Skip to content

Connect Auth0 to Black Cat SSPM

Version française

Connect your Auth0 tenant so Black Cat can review users, multi-factor enforcement, roles, applications, connections and tenant session settings.

≈ 10 min · audit access · no write-capable permission

What Black Cat reads, and why

PermissionWhat it lets Black Cat doStatus
read:usersLets Black Cat list users, their multi-factor enrolment and last login.Required
read:rolesLets Black Cat list the roles defined in your tenant and the privileges they carry.Required
read:role_membersLets Black Cat see which users hold each role.Required
read:clientsLets Black Cat review applications, their grant types and callback URLs.Required
read:connectionsLets Black Cat list the identity connections your tenant accepts.Required
read:connections_optionsLets Black Cat review each connection's password policy and brute-force protection.Required
read:tenant_settingsLets Black Cat review tenant-wide settings such as session lifetime and dynamic client registration.Required
read:logsLets Black Cat review recent tenant activity for administrative changes and audit coverage.Required
read:guardian_factorsLets Black Cat see which multi-factor methods are enabled for the tenant.Required
read:mfa_policiesLets Black Cat see whether multi-factor authentication is required of every user.Required

What you'll need

  • Auth0 tenant domain Required — Your tenant address, for example acme.eu.auth0.com.
  • Machine-to-machine client ID Required — Shown on the read-only application you create for Black Cat in the Auth0 dashboard.
  • Client secret Required — Issued with the client ID on the same read-only Auth0 application.

Where to create it

What we check on Auth0 →

Other setup guides

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications are based on publicly available documentation and may change over time.

See your own SaaS posture in 10 minutes

Run a free posture scan — no credit card required, read-only-by-default access you can revoke any time.

Run a free posture scan