Re-verifying identity in-page with a passkey sounds like a small feature until you realise Auth0's own passkey verification route has no concept of who was already logged in. Plus a WebAuthn setting I couldn't find a dashboard control for anywhere, and the one place you can still override it.
Toby Allen
Solutions Engineer at Okta. I write about identity, access management, and security. This site archives my published articles, talks, and presentations.
Series - Indepth Explainers
Latest
What this site's traffic actually shows since the move to Next.js
The stats page on this site only ever showed the last 14 days, which meant every time I looked at it I was looking at noise. I rebuilt it to track lifetime totals properly, and the all-time numbers - covering the time since this site moved off WordPress - turned up a few things I didn't expect.
Six reviews caught the architecture and missed the data
A live-event monitoring dashboard went through six rounds of adversarial review before a line of code shipped - and every one of them was reviewing an argument, not the actual files, for four rounds running.
Auth0 Anonymous Sessions: The Cookieless Transfer Ticket Handoff
Auth0 has documented a second way to carry an anonymous session into login: a transfer ticket, exchanged for a short-lived anon_transfer_token and passed straight to /authorize as a query parameter, with no cookie involved at all.
Ten attempts, one diagram: what fixing an AI-generated image actually taught me
I asked Claude Code to generate a technical architecture diagram with gpt-image-1 for a blog post. Getting one five-box diagram fully correct took ten regenerations, and the version that shipped first was itself wrong - it got a clean render by quietly dropping the exact claim the whole post was about.
Integrating Intercom with Auth0 On-Behalf-Of Token Exchange for a Full Login Audit Trail
Third-party support tools like Intercom are usually bolted onto an application with a shared API key and a loosely-typed user ID. Auth0's On-Behalf-Of token exchange lets you do better: every message a customer sends carries a real, auditable delegation chain back to the login that started it, and a CIBA push puts a human back in the loop for the requests that need one.