> ## Documentation Index
> Fetch the complete documentation index at: https://enterprise-docs.crewai.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Auth0 SSO

> Configure Auth0 as the authentication provider for CrewAI Factory.

## Overview

This guide connects a CrewAI Factory installation directly to Auth0 through OpenID Connect.

## Prerequisites

* Administrative access to an Auth0 tenant
* Your CrewAI Factory installation URL

## Create the Auth0 Application

1. In the [Auth0 Dashboard](https://manage.auth0.com), go to **Applications** → **Applications**.
2. Select **Create Application**.
3. Choose **Regular Web Application**.
4. Under **Application URIs**, configure:
   * **Allowed Callback URLs:** `https://<your-domain>/auth/auth0/callback`
   * **Allowed Logout URLs:** `https://<your-domain>`
   * **Allowed Web Origins:** `https://<your-domain>`
5. Save the application.

From the application settings, copy:

* **Domain** → `AUTH0_DOMAIN`
* **Client ID** → `AUTH0_CLIENT_ID`
* **Client Secret** → `AUTH0_CLIENT_SECRET`

## Configure Group Claims for Team Mapping

Auth0 Core RBAC roles can supply values for CrewAI Team mapping. In **User Management** → **Roles**, create the roles that should control Team access and assign them to users.

Auth0 does not add role names to ID tokens automatically. Create a **Post Login Action** that emits the complete role list as a namespaced custom claim:

```javascript theme={null}
exports.onExecutePostLogin = async (event, api) => {
  const roles = event.authorization?.roles ?? [];

  api.idToken.setCustomClaim(
    "https://crewai.example.com/roles",
    roles
  );
};
```

Replace `https://crewai.example.com` with a URI namespace controlled by your organization. Deploy the Action and add it to **Actions** → **Flows** → **Login**.

Set `SSO_GROUP_MEMBERSHIP_CLAIM_NAME` to the complete claim name:

```yaml theme={null}
envVars:
  SSO_GROUP_MEMBERSHIP_CLAIM_NAME: "https://crewai.example.com/roles"
```

Always emit the claim, including an empty array when the user has no roles.

<Note>
  If an upstream identity provider is already the source of truth for groups, preserve those groups instead of recreating them as Auth0 roles. Groups provisioned through Auth0 inbound SCIM can be emitted from a Post Login Action as a namespaced claim. CrewAI does not provide a SCIM endpoint; provisioning remains between the upstream provider and Auth0.
</Note>

See Auth0's documentation for [Authorization Core RBAC](https://auth0.com/docs/manage-users/access-control/configure-core-rbac), [Post Login Actions](https://auth0.com/docs/customize/actions/explore-triggers/post-login), and [custom claims](https://auth0.com/docs/secure/tokens/json-web-tokens/create-custom-claims).

## Configure Helm Values

Add the following values to your Factory configuration:

```yaml theme={null}
envVars:
  AUTH_PROVIDER: "auth0"
  AUTH0_DOMAIN: "your-tenant.auth0.com"
  AUTH0_CLIENT_ID: "<Auth0 client ID>"
  AUTH0_NAMESPACE: "https://crewai.example.com"
  SSO_GROUP_MEMBERSHIP_CLAIM_NAME: "https://crewai.example.com/roles"

secrets:
  AUTH0_CLIENT_SECRET: "<Auth0 client secret>"
```

`AUTH0_NAMESPACE` is the Auth0 API identifier used as the OAuth audience. Use the same URI namespace when defining namespaced claims.

<Warning>
  `AUTH0_CLIENT_SECRET` belongs under `secrets:`. Do not place it under `envVars:`, where it would be stored in a ConfigMap.
</Warning>

## Map Auth0 Values to CrewAI Teams

Follow [SSO Team Mapping](/features/sso-team-mapping) and use each exact role or group value emitted in the configured claim as the CrewAI mapping's `group_name`.

An Auth0 role does not become a CrewAI RBAC role directly. It grants membership in the mapped Team, and the user inherits the CrewAI roles granted to that Team.

## Verify Login

After installing or upgrading CrewAI Factory, sign in through Auth0 and verify:

1. The callback returns to your Factory URL.
2. The ID token contains the configured namespaced claim as an array.
3. Users with mapped values join the expected CrewAI Teams.
4. Users with an empty array lose only JIT-managed Team memberships.
