# Auth0

**Canonical:** https://apis.io/providers/auth0/  
**Website:** https://auth0.com/  
**APIs profiled:** 76

Auth0 (now part of Okta) is a leading identity-as-a-service platform providing authentication and authorization for applications, APIs, and AI agents. It implements OpenID Connect, OAuth 2.0, SAML 2.0, WS-Federation, and SCIM, and exposes a Management API (OpenAPI 3.1, 221 paths, 2,567 schemas), an Authentication API, a My Account API, a My Organization API, FGA (Fine-Grained Authorization, OpenFGA / Zanzibar-based), and Auth0 for AI Agents — covering Token Vault, asynchronous authorization, Auth for MCP, and FGA for RAG.

## Kin Score — 53.6 / 100 (developing)

Scored 2026-08-20 under rubric 0.12.0. Trend: flat (+1.0 from 52.6).

| Facet | Score |
|---|---|
| Discoverability | 59.3 |
| Contract Quality | 69.2 |
| Governance | 26.5 |
| Contract Governance | 26.5 |
| Operational Transparency | 42.1 |
| Developer Ergonomics | 57.1 |
| Commercial Clarity | 51.3 |
| Access Clarity | 51.3 |

## Agent readiness — 46.8 (agent-ready)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | derived |
| Reversibility Documented | verified |
| MCP Server | documented |
| Auth Clarity | yes |
| Idempotency | no |
| Error Semantics | no |
| OpenAPI Examples | partial |
| Rate Limit Signal | documented |
| Event Surface Described | derived |
| Agent Skills | yes |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | no |

## Access

Freemium · Self-serve signup — onboarding: self-serve, pricing: freemium, trial: no (confidence: high).

## APIs (76)

- **Auth0 My Account API** — User self-service endpoints for managing authentication factors and account settings. Recently extended with ACR enforcement for sensitive scopes.
- **Auth0 My Organization API** — Organization-scoped endpoints for B2B customers to manage their own Organizations — IdP configuration, SCIM provisioning, and Home Realm Discovery.
- **Auth0 for AI Agents** — Identity and authorization product line for AI agents. Bundles Token Vault (delegated API credentials for Google/GitHub/Slack etc.), asynchronous authorization (human-in-the-loo...
- **Auth0 actions API** — The actions API from Auth0 — 16 operation(s) for actions.
- **Auth0 anomaly API** — The anomaly API from Auth0 — 1 operation(s) for anomaly.
- **Auth0 Assertions API** — The Assertions API from Auth0 — 1 operation(s) for assertions.
- **Auth0 attack-protection API** — The attack-protection API from Auth0 — 5 operation(s) for attack-protection.
- **Auth0 Authorization Models API** — The Authorization Models API from Auth0 — 2 operation(s) for authorization models.
- **Auth0 Authorize User API** — The Authorize User API from Auth0 — 1 operation(s) for authorize user.
- **Auth0 AuthZenService API** — The AuthZenService API from Auth0 — 6 operation(s) for authzenservice.
- **Auth0 branding API** — The branding API from Auth0 — 12 operation(s) for branding.
- **Auth0 client-grants API** — The client-grants API from Auth0 — 3 operation(s) for client-grants.
- **Auth0 clients API** — The clients API from Auth0 — 8 operation(s) for clients.
- **Auth0 connection-profiles API** — The connection-profiles API from Auth0 — 4 operation(s) for connection-profiles.
- **Auth0 connections API** — The connections API from Auth0 — 15 operation(s) for connections.
- **Auth0 connections-directory-provisionings API** — The connections-directory-provisionings API from Auth0 — 1 operation(s) for connections-directory-provisionings.
- **Auth0 connections-scim-configurations API** — The connections-scim-configurations API from Auth0 — 1 operation(s) for connections-scim-configurations.
- **Auth0 custom-domains API** — The custom-domains API from Auth0 — 5 operation(s) for custom-domains.
- **Auth0 DB Connections API** — The DB Connections API from Auth0 — 1 operation(s) for db connections.
- **Auth0 DbConnections API** — The DbConnections API from Auth0 — 1 operation(s) for dbconnections.
- **Auth0 Deprecated > Authenticate API** — The Deprecated > Authenticate API from Auth0 — 2 operation(s) for deprecated > authenticate.
- **Auth0 Deprecated > Delegated Authentication API** — The Deprecated > Delegated Authentication API from Auth0 — 1 operation(s) for deprecated > delegated authentication.
- **Auth0 Deprecated > Impersonation API** — The Deprecated > Impersonation API from Auth0 — 1 operation(s) for deprecated > impersonation.
- **Auth0 Deprecated > Link Accounts API** — The Deprecated > Link Accounts API from Auth0 — 1 operation(s) for deprecated > link accounts.
- **Auth0 Deprecated > Passwordless API** — The Deprecated > Passwordless API from Auth0 — 2 operation(s) for deprecated > passwordless.
- **Auth0 device-credentials API** — The device-credentials API from Auth0 — 2 operation(s) for device-credentials.
- **Auth0 Device Flow API** — The Device Flow API from Auth0 — 1 operation(s) for device flow.
- **Auth0 email-templates API** — The email-templates API from Auth0 — 2 operation(s) for email-templates.
- **Auth0 emails API** — The emails API from Auth0 — 1 operation(s) for emails.
- **Auth0 event-streams API** — The event-streams API from Auth0 — 7 operation(s) for event-streams.
- **Auth0 events API** — The events API from Auth0 — 1 operation(s) for events.
- **Auth0 flows API** — The flows API from Auth0 — 6 operation(s) for flows.
- **Auth0 forms API** — The forms API from Auth0 — 2 operation(s) for forms.
- **Auth0 grants API** — The grants API from Auth0 — 2 operation(s) for grants.
- **Auth0 groups API** — The groups API from Auth0 — 3 operation(s) for groups.
- **Auth0 guardian API** — The guardian API from Auth0 — 18 operation(s) for guardian.
- **Auth0 hooks API** — The hooks API from Auth0 — 3 operation(s) for hooks.
- **Auth0 jobs API** — The jobs API from Auth0 — 5 operation(s) for jobs.
- **Auth0 keys API** — The keys API from Auth0 — 9 operation(s) for keys.
- **Auth0 log-streams API** — The log-streams API from Auth0 — 2 operation(s) for log-streams.
- …and 36 more, listed in full on the page.

## MCP servers (1)

- **Auth0 MCP Server**

## Agentic access (1)

- **Auth0 Agentic Access** — 458 operations · 272 acting · 11 human-in-the-loop

## Security (4)

- **Auth0 Authentication** — http/oauth2 · 2 schemes
- **Auth0 Domain Security** — TLSv1.3 · HSTS · DMARC
- **Auth0 Vulnerability Disclosure** — Bugcrowd · security.txt · contact published
- **Auth0 Trust Center** — SOC 2, ISO 27001, ISO 27017, ISO 27018, PCI DSS, HIPAA, FedRAMP, GDPR, CSA STAR, FIPS 140

## Plans (1)

- **Auth0 Plans Pricing**

## Use cases (7)

- **Customer Identity** — Add secure, scalable authentication to customer-facing web and mobile applications with social login and passwordless options.
- **Workforce Identity** — Federate with enterprise IdPs for employee authentication with SSO, MFA, and SCIM provisioning.
- **B2B Identity** — Provide multi-tenant identity for SaaS applications with per-customer organization management and custom login flows.
- **API Authorization** — Secure REST and GraphQL APIs using OAuth 2.0 access tokens with audience and scope validation.
- **Machine-to-Machine Auth** — Issue OAuth 2.0 client credentials tokens for service-to-service API authentication without user involvement.
- **AI Agent Identity** — Issue dedicated agent identities; broker user-delegated tokens to third-party APIs via Token Vault; enforce FGA on RAG retrieval.
- **MCP Server Authentication** — Auth for MCP (GA) secures Model Context Protocol servers using Client ID Metadata Registration and On-Behalf-Of Token Exchange.

## Tags

AI Agents, Authentication, Authorization, FGA, Identity Management, MCP, Okta, OpenID Connect, SAML, Security, SCIM

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/auth0/). Scores are computed from the provider's own public artifacts under a published rubric.
