Auth0
Hosted identity with enterprise SSO, MFA and fine-grained rules.
The rule
This is the whole text, exactly as your agent receives it. Nothing is held back for the paid tier.
Tokens
- Always request an `audience`. Without it Auth0 returns an opaque token your API cannot verify — the single most common integration failure.
- The API verifies signature and
audandiss. A correctly signed token issued for a different API is still not for you. - Never send an ID token to an API. ID tokens describe the user; access tokens authorise the call.
Secrets
- The client secret is server-side only. Browser and mobile apps use PKCE and hold no secret.
- Never log a token.
Claims
- Custom claims must be namespaced with a URL, or they are silently dropped.
- Roles are not in the token by default; add them with an Action.
Sessions
offline_accessin the scope, or sessions end when the access token expires and users are logged out at apparently random moments.- Clear cached user-scoped state on logout.
Never
- Never authorise from a client-held user id; use the verified
subclaim. - Never share one tenant across environments.
6 formats, one per tool
Each tab is the file that tool actually reads, at the path it actually looks in. Knowing where each one looks is most of the work of supporting it.
---
description: Auth0 conventions
globs: ["src/features/auth/**", "src/services/**", "app/api/auth/**"]
alwaysApply: false
---
# Auth0
## Tokens
- **Always request an `audience`.** Without it Auth0 returns an opaque token
your API cannot verify — the single most common integration failure.
- The API verifies signature **and** `aud` **and** `iss`. A correctly signed
token issued for a different API is still not for you.
- Never send an ID token to an API. ID tokens describe the user; access tokens
authorise the call.
## Secrets
- The client secret is server-side only. Browser and mobile apps use PKCE and
hold no secret.
- Never log a token.
## Claims
- Custom claims must be namespaced with a URL, or they are silently dropped.
- Roles are not in the token by default; add them with an Action.
## Sessions
- `offline_access` in the scope, or sessions end when the access token expires
and users are logged out at apparently random moments.
- Clear cached user-scoped state on logout.
## Never
- Never authorise from a client-held user id; use the verified `sub` claim.
- Never share one tenant across environments.
Hand-written by the module author, frontmatter and all. It is the source the four derived formats are rendered from, so a correction lands here first.
What else this module writes
The rule is one file of several. Selecting Auth0 contributes all of this too — merged with every other module you pick, with conflicts resolved rather than duplicated.
AUTH0_DOMAINrequiredTenant domain.AUTH0_CLIENT_IDrequiredApplication client id. Public.AUTH0_AUDIENCErequiredAPI identifier. Omitting it returns an opaque token your API cannot verify.AUTH0_CLIENT_SECREToptionalServer-rendered apps only. Never in a SPA or mobile bundle.AUTH0_SECREToptionalEncrypts the session cookie in server-rendered apps.Advisory history
Every time this rule turned out to be wrong, and what we did about it.
This rule has been accurate since it was published. That is a fact about the rule, not a promise about the future — which is the whole reason this section exists.
Pro tells you the day a correction lands that affects a repo you actually have.
See what Pro adds →Rules people add alongside this one
The wizard picks the rest of the stack with you, writes all 6 formats, and leaves a manifest so check can tell you when any of it drifts.