Auth0
Version
This integration utilizes the Auth0 Management API v2.
Base URL
The base URL used for all Auth0 API endpoints contains the Subdomain:https://subdomain.auth0.com/api/v2/
Authentication & Authorization
The DataGrail Auth0 integration connects using OAuth 2.0 with the following credentials: Client ID and Client Secret.
Scopes
The Auth0 integration requires specific scopes that must be granted in order to function for a given capability.
| Scope | Access | Deletion | System Detection |
|---|---|---|---|
read:email_provider | ✅ | ||
read:resource_servers | ✅ | ||
read:connections | ✅ | ||
read:users | ✅ | ✅ | |
read:users_app_metadata | ✅ | ||
read:client_grants | ✅ | ||
read:clients | ✅ | ||
read:client_keys | ✅ | ||
read:logs | ✅ | ||
read:logs_users | ✅ | ||
delete:users | ✅ |
Endpoints Utilized
DataGrail uses the following endpoints to authorize and test the connection:
| Method | Endpoint | Purpose | Docs |
|---|---|---|---|
| POST | https://subdomain.auth0.com/oauth/token | Get token | |
| POST | https://auth0.com/oauth/token | Refresh access token |
Limits
Limits in Auth0 are calculated using the leaky
bucket algorithm. All requests that are made after rate limits have been
exceeded are throttled and an HTTP 429 Too Many Requests error is returned.
Requests succeed again after enough requests have emptied out of the bucket.
- DataGrail supports requests throttling to stay within 70-80% of specified service rate limits.
- DataGrail processes API responses with HTTP 429 status to interrupt requests, waiting and retrying (using an exponential backoff strategy).
Capabilities
Access
DataGrail's Auth0 integration provides Synchronous Access capabilities for the following supported identifier category: Email.Data Interactions
For Access requests, DataGrail will take the following actions:
- Find a user via email.
- Fetch logs for the user.
Endpoints Utilized
| Method | Endpoint | Purpose | Docs |
|---|---|---|---|
| GET | /users-by-email | Search users by email | |
| GET | /users/user_id/logs | Get user's log events |
Deletion
DataGrail's Auth0 integration provides Synchronous Deletion capabilities for the following supported identifier category: Email.Data Interactions
For Deletion requests, DataGrail will take the following actions:
- Delete a user permanently from Auth0.
Endpoints Utilized
System Detection
DataGrail provides continuous system detection, delivering a real-time inventory of your data assets.Data Interactions
DataGrail's System Detection process runs once daily and performs the following actions:
- Retrieve clients (applications and SSO integrations) of "non_interactive" and "auth0" types.
- Retrieve connections, excluding
auth0,datagrailandUsername-Password-Authentication. - Retrieve APIs (resource servers), excluding
datagrail.ioandauth0.com. - Retrieve email provider details.
Endpoints Utilized
| Method | Endpoint | Purpose | Docs |
|---|---|---|---|
| GET | /clients | Get clients | |
| GET | /connections | Get all connections | |
| GET | /emails/provider | Get email provider | |
| GET | /resource-servers | Get resource servers |
Disclaimer: The information contained in this message does not constitute as legal advice. We would advise seeking professional counsel before acting on or interpreting any material.