-image\"\n        alt=\"Supertokens\"\n        title=\"Supertokens\"\n        src=\"/static/18ecc2d2c11698d5649e18d0a9467fd7/f058b/Supertokens.png\"\n        srcset=\"/static/18ecc2d2c11698d5649e18d0a9467fd7/c26ae/Supertokens.png 158w,\n/static/18ecc2d2c11698d5649e18d0a9467fd7/6bdcf/Supertokens.png 315w,\n/static/18ecc2d2c11698d5649e18d0a9467fd7/f058b/Supertokens.png 630w,\n/static/18ecc2d2c11698d5649e18d0a9467fd7/40601/Supertokens.png 945w,\n/static/18ecc2d2c11698d5649e18d0a9467fd7/78612/Supertokens.png 1260w,\n/static/18ecc2d2c11698d5649e18d0a9467fd7/29007/Supertokens.png 1600w\"\n        sizes=\"(max-width: 630px) 100vw, 630px\"\n        style=\"width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0;\"\n        loading=\"lazy\"\n        decoding=\"async\"\n      />\n  </a>\n    </span></p>\n<p><a href=\"https://supertokens.com/\" target=\"_blank\" rel=\"nofollow\">SuperTokens</a> offers an open-source alternative to Auth0 that addresses many of its limitations, while providing robust SSO capabilities.</p>\n<h3 id=\"self-hosting-and-full-control\" style=\"position:relative;\"><a href=\"#self-hosting-and-full-control\" aria-label=\"self hosting and full control permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a><strong>Self-Hosting and Full Control</strong></h3>\n<p>Unlike Auth0, SuperTokens gives you complete control over your authentication infrastructure:</p>\n<ul>\n<li>\n<p>Self-host on your own infrastructure or use SuperTokens’ managed service.</p>\n</li>\n<li>\n<p>Access to all source code (MIT-licensed) for full transparency.</p>\n</li>\n<li>\n<p>Deploy in your own cloud environment for complete data sovereignty.</p>\n</li>\n<li>\n<p>Modify any component to suit your specific requirements.</p>\n</li>\n</ul>\n<p>This level of control eliminates vendor lock-in and gives you ownership of your authentication system.</p>\n<h3 id=\"built-in-sso-and-multi-tenant-support\" style=\"position:relative;\"><a href=\"#built-in-sso-and-multi-tenant-support\" aria-label=\"built in sso and multi tenant support permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a><strong>Built-in SSO and Multi-Tenant Support</strong></h3>\n<p>SuperTokens offers comprehensive SSO capabilities, with multi-tenant support out of the box:</p>\n<ul>\n<li>\n<p>Implement SSO across multiple domains and applications seamlessly.</p>\n</li>\n<li>\n<p>Create tenant-specific authentication policies and branding.</p>\n</li>\n<li>\n<p>Support for both B2B and B2C scenarios with different authentication requirements.</p>\n</li>\n<li>\n<p>Custom claims and session properties per tenant.</p>\n</li>\n</ul>\n<p>For SaaS applications serving multiple organizations, these features are invaluable.</p>\n<h3 id=\"session-security-and-transparency\" style=\"position:relative;\"><a href=\"#session-security-and-transparency\" aria-label=\"session security and transparency permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a><strong>Session Security and Transparency</strong></h3>\n<p>SuperTokens provides superior session management with full transparency:</p>\n<ul>\n<li>\n<p>Automatic refresh token rotation, for enhanced security.</p>\n</li>\n<li>\n<p>Built-in anti-CSRF protection.</p>\n</li>\n<li>\n<p>Customizable token lifetimes and validation logic.</p>\n</li>\n<li>\n<p>Session hijacking detection.</p>\n</li>\n</ul>\n<p>You can inspect and modify the session handling code to match your specific security requirements.</p>\n<div\n              class=\"gatsby-code-button-container\"\n              data-toaster-id=\"29551746972281870000\"\n              data-toaster-class=\"gatsby-code-button-toaster\"\n              data-toaster-text-class=\"gatsby-code-button-toaster-text\"\n              data-toaster-text=\"Copied!\"\n              data-toaster-duration=\"3500\"\n              onClick=\"copyToClipboard(`// Example of custom session validation in SuperTokens\nimport Session from &quot;supertokens-node/recipe/session&quot;;\n\nSession.init({\n  override: {\n    functions: (originalImplementation) => {\n      return {\n        ...originalImplementation,\n        createNewSession: async function(input) {\n          // Custom validation before creating session\n          if (input.userId === &quot;blacklisted&quot;) {\n            throw new Error(&quot;User is blacklisted&quot;);\n          }\n         \n          // Add custom claims to session\n          input.sessionData = {\n            ...input.sessionData,\n            role: &quot;admin&quot;,\n            orgId: &quot;org123&quot;\n          };\n         \n          return originalImplementation.createNewSession(input);\n        }\n      };\n    }\n  }\n});\n`, `29551746972281870000`)\"\n            >\n              <div\n                class=\"gatsby-code-button\"\n                data-tooltip=\"\"\n              >\n                <svg class=\"gatsby-code-button-icon\" xmlns=\"http://www.w3.org/2000/svg\" width=\"24\" height=\"24\" viewBox=\"0 0 24 24\"><path fill=\"none\" d=\"M0 0h24v24H0V0z\"/><path d=\"M16 1H2v16h2V3h12V1zm-1 4l6 6v12H6V5h9zm-1 7h5.5L14 6.5V12z\"/></svg>\n              </div>\n            </div>\n<div class=\"gatsby-highlight\" data-language=\"js\"><pre class=\"language-js\"><code class=\"language-js\"><span class=\"token comment\">// Example of custom session validation in SuperTokens</span>\n<span class=\"token keyword\">import</span> Session <span class=\"token keyword\">from</span> <span class=\"token string\">\"supertokens-node/recipe/session\"</span><span class=\"token punctuation\">;</span>\n\nSession<span class=\"token punctuation\">.</span><span class=\"token function\">init</span><span class=\"token punctuation\">(</span><span class=\"token punctuation\">{</span>\n  <span class=\"token literal-property property\">override</span><span class=\"token operator\">:</span> <span class=\"token punctuation\">{</span>\n    <span class=\"token function-variable function\">functions</span><span class=\"token operator\">:</span> <span class=\"token punctuation\">(</span><span class=\"token parameter\">originalImplementation</span><span class=\"token punctuation\">)</span> <span class=\"token operator\">=></span> <span class=\"token punctuation\">{</span>\n      <span class=\"token keyword\">return</span> <span class=\"token punctuation\">{</span>\n        <span class=\"token operator\">...</span>originalImplementation<span class=\"token punctuation\">,</span>\n        <span class=\"token function-variable function\">createNewSession</span><span class=\"token operator\">:</span> <span class=\"token keyword\">async</span> <span class=\"token keyword\">function</span><span class=\"token punctuation\">(</span><span class=\"token parameter\">input</span><span class=\"token punctuation\">)</span> <span class=\"token punctuation\">{</span>\n          <span class=\"token comment\">// Custom validation before creating session</span>\n          <span class=\"token keyword\">if</span> <span class=\"token punctuation\">(</span>input<span class=\"token punctuation\">.</span>userId <span class=\"token operator\">===</span> <span class=\"token string\">\"blacklisted\"</span><span class=\"token punctuation\">)</span> <span class=\"token punctuation\">{</span>\n            <span class=\"token keyword\">throw</span> <span class=\"token keyword\">new</span> <span class=\"token class-name\">Error</span><span class=\"token punctuation\">(</span><span class=\"token string\">\"User is blacklisted\"</span><span class=\"token punctuation\">)</span><span class=\"token punctuation\">;</span>\n          <span class=\"token punctuation\">}</span>\n         \n          <span class=\"token comment\">// Add custom claims to session</span>\n          input<span class=\"token punctuation\">.</span>sessionData <span class=\"token operator\">=</span> <span class=\"token punctuation\">{</span>\n            <span class=\"token operator\">...</span>input<span class=\"token punctuation\">.</span>sessionData<span class=\"token punctuation\">,</span>\n            <span class=\"token literal-property property\">role</span><span class=\"token operator\">:</span> <span class=\"token string\">\"admin\"</span><span class=\"token punctuation\">,</span>\n            <span class=\"token literal-property property\">orgId</span><span class=\"token operator\">:</span> <span class=\"token string\">\"org123\"</span>\n          <span class=\"token punctuation\">}</span><span class=\"token punctuation\">;</span>\n         \n          <span class=\"token keyword\">return</span> originalImplementation<span class=\"token punctuation\">.</span><span class=\"token function\">createNewSession</span><span class=\"token punctuation\">(</span>input<span class=\"token punctuation\">)</span><span class=\"token punctuation\">;</span>\n        <span class=\"token punctuation\">}</span>\n      <span class=\"token punctuation\">}</span><span class=\"token punctuation\">;</span>\n    <span class=\"token punctuation\">}</span>\n  <span class=\"token punctuation\">}</span>\n<span class=\"token punctuation\">}</span><span class=\"token punctuation\">)</span><span class=\"token punctuation\">;</span>\n</code></pre></div>\n<h3 id=\"flexible-login-methods\" style=\"position:relative;\"><a href=\"#flexible-login-methods\" aria-label=\"flexible login methods permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a><strong>Flexible Login Methods</strong></h3>\n<p>SuperTokens allows you to combine multiple authentication methods seamlessly:</p>\n<ul>\n<li>\n<p>Enterprise SSO via SAML and OIDC</p>\n</li>\n<li>\n<p>Passwordless authentication (email/SMS)</p>\n</li>\n<li>\n<p>Social login (Google, GitHub, etc.)</p>\n</li>\n<li>\n<p>Traditional email/password</p>\n</li>\n</ul>\n<p>This flexibility enables you to support various user segments with different authentication preferences, while maintaining a unified session management system.</p>\n<h3 id=\"custom-ui-and-api-control\" style=\"position:relative;\"><a href=\"#custom-ui-and-api-control\" aria-label=\"custom ui and api control permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a><strong>Custom UI and API Control</strong></h3>\n<p>SuperTokens gives you full control over your authentication UI and backend logic:</p>\n<ul>\n<li>\n<p>Use pre-built UI components or create completely custom interfaces.</p>\n</li>\n<li>\n<p>Override any API endpoint, and add custom logic.</p>\n</li>\n<li>\n<p>Implement custom verification flows.</p>\n</li>\n<li>\n<p>Add organization-specific branding.</p>\n</li>\n</ul>\n<p>With SuperTokens, you’re not limited to template customizations—you have complete freedom to implement any authentication experience.</p>\n<h2 id=\"when-should-you-choose-supertokens-over-auth0\" style=\"position:relative;\"><a href=\"#when-should-you-choose-supertokens-over-auth0\" aria-label=\"when should you choose supertokens over auth0 permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a><strong>When Should You Choose SuperTokens Over Auth0?</strong></h2>\n<p>While Auth0 remains a solid choice for certain use cases, there are several scenarios where SuperTokens offers significant advantages:</p>\n<h3 id=\"youre-building-a-multi-tenant-saas\" style=\"position:relative;\"><a href=\"#youre-building-a-multi-tenant-saas\" aria-label=\"youre building a multi tenant saas permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a><strong>You’re Building a Multi-Tenant SaaS</strong></h3>\n<p>If you’re developing a SaaS platform that serves multiple organizations, SuperTokens provides benefits that Auth0 doesn’t:</p>\n<ul>\n<li>\n<p>Per-tenant SSO configuration—without premium pricing.</p>\n</li>\n<li>\n<p>Tenant-specific authentication flows and branding.</p>\n</li>\n<li>\n<p>Custom session properties and validation logic per tenant.</p>\n</li>\n<li>\n<p>Easier implementation of organization switching within apps.</p>\n</li>\n</ul>\n<p>These features allow you to offer enterprise-grade authentication to your customers, without the associated enterprise-grade costs.</p>\n<h3 id=\"you-want-to-avoid-high-licensing-fees\" style=\"position:relative;\"><a href=\"#you-want-to-avoid-high-licensing-fees\" aria-label=\"you want to avoid high licensing fees permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a><strong>You Want to Avoid High Licensing Fees</strong></h3>\n<p>Auth0’s per-user pricing model can become expensive as your user base grows:</p>\n<ul>\n<li>\n<p>SuperTokens’ open-source version is free, with no per-user fees.</p>\n</li>\n<li>\n<p>SuperTokens’ managed service offers predictable pricing that is not tied to number of users.</p>\n</li>\n<li>\n<p>No essential functionality locked behind premium tiers.</p>\n</li>\n<li>\n<p>Lower total cost of ownership, especially for applications with a large user base.</p>\n</li>\n</ul>\n<p>For startups and growing businesses, this cost advantage can be significant.</p>\n<h3 id=\"you-require-custom-authentication-logic\" style=\"position:relative;\"><a href=\"#you-require-custom-authentication-logic\" aria-label=\"you require custom authentication logic permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a><strong>You Require Custom Authentication Logic</strong></h3>\n<p>If your application has unique authentication requirements, SuperTokens offers greater flexibility:</p>\n<ul>\n<li>\n<p>Override any authentication flow component.</p>\n</li>\n<li>\n<p>Implement custom verification processes.</p>\n</li>\n<li>\n<p>Add application-specific security checks.</p>\n</li>\n<li>\n<p>Create unique user experiences based on context.</p>\n</li>\n</ul>\n<p>This flexibility allows you to implement authentication flows that match your exact business requirements, rather than adapting your requirements to fit the authentication provider.</p>\n<h3 id=\"you-value-full-transparency\" style=\"position:relative;\"><a href=\"#you-value-full-transparency\" aria-label=\"you value full transparency permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a><strong>You Value Full Transparency</strong></h3>\n<p>With SuperTokens, you have complete visibility into how your authentication system works:</p>\n<ul>\n<li>\n<p>MIT-licensed open-source code.</p>\n</li>\n<li>\n<p>Full audit capability for security reviews.</p>\n</li>\n<li>\n<p>No black-box components in critical security infrastructure.</p>\n</li>\n<li>\n<p>Community-reviewed and continuously improved codebase.</p>\n</li>\n</ul>\n<p>For security-conscious organizations, this transparency can be invaluable.</p>\n<h2 id=\"final-thoughts-moving-beyond-auth0-for-scalable-sso\" style=\"position:relative;\"><a href=\"#final-thoughts-moving-beyond-auth0-for-scalable-sso\" aria-label=\"final thoughts moving beyond auth0 for scalable sso permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a><strong>Final Thoughts: Moving Beyond Auth0 for Scalable SSO</strong></h2>\n<p>Auth0 is a leading authentication platform known for its ease of setup and extensive features. However, it has limitations, including high costs, limited customization, and vendor lock-in, which can be challenging for growing businesses.</p>\n<p>SuperTokens offers an open-source alternative that emphasizes developer control, transparency, and flexibility. It enables sophisticated authentication systems, without the drawbacks of traditional providers, making it ideal for teams seeking customizable solutions with predictable costs.</p>\n<p>For those building new applications or considering a migration from Auth0, SuperTokens may align better with long-term technical and business goals, and provide your organization with transparent and adaptable authentication technology.</p>","frontmatter":{"date":"May 14, 2025","title":"Auth0 SSO: Setup and Tips","cover":"auth0_sso.png","author":"Mostafa Ibrahim","description":"Learn how Auth0 SSO works, where it falls short, and discover a simpler open-source alternative for modern authentication flows."},"fields":{"slug":"/auth0-sso/"}},"site":{"siteMetadata":{"title":"SuperTokens Blog"}}},"pageContext":{"id":"614636a6-824f-5e1a-beee-5c7ae885d806","fields__slug":"/auth0-sso/","__params":{"fields__slug":"auth0-sso"}}},
    "staticQueryHashes": []}