Achieve Single Sign-On Between Applications in Auth0

Overview

Single Sign-On (SSO) allows users to authenticate seamlessly across multiple applications. Achieving SSO depends on whether the applications share the same connection or use different connections. Configure silent authentication and a custom domain for shared connections, or understand the limitations of account linking for different connections.

Applies To

  • Auth0
  • Single Sign-On (SSO)
  • Multiple Applications

Solution

How does Auth0 handle SSO across multiple applications with the same connection?

If all applications use the same database connection, SSO functions seamlessly. Configure silent authentication to avoid visible redirects. Silent authentication relies on an invisible iframe to issue a token using the session in Auth0. Configure a custom domain when using silent authentication. A custom domain allows the application to share the same origin as the Auth0 tenant and prevents browsers from blocking third-party cookies.

 

SSO Behaves Differently Across Multiple Applications With Different Connections

Account linking provides consistency across different connections for an individual user, but it does not automatically enable SSO between applications that use different connections. Review the following scenario to understand how applications with different connections interact.

  • App1 uses only a database connection.
  • App2 uses only a passwordless connection.
  • A user's database account links with their passwordless account.

In this scenario, SSO does not function between App1 and App2. The authentication flow proceeds as follows when SSO fails between applications with different connections.

  1. The user logs into App1 with database credentials.
  2. When accessing App2, the user must log in with passwordless credentials. Auth0 does not accept the existing session from the database connection for App2.
  3. Once the user authenticates via passwordless, Auth0 issues the user profile in the token from the primary identity (the database connection in this case).

Recommended content

No recommended content found...