# Auth0

> Part of the NocoDB documentation (Product docs > Account & Billing > Authentication ☁ > OpenID Connect). Index of all pages: https://nocodb.com/llms.txt. Any docs page is available as Markdown by adding `.md` to its URL.

URL: https://nocodb.com/docs/product/account-settings/authentication/oidc-sso/auth0
Last updated: 2026-10-03

Configure Auth0 as an OIDC identity provider for NocoDB SSO.

This page gives the steps to configure Auth0 as the Identity service provider for NocoDB.

### NocoDB, Retrieve `Redirect URL`

1. Go to `Account Settings`.
2. Select `Authentication (SSO)`.
3. Click the `New Provider` button. A popup modal opens.
4. In the popup modal, specify a `Display name` for the provider. The login page shows the provider with this name.
5. Copy the `Redirect URL`. You configure it later in the Identity Provider.

<img alt="OIDC SSO Configuration" src={__img0} placeholder="blur" />
<img alt="OIDC SSO Configuration" src={__img1} placeholder="blur" />
<img alt="OIDC SSO Configuration" src={__img2} placeholder="blur" />

### Auth0, Configure NocoDB as an Application

1. Open your [Auth0 account](https://auth0.com/).
   * Go to `Applications` > `Create Application`.
2. In the `Create Application` modal:
   * Select `Regular Web Application`.
   * Click `Create`.
3. On the Quick start screen, go to the `Settings` tab.
   * Copy the `Client ID` and `Client Secret` from the `Basic Information` section.
4. Go to the `Application URIs` section.
   * Below `Allowed Callback URLs`, add the `Redirect URL` that you copied in step(2).
   * Click `Save Changes`.
5. On the `Settings` tab, go to the `Advanced Settings` section. Click the `Endpoints` tab.
   * Copy the `OAuth Authorization URL`, `OAuth Token URL`, `OAuth User Info URL` and `JSON Web Key Set URL`.

### NocoDB, Configure Auth0 as an Identity Provider

1. In NocoDB, open `Account Settings` > `Authentication` > `OIDC`. The "Register OIDC Identity Provider" modal opens. Enter this information:

| NocoDB field        | Value                                                                                 |
| ------------------- | ------------------------------------------------------------------------------------- |
| `Client ID`         | The `Client ID` from step (5) above                                                   |
| `Client Secret`     | The `Client Secret` from step (5) above                                               |
| `Authorization URL` | The `OAuth Authorization URL` from step (7) above                                     |
| `Token URL`         | The `OAuth Token URL` from step (7) above                                             |
| `Userinfo URL`      | The `OAuth User Info URL` from step (7) above                                         |
| `JWK Set URL`       | The `JSON Web Key Set URL` from step (7) above                                        |
| `Scope`             | `openid` `profile` `email` `offline_access`                                           |
| Username Attribute  | The name of the claim that holds the email of the user. The default value is "email." |

The sign-in page now shows the `Sign in with <SSO>` option to users.

<img alt="SAML SSO Configuration" src={__img3} placeholder="blur" />

<Callout type="info">
  Post sign-out, refresh page (for the first time) if you do not see 

  `Sign in with SSO`

   option
</Callout>

For information about Auth0 API Scopes, refer [here](https://auth0.com/docs/secure/tokens/refresh-tokens).

<Callout type="info">
  For more common questions and troubleshooting, see our 

  [SSO FAQ](/docs/product/account-settings/authentication/FAQs)

  .
</Callout>

## Availability

* OIDC SSO is available on **NocoDB Cloud** (Business plan and above) and on licensed self-hosted deployments (Business plan and above). For access, reach [**out to sales team**](https://cal.com/nocodb/sales).
* For users on the **Business plan**, the SSO configuration menu is in the workspace sidebar, at **Settings** > **Single Sign-On (SSO)**. For more information, refer [here](/docs/product/account-settings/authentication#business-plan).
* **Domain Verification Required for Cloud Plans**: Before you configure OIDC SSO, you must verify your domain in NocoDB. This is necessary for both Business and Enterprise plans in the cloud. Only users with email addresses from verified domains can sign in through SSO. For more information, refer to [Domain Verification](/docs/product/account-settings/authentication#domain-verification).

---

## Related pages

- [Okta](https://nocodb.com/docs/product/account-settings/authentication/oidc-sso/okta.md): Configure Okta as an OIDC identity provider for NocoDB SSO.
- [Ping Identity](https://nocodb.com/docs/product/account-settings/authentication/oidc-sso/ping-identity.md): Configure Ping Identity as an OIDC identity provider for NocoDB.
- [Azure AD (Entra)](https://nocodb.com/docs/product/account-settings/authentication/oidc-sso/azure-ad.md): Configure Azure AD as an OIDC identity provider for NocoDB SSO.
