Auth0
For the software your own team ships, Auth0 is where the third-party connections live. Urengi reads the tenant's applications and social or enterprise connections, so an identity provider you depend on is reviewed like any other vendor.
- Category
- Identity & SSO
- Auth method
- Machine-to-machine token
- Direction
- Read-only
- Sync frequency
- Daily
- Scopes requested
- 3
- Available on
- Growth and Enterprise
- Maintained by
- Urengi
What the Auth0 integration does
Three reads aimed at the dependencies your product inherits.
Applications as dependencies
Every application in the tenant is listed with its type and the connections it allows, so a login path nobody documented stops being invisible.
Connections are vendors too
Social and enterprise connections are third parties in your auth path. Each one is queued for review with the applications that rely on it attached.
Tenant drift reopens the review
A new connection or a changed grant type is a change to your attack surface. Urengi reopens rather than waiting for someone to mention it.
Exactly what Urengi can see
Three read-only scopes against the Management API. No user data leaves your tenant.
Urengi reads
- Application names, types and grant types
- Connection names and strategies
- Tenant name and region
Urengi writes
- Nothing — this connection is read-only
Urengi never touches
- End-user profiles, emails or metadata
- Logs, sessions or refresh tokens
- Rules, actions or hooks
- Anything after you revoke the client grant
Connect it in four steps
One authorisation, one field mapping, and a test sync you run yourself.
01
Authorise the connection
Open Auth0 from this page and approve the scopes listed above — OAuth in a browser tab, or a scoped API key you paste. An admin approves them once.
02
Choose what syncs
Pick the projects, spaces or accounts Urengi should watch. Narrow is fine to start with; widening it later does not re-authorise anything.
03
Map your fields
Match owners, cost centres and tiers to what Urengi already tracks. Defaults arrive pre-filled from the first sync, so most teams change nothing.
04
Run a test sync
Pull one record and check it landed on the right review. The audit entry confirms the mapping before a real vendor is touched.
Your token, your rules.
Urengi stores the Auth0 token encrypted at rest under a per-tenant key and never replays it outside the scopes you approved. Revoke the app in Auth0 and every Urengi write stops within seconds — the audit log keeps the history, the connection simply ends.
Read the security statement- SOC 2 Type II
- audited annually
- Per-tenant keys
- no shared secrets
- Revocable in Auth0
- one click, no ticket
- EU or US residency
- chosen at signup