Delegation bounded by an amount instead of time: a capped in-game purchase allowance, a category-scoped grocery basket, and why neither is a running total - OpenFGA holds nothing between checks. The same shape turns up again in a minor's graduated account access as they age.
https://tobytes.com/articles/delegation-bounded-by-amount-fga
#auth0 #fga
Auth0's Passkey APIs let you build passkey sign-in directly into your own UI instead of redirecting to Universal Login. Wrote up how the two fit together, hand-rolled vs pre-built self-service passkey management, and one Allowed Origins (CORS) setting worth checking before you go chasing a WebAuthn bug that isn't there.
https://tobytes.com/articles/building-embedded-passkey-login-with-auth0
#auth0 #passkeys #identity
Running the same OpenFGA model, unchanged, across six industries - and the interesting part isn't that it's reused, it's which primitive gets reused for what. Joint ownership vs a permanent limited role vs an actual delegation, and where flattening them would go wrong.
https://tobytes.com/articles/one-fga-model-twelve-industries
#auth0 #fga #identity
Auth0 Anonymous Sessions sets the auth0_anon cookie only on a genuine create call, never on a renewal - confirmed by testing both explicit session_token and cookie-only renewals. Metadata is fixed at creation too, by design. Same underlying reason for both, and it forces a different pattern for tracking anything (a cart, in my case) across the handoff to login.
https://tobytes.com/articles/auth0-anonymous-sessions-fixed-at-creation
#auth0 #identity #webdev
A login and the person behind it aren't the same security principal. Extending the delegated-access model from earlier this year with person/persona/business, and mapping it to real Auth0 sub claims for a personal login versus one federated through a workplace IdP.
https://tobytes.com/articles/separating-people-from-accounts-persona-model
#auth0 #identity #fga
Auth0 published a guide for running @auth0/auth0-hono on Cloudflare Workers. I built the real thing and hit two gotchas the guide skips: authRequired defaults to true and locks every route including the homepage, and the SDK's cookie handler needs the nodejs_compat flag for an undocumented async_hooks dependency.
https://tobytes.com/articles/auth0-hono-cloudflare-workers-gotchas
#auth0 #cloudflare #oauth
My live Auth0 session and token demo grew three new patterns since I first wrote this up: CIBA against a real Guardian push (now with a Rich Authorization Requests toggle), the Device Authorization Grant, and a comparison against a real Hono app on Cloudflare Workers. The session view also moved out of a single profile page into a sidebar that's visible on every page in the app.
https://tobytes.com/articles/auth0-token-session-demo
#auth0 #oauth #identity
Updated my Auth0 session and token management taxonomy with two grant types I'd left out the first time: CIBA and the Device Authorization Grant. Both are decoupled from the requesting device's own browser but solve different problems. Also added what Rich Authorization Requests (part of Highly Regulated Identity) changes on a CIBA push - structured fields instead of one opaque string.
https://tobytes.com/articles/auth0-session-token-management-options-explained
#auth0 #oauth #identity
Auth0's session_transfer_token generalises from native-to-web handoffs to bridging two different domains on one tenant - but the audience parameter has an undocumented requirement. Name the wrong domain and you get a 200 response that looks like success and isn't.
https://tobytes.com/articles/auth0-cross-domain-sso-session-transfer-token-audience-domain
#auth0 #identity #oauth
Tap 'Open in browser' in a mobile app and get asked to log in again - that's two independent OAuth clients with no shared context.
Auth0's session_transfer_token fixes it: single-use, 60s, IP-bound. Exchange your refresh token for the STT and pass it to /authorize. Full web session, no re-auth.
https://tobytes.com/articles/auth0-native-to-web-sso-session-transfer-token
#Auth0 #identity #oauth
Built a live Auth0 demo with eight integration patterns side by side.
The interesting part: a unified profile page that correlates Traditional, BFF, and SPA sessions via the session_id field on refresh tokens - showing which apps share an Auth0 AS session and which are isolated.
Also covers MRRT exchange ledger, Fingerprint ad-blocker bypass, On-Behalf-Of delegation, and Custom Token Exchange.
https://tobytes.com/articles/auth0-token-session-demo
#Auth0 #OAuth #Identity
OpenID's Shared Signals Framework and Continuous Access Evaluation Profile went final in August 2025. Auth0 has no native role in either direction of the standard.
I built a reference implementation anyway - signed SETs out, verified CAEP signals in, a shared policy enforcement point instead of a heavier authorisation service, and CIBA as the backend-initiated step-up mechanism.
https://tobytes.com/articles/continuous-access-evaluation-for-auth0-caep-ssf-demo
#auth0 #identity #ciba
Part three in the delegated access series.
The approval flow: FGA resolves the approver, Auth0 CIBA sends a Guardian push, approval creates a delegation. Also: why CIBA consent does not persist across sessions, and why that's fine.
https://tobytes.com/articles/delegated-access-approval-auth0-ciba
#Auth0 #CIBA #Identity #FGA
Terence Eden
@Edent__dup_2944@mastodon.social
Longer hair than you. Got the ⏻ symbol into #Unicode. Open Standards / Source / Data geek. Known as @Edent on most social platforms. Bit obsessed with #SolarPower but not quite a #SolarPunk. Please read the link before replying. Yes, that means you!
mastodon.social
I think I've cracked it!
Using #OpenStreetMap as a custom OIDC provider in #Auth0. Which means people can log in to OpenBenches with their #OSM credentials via OAuth.
If you'd like to test it, please visit https://openbenches.org/login
(You don't need to upload a photo.)
You've seen all posts