Overview

The Auth0 integration monitors your identity platform configuration: users, roles, organizations, connections, rules, actions, and logs. LowerPlane uses read-only access via OAuth 2.0 Client Credentials to collect compliance evidence automatically.

Prerequisites

You need Auth0 Dashboard Admin permissions to create a Machine-to-Machine application with the required scopes.

How to Get Your Credentials

1

Log in to Auth0

Log in to your Auth0 Dashboard and select your tenant.
2

Create a Machine-to-Machine Application

Go to Applications > Applications > Create Application. Choose Machine to Machine Applications and authorize it against the Auth0 Management API.
3

Assign permissions

Grant the following scopes:
  • read:users — Read user profiles
  • read:roles — Read role definitions
  • read:organizations — Read organizations
  • read:organization_members — Read organization memberships
4

Copy credentials

Copy the Client ID, Client Secret, and your Domain (e.g., your-tenant.us.auth0.com).

Connecting in LowerPlane

  1. Go to Settings > Integrations in LowerPlane
  2. Find Auth0 under Identity Providers
  3. Enter your Client ID, Client Secret, and Domain
  4. Click Connect
Your Auth0 Domain is visible at the top of the Auth0 Dashboard and typically follows the format your-tenant.region.auth0.com.

What LowerPlane Monitors

Users & Roles

User accounts, role assignments, MFA enrollment, and login activity.

Organizations

Organizations, member assignments, and connection configurations.

Connections & Rules

Identity connections, authentication rules, and custom actions.

Logs

Authentication and management API audit logs.

Frameworks Supported

FrameworkWhat It Proves
SOC 2Access controls and authentication mechanisms are enforced
ISO 27001Identity and access management policies are implemented
HIPAAUser authentication and access logging are in place
GDPRUser consent and data access controls are maintained