I asked Claude Code to build a demo of Auth0's real My Account API, not the Management API with a user token wearing its name. Four separate pieces of tenant configuration and one Early Access MFA policy stood between a correctly-written client and a working token - and the profile endpoint simply isn't there yet.
Toby Allen
Solutions Engineer at Okta. I write about identity, access management, and security. This site archives my published articles, talks, and presentations.
Series - Indepth Explainers
Latest
FGA as an API Gateway Enforcement Point: OpenFGA Behind a Cloudflare Worker
A real Cloudflare Worker in front of a real OpenFGA store, deciding every request's fate before a line of application code runs. The access token carries no permissions claim at all; the allow, deny, or unavailable verdict happens entirely at the gateway.
Embedded Passkey Step-Up, and Forcing User Verification Auth0 Won't Let You Configure
Re-verifying identity in-page with a passkey sounds like a small feature until you realise Auth0's own passkey verification route has no concept of who was already logged in. Plus a WebAuthn setting I couldn't find a dashboard control for anywhere, and the one place you can still override it.
What this site's traffic actually shows since the move to Next.js
The stats page on this site only ever showed the last 14 days, which meant every time I looked at it I was looking at noise. I rebuilt it to track lifetime totals properly, and the all-time numbers - covering the time since this site moved off WordPress - turned up a few things I didn't expect.
Six reviews caught the architecture and missed the data
A live-event monitoring dashboard went through six rounds of adversarial review before a line of code shipped - and every one of them was reviewing an argument, not the actual files, for four rounds running.
Auth0 Anonymous Sessions: The Cookieless Transfer Ticket Handoff
Auth0 has documented a second way to carry an anonymous session into login: a transfer ticket, exchanged for a short-lived anon_transfer_token and passed straight to /authorize as a query parameter, with no cookie involved at all.