{"ast":{"$$mdtype":"Tag","name":"article","attributes":{},"children":[{"$$mdtype":"Tag","name":"Heading","attributes":{"level":1,"id":"configure-sso-with-auth0-oidc","__idx":0},"children":["Configure SSO with Auth0 OIDC"]},{"$$mdtype":"Tag","name":"ConfigOptionRequirements","attributes":{"products":["Redoc","Revel","Reef","Realm"],"plans":["Enterprise","Enterprise+"]},"children":[]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Follow this guide to configure an SSO integration between Auth0 OpenID Connect protocol and Reunite."]},{"$$mdtype":"Tag","name":"Admonition","attributes":{"type":"warning","name":"Avoid lockout"},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Before completing the Reunite setup, ensure you ",{"$$mdtype":"Tag","name":"Link","attributes":{"href":"#preserve-the-owner-organization-role"},"children":["preserve the Owner organization role"]}," to avoid getting locked out of your organization."]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"add-auth0-as-a-corporate-identity-provider-in-reunite","__idx":1},"children":["Add Auth0 as a corporate identity provider in Reunite"]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["In Reunite, navigate to your organization's ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Overview"]}," page."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Select ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["SSO and login"]}," in the navigation menu on the left side of the page."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Add"]}," in the Guest or Corporate Identity Provider section."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Select ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["OpenID Connect"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Enter a name for your identity provider."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Select the default ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Organization Role"]}," for users who log in with the identity provider."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["(Optional) Enter the name of the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Default Team"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Copy the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Callback URL"]},"."," ","Keep this tab open and continue with the Auth0 configuration in a new tab."]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"create-an-application-in-auth0","__idx":2},"children":["Create an application in Auth0"]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Log in to Auth0 and select ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Applications"]}," from the menu on the left side of the page."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Create Application"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Choose ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Regular Web Applications"]},", and click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Create"]},"."]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"copy-settings-between-auth0-and-reunite","__idx":3},"children":["Copy settings between Auth0 and Reunite"]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["In Auth0's ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Application Settings"]}," tab, scroll to ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Application URIs"]}," and paste the previously copied callback URL into the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Allowed Callback URLs"]}," field."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Click the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Save Changes"]}," button."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Scroll to ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Advanced Settings"]}," > ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Endpoints"]},", copy the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["OpenID Configuration"]},", and paste it in Reunite into the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Configuration (.well-known)"]}," field."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["In Auth0, scroll to ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Basic Information"]},", copy the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Client ID"]}," and ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Client Secret"]},", and paste them into Reunite."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["In Reunite's ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["RBAC Teams Claim Name"]}," field, enter ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["https://redocly.com/sso/teams"]},"."]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"preserve-the-owner-organization-role","__idx":4},"children":["Preserve the Owner organization role"]},{"$$mdtype":"Tag","name":"Admonition","attributes":{"type":"danger","name":"Critical step"},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Complete this step before clicking ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Save"]}," in Reunite to prevent getting locked out of your organization."]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["To prevent Auth0 from changing users' roles to the default organization role specified in the SSO settings:"]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["In Auth0, navigate to ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["User Management"]}," > ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Roles"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Create a role named ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["redocly.owners"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Navigate to ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Users"]}," > ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Roles"]}," and assign the ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["redocly.owners"]}," role to users with an Owner role in your organization."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Return to Reunite and click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Save"]}," to complete the identity provider setup."]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"setup-an-action-for-your-application","__idx":5},"children":["Setup an Action for your application"]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["In Auth0, navigate to ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Actions"]}," > ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Library"]},", then click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Create Action"]}," and select ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Build from Scratch"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Add a name for your action."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["In the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Trigger"]}," drop-down, select ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Login/Post Login"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Create"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Add the following code to the action and click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Deploy"]},":",{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"data-language":"js","header":{"controls":{"copy":{}}},"source":"exports.onExecutePostLogin = async (event, api) => {\nconst namespace = 'https://redocly.com/sso';\nif (event.authorization && event.authorization.roles) {\n  api.idToken.setCustomClaim(`${namespace}/teams`, event.authorization.roles);\n}\n};\n","lang":"js"},"children":[]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Navigate to ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Actions"]}," > ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Triggers"]},", and select ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["post-login"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Add Action"]},", select the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Custom"]}," tab, and drag and drop your action between ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Start"]}," and ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Complete"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Apply"]},"."]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"resources","__idx":6},"children":["Resources"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":[{"$$mdtype":"Tag","name":"Link","attributes":{"href":"/docs/realm/reunite/organization/sso/sso"},"children":["Single sign-on and login"]}]}," - Understand different identity provider types in Reunite and how they integrate with your project authentication"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":[{"$$mdtype":"Tag","name":"Link","attributes":{"href":"/docs/realm/reunite/organization/sso/add-idp"},"children":["Add identity providers"]}]}," - Step-by-step guide for adding identity providers in Reunite for centralized authentication management"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":[{"$$mdtype":"Tag","name":"Link","attributes":{"href":"/docs/realm/reunite/organization/sso/configure-sso"},"children":["Configure project SSO"]}]}," - Enable multiple identity provider types to give users flexible authentication options for your projects"]}]}]},"frontmatter":{"products":["Redoc","Revel","Reef","Realm"],"plans":["Enterprise","Enterprise+"]},"tagList":["admonition","configOptionRequirements"],"title":"Configure SSO with Auth0 OIDC","lastModified":"2026-10-01T23:00:57.000Z"}