| Authentication |
| Product focus and ideal customer | One identity layer for products, users, and services Combines hosted customer identity, an account-security portal, low-code authorization, Organizations on Business and above, and machine identity. Enterprise adds SSO, provisioning, and deployment control. | Available Broad managed CIAM Serves B2C and B2B applications with Organizations, enterprise connections, provisioning features, and optional advanced services. |
| Authentication methods | Password, passwordless, social, MFA, passkeys, and SSO Includes email/password, single-use magic links, four social providers, TOTP MFA, trusted devices, and passkeys. Business and Enterprise plans add SSO. | Database, passwordless, social, and enterprise connections Supports email, username, or phone identities, passkeys, email/SMS passwordless, social providers, and a broad enterprise-provider catalog. Some newer database-integrated passwordless flows remain Early Access. |
| OAuth/OIDC and API protection | One OAuth layer for users, APIs, and services Authorization Code with PKCE, Refresh Token, and Client Credentials flows share APIs, audiences, scopes, signed JWTs, JWKS validation, and optional introspection. | OAuth 2.0, OIDC, and JWT API authorization Issues scoped JWT access tokens for registered APIs and supports standard interactive and service flows; the Authentication API also documents FAPI and SAML. |
| MFA and passkeys | Built-in MFA, recovery, trusted devices, and passkeys Authenticator-app MFA, recovery codes, configurable remembered devices, and WebAuthn enrollment and sign-in are managed alongside the user account. | Broad MFA factor set and passkeys Offers TOTP, email, phone, push, WebAuthn, recovery codes, and Duo. Passkeys are listed on every plan; Pro and Enterprise MFA capabilities are plan-gated. |
| Authorization |
| Roles and permissions | Low-code roles and fine-grained permissions Teams manage roles and direct or inherited permissions in the admin console or API, then emit them as token claims alongside OAuth scopes. | Plan, add-on, or setup dependent Core RBAC with optional FGA Roles and API permissions can be assigned through the Dashboard or Management API and included in access tokens. Public pricing lists Role Management from Essentials upward. |
| Sessions and revocation | User-visible session controls and API revocation Users and administrators can inspect and revoke browser and OAuth sessions. APIs can reject revoked tokens on their next introspection check; locally validated JWTs remain valid until expiry. | Available Session and refresh-token revocation Sessions and associated refresh tokens can be revoked. Self-contained JWT access tokens remain valid until expiry and should be short-lived where that matters. |
| Branding |
| User self-service | Hosted profile and account-security portal Users manage profile data, password, linked identities, passkeys, browser and OAuth sessions, data export, and account deletion in the same branded hosted experience. | Plan, add-on, or setup dependent API building blocks for an application-owned portal The My Account API supports self-service account and authentication-method features, while Universal Login hosts password and verification flows. A complete hosted profile portal is not documented. |
| White-label branding | Deep branding across login and account journeys Every plan includes themes, brand assets, seven languages, and advanced per-page and per-state HTML/CSS for both hosted login and the profile portal. | Highly configurable Universal Login No-code themes, branding APIs, localized text, and Liquid page templates support deep login customization. Some advanced signup and login customization is plan-gated. |
| Custom domains | Customer-portal custom-domain wizard on every plan Customers configure their domain through a simple portal workflow, with Guardhouse support available when DNS or rollout needs attention. | Available One custom domain on current plans Current pricing lists one domain on Free, Essentials, and Professional; Free requires card verification. Multiple domains are an Enterprise capability. |
| Transactional email | Branded email with 17 editable templates Teams can use SMTP, Postmark, SendGrid, or Amazon SES and preview or test verification, recovery, invitation, security, and account emails. | Available Customizable identity-workflow emails Provides templates for verification, recovery, invitations, passwordless, MFA, and security events. Custom templates require an external email provider and are HTML-only. |
| Pricing |
| Pricing model | Published plans with substantial included usage Startup is $50/€45 per month with 100,000 MAU, 10,000 M2M tokens, and 1,000,000 introspections. Business is $250/€225 with 500,000 MAU, 100,000 M2M tokens, and 5,000,000 introspections; Enterprise is contract-priced. | Plan, add-on, or setup dependent MAU tiers, feature plans, and add-ons The Auth0 B2C monthly selector displayed $35 for Essentials and $240 for Professional at 500 MAU; Free allows up to 25,000 MAU. Prices change with use case, MAU tier, billing cycle, and add-ons. |
| Developer experience |
| User administration | Integrated administration console and API Admins can search, invite, create, update, block, anonymize, delete, reset credentials, and assign roles or permissions without a separate user-management product. | Available Dashboard and Management API Admins can create, view, modify, search, block, and delete users, subject to connection and plan behavior. |
| Webhooks | Operational user lifecycle webhooks User-created and user-updated events include HMAC signatures, retry controls, secret rotation, and delivery history. | Plan, add-on, or setup dependent Event Streams to webhooks and other destinations Can forward supported identity events to webhooks, AWS EventBridge, or Actions. The current Dashboard and documentation label Event Streams as Early. |
| SDKs and frameworks | Available First-party SDKs plus standards-based integration .NET/ASP.NET Core and React are the primary SDKs. Node.js, React Native, and Python are beta, with FastAPI and Flask helpers; standard OIDC works beyond that set. | Large maintained SDK and quickstart catalog Covers major SPA, server-rendered web, backend API, native/mobile, and Management API stacks. |
| Migration assistance | Migration assistance and bulk import across plans Guardhouse can support export mapping, bulk user import, validation, and cutover. Scope and responsibilities are agreed for the source system and rollout. | Available Export tooling, Professional Services, and partners User profiles can be exported by job. Password hashes and MFA secrets require an eligible, encrypted support-request process. Professional Services and partners are available separately. |
| Support and ecosystem | Direct support aligned to the plan Business includes priority support. Enterprise support, account management, and any response commitments are tailored to the customer agreement. Migration assistance is scoped directly with the Guardhouse team. | Layered support, Marketplace, and partners Free includes community support, paid self-service plans add standard support, and Enterprise can add Premier Success. A broad Marketplace and partner network extend the platform. |
| M2M and AI |
| M2M authentication | Human and machine identity in the same plan Scoped Client Credentials use the same APIs, audiences, and permissions as user access. Startup includes 10,000 M2M tokens per month; Business includes 100,000. | Plan, add-on, or setup dependent Client Credentials with issuance quotas Current pricing lists 1,000 included M2M authentications on Free and Essentials and 5,000 on Professional and Enterprise. M2M add-ons are limited to Professional and Enterprise. |
| AI agents and MCP servers | OAuth protection for agents, APIs, and MCP servers Agent and System/MCP resource types use Client Credentials, scopes, signed JWTs, JWKS validation, and optional introspection in the same identity platform. | Dedicated agent and MCP capabilities Auth for MCP covers discovery, registration, scoped access, and token exchange; Token Vault handles delegated third-party API tokens. Exact access varies by plan, add-on, and feature release stage. |
| Deployment |
| Cloud regions | Available Straightforward USA or EU cloud choice Teams choose the USA or EU Guardhouse Cloud region during setup, then move to Enterprise deployment options when they need more infrastructure control. | Six public-cloud regions plus private-cloud choices Public Cloud supports Australia, Canada, Europe, Japan, the UK, and the US. Private Cloud adds AWS and Azure regional options by contract. |
| Self-hosting and deployment ownership | Enterprise deployment choice and BYOK Enterprise can be customer-operated as a Docker deployment or operated by LegioSoft. The hosting model and responsibilities are tailored to customer requirements; customer-controlled encryption keys are also available. | Plan, add-on, or setup dependent Public Cloud or Auth0-managed Private Cloud Private Cloud is a dedicated managed service on AWS or Azure. Auth0 does not document a customer-operated self-hosted distribution. |