Auth0's Passkey APIs let you build passkey sign-in directly into your own UI instead of redirecting to Universal Login. Here's how that fits alongside Universal Login, what self-service passkey management looks like hand-rolled versus with Auth0's official pre-built components, and one Allowed Origins (CORS) setting worth checking before you go looking for a WebAuthn bug that isn't there.
Toby Allen
Solutions Engineer at Okta. I write about identity, access management, and security. This site archives my published articles, talks, and presentations.
Series - Indepth Explainers
Latest
One authorisation model, a dozen industries
It's easy to claim an authorisation model is generic. It's more convincing to run the exact same model, unmodified, across media, healthcare, financial services, telco, retail and legal case management, and show the tests passing every time.
Auth0 Anonymous Sessions: Cookies and Metadata Are Both Fixed at Creation
An anonymous session's cookie and its metadata are both set once, at the moment the session is created, and neither one changes again for the rest of that session's life. That single fact reshapes how you have to track state across the handoff into a known identity.
Separating people from accounts: why a login isn't a person
The delegated-access series treated the authenticated login as the whole security principal. It isn't quite. The same real person routinely holds more than one login, and an authorisation model that can't tell them apart ends up merging blast radii it shouldn't.
Decoupling Social Post Scheduling From Blog Deploys
This blog's cross-posting to Bluesky, Mastodon, and LinkedIn used to only fire as a side effect of a successful Vercel deploy, which meant a social post could never exist without a brand new article behind it. I pulled the two apart into an independent queue, and found neither LinkedIn nor Bluesky actually auto-fetch a link's image the way the compose box makes you assume.
Deploying @auth0/auth0-hono to Cloudflare Workers: Three Things the Guide Doesn't Mention
Auth0 published a guide for running a confidential client on Cloudflare Workers with @auth0/auth0-hono. I built the guide's example for real and hit three things it doesn't mention — a middleware default that locks down every route, an undocumented Node API dependency, and a session model that changes what revoking a session actually means.