Overview
This guide connects a CrewAI Factory installation directly to Auth0 through OpenID Connect.Prerequisites
- Administrative access to an Auth0 tenant
- Your CrewAI Factory installation URL
Create the Auth0 Application
- In the Auth0 Dashboard, go to Applications → Applications.
- Select Create Application.
- Choose Regular Web Application.
- Under Application URIs, configure:
- Allowed Callback URLs:
https://<your-domain>/auth/auth0/callback - Allowed Logout URLs:
https://<your-domain> - Allowed Web Origins:
https://<your-domain>
- Allowed Callback URLs:
- Save the application.
- Domain →
AUTH0_DOMAIN - Client ID →
AUTH0_CLIENT_ID - Client Secret →
AUTH0_CLIENT_SECRET
Configure Group Claims for Team Mapping
Auth0 Core RBAC roles can supply values for CrewAI Team mapping. In User Management → Roles, create the roles that should control Team access and assign them to users. Auth0 does not add role names to ID tokens automatically. Create a Post Login Action that emits the complete role list as a namespaced custom claim:https://crewai.example.com with a URI namespace controlled by your organization. Deploy the Action and add it to Actions → Flows → Login.
Set SSO_GROUP_MEMBERSHIP_CLAIM_NAME to the complete claim name:
If an upstream identity provider is already the source of truth for groups, preserve those groups instead of recreating them as Auth0 roles. Groups provisioned through Auth0 inbound SCIM can be emitted from a Post Login Action as a namespaced claim. CrewAI does not provide a SCIM endpoint; provisioning remains between the upstream provider and Auth0.
Configure Helm Values
Add the following values to your Factory configuration:AUTH0_NAMESPACE is the Auth0 API identifier used as the OAuth audience. Use the same URI namespace when defining namespaced claims.
Map Auth0 Values to CrewAI Teams
Follow SSO Team Mapping and use each exact role or group value emitted in the configured claim as the CrewAI mapping’sgroup_name.
An Auth0 role does not become a CrewAI RBAC role directly. It grants membership in the mapped Team, and the user inherits the CrewAI roles granted to that Team.
Verify Login
After installing or upgrading CrewAI Factory, sign in through Auth0 and verify:- The callback returns to your Factory URL.
- The ID token contains the configured namespaced claim as an array.
- Users with mapped values join the expected CrewAI Teams.
- Users with an empty array lose only JIT-managed Team memberships.
