Auth0
Auth0 is an identity platform for adding sign-up, login and access control to your applications. With Weld you can sync your Auth0 users, login activity, applications, roles and organizations into your data warehouse, and join them with your product and billing data to report on sign-ups, active users and who has access to what.
Features
| Feature name | Supported | |
|---|---|---|
| Column Hashing | True | Column level |
| Blocking | True | Column level |
| Incremental | True | |
| Custom data | False | |
| History | True | |
| ReSync | True | Table level |
| Templates | False |
Data Schema
Setup Guide - ELT
Prerequisites
You need access to the Auth0 Dashboard of the tenant you want to sync, with permission to create applications. Weld connects through a Machine to Machine application that you create for it, and only reads from Auth0 — it never writes back.
Step 1 - Create a Machine to Machine application
-
Sign in to the Auth0 Dashboard and select the tenant you want to sync.
-
Go to Applications → Applications and click Create Application.
-
Give it a name, for example
Weld, choose Machine to Machine Applications and click Create. -
When asked which API to authorize, select Auth0 Management API.
-
Select the following permissions and click Authorize:
read:users,read:logs,read:logs_users,read:stats,read:clients,read:client_grants,read:connections,read:grants,read:organizations,read:organization_members,read:organization_member_roles,read:roles,read:resource_servers,read:actions,read:log_streams,read:event_streams -
Open the application's Settings tab and copy the Domain, Client ID and Client Secret.
Leave out read:client_keys, read:client_credentials, read:user_idp_tokens and read:connections_options. They only expose secrets, which Weld never syncs: client secrets, signing secrets, identity provider tokens and log stream credentials are left out of your warehouse even when these permissions are granted.
Step 2 - Create the connection
- In the Weld app, navigate to Connections and click + New Connection.
- Search for Auth0 and select it.
- Enter the destination schema name of your choice. This name is used to identify the connection in future syncs.
- Enter the Domain, for example
my-tenant.eu.auth0.com. Use your tenant's ownauth0.comdomain shown on the application's Settings tab, not a custom domain. - Paste the Client ID and Client Secret.
- Click Connect to validate the credentials and establish the connection.
Step 3 - Data To Sync
Select the tables you wish to include in the sync. You can view the schema, remove columns or hash sensitive information. Tables listed in brackets come along with the table before them.
- Users —
users(withuser_identities,user_profile_data,user_metadata,user_app_metadata) - Activity —
logs(withlog_detail_accessed_secret),stats_daily - Applications and APIs —
client(withclient_callback,client_grant_type,client_metadata),client_grant(withclient_grant_scope),grants(withgrant_scope),resource_server(withresource_server_scopes) - Connections —
connection(withconnection_realm,connection_enabled_client,connection_metadata) - Roles and permissions —
role(withrole_permission) - Organizations —
organization(withorganization_metadata),organization_member(withorganization_member_role) - Actions —
action(withaction_supported_trigger,action_secret,action_dependency,action_integration),action_trigger(withaction_trigger_runtime,action_trigger_compatible) - Streaming —
log_stream(withlog_stream_sink),event_stream(withevent_stream_subscription)
Metadata tables — user_metadata, user_app_metadata, user_profile_data, client_metadata, connection_metadata, organization_metadata and log_stream_sink — hold one row per key, with the key in name and its value in value.
users, user_identities and the user metadata tables contain personal information such as email addresses, names and IP addresses. Use column-level hashing or blocking on those columns if you do not want the raw values in your warehouse.
Auth0 only keeps logs for a limited time — between 1 and 30 days depending on your Auth0 plan — so the first sync of logs starts from the oldest log Auth0 still has. Keep the connection syncing to build up a longer history in your warehouse.
Users deleted in Auth0 can remain in the users table for up to 30 days before they are removed.
Step 4 - Configure sync
- Select how often you would like the data to sync.
- Optionally choose a start date for
stats_daily. Without one, daily stats are backfilled for the last year. - Provide a unique destination table name.
Weld will take over from here and commence syncing data from your Auth0 tenant.