Auth0

Hosted identity with enterprise SSO, MFA and fine-grained rules.

adds it to an existing project · no account needed
Currentas published in v1.5.1

The rule

This is the whole text, exactly as your agent receives it. Nothing is held back for the paid tier.

Tokens

  • Always request an `audience`. Without it Auth0 returns an opaque token your API cannot verify — the single most common integration failure.
  • The API verifies signature and aud and iss. A correctly signed token issued for a different API is still not for you.
  • Never send an ID token to an API. ID tokens describe the user; access tokens authorise the call.

Secrets

  • The client secret is server-side only. Browser and mobile apps use PKCE and hold no secret.
  • Never log a token.

Claims

  • Custom claims must be namespaced with a URL, or they are silently dropped.
  • Roles are not in the token by default; add them with an Action.

Sessions

  • offline_access in the scope, or sessions end when the access token expires and users are logged out at apparently random moments.
  • Clear cached user-scoped state on logout.

Never

  • Never authorise from a client-held user id; use the verified sub claim.
  • Never share one tenant across environments.

6 formats, one per tool

Each tab is the file that tool actually reads, at the path it actually looks in. Knowing where each one looks is most of the work of supporting it.

.cursor/rules/auth0.mdchand-written
---
description: Auth0 conventions
globs: ["src/features/auth/**", "src/services/**", "app/api/auth/**"]
alwaysApply: false
---

# Auth0

## Tokens

- **Always request an `audience`.** Without it Auth0 returns an opaque token
  your API cannot verify — the single most common integration failure.
- The API verifies signature **and** `aud` **and** `iss`. A correctly signed
  token issued for a different API is still not for you.
- Never send an ID token to an API. ID tokens describe the user; access tokens
  authorise the call.

## Secrets

- The client secret is server-side only. Browser and mobile apps use PKCE and
  hold no secret.
- Never log a token.

## Claims

- Custom claims must be namespaced with a URL, or they are silently dropped.
- Roles are not in the token by default; add them with an Action.

## Sessions

- `offline_access` in the scope, or sessions end when the access token expires
  and users are logged out at apparently random moments.
- Clear cached user-scoped state on logout.

## Never

- Never authorise from a client-held user id; use the verified `sub` claim.
- Never share one tenant across environments.

Hand-written by the module author, frontmatter and all. It is the source the four derived formats are rendered from, so a correction lands here first.

What else this module writes

The rule is one file of several. Selecting Auth0 contributes all of this too — merged with every other module you pick, with conflicts resolved rather than duplicated.

Environment
AUTH0_DOMAINrequiredTenant domain.
AUTH0_CLIENT_IDrequiredApplication client id. Public.
AUTH0_AUDIENCErequiredAPI identifier. Omitting it returns an opaque token your API cannot verify.
AUTH0_CLIENT_SECREToptionalServer-rendered apps only. Never in a SPA or mobile bundle.
AUTH0_SECREToptionalEncrypts the session cookie in server-rendered apps.
Dependencies
Depends on the rest of the stack — this module installs different packages depending on what else you select, so there is no single list to show.
Folders
src/features/auth/screens/src/hooks/auth/

Advisory history

Every time this rule turned out to be wrong, and what we did about it.

No corrections yet

This rule has been accurate since it was published. That is a fact about the rule, not a promise about the future — which is the whole reason this section exists.

Pro tells you the day a correction lands that affects a repo you actually have.

See what Pro adds →

Rules people add alongside this one

Put this rule in a real project

The wizard picks the rest of the stack with you, writes all 6 formats, and leaves a manifest so check can tell you when any of it drifts.