Importing Users from Auth0

Importing Users from Auth0

Import your users from an Auth0 tenant into a Skycloak realm, optionally with their existing passwords.

Imported entities

For each Auth0 user:

Auth0 Skycloak
Email and whether it is verified Email, email verified
Username (or the email when there is none) Username
Given and family name (or the full name when those are empty) First and last name
Blocked The user is created disabled
Creation date Kept as the user’s creation date
Password The existing password, if you upload Auth0’s password file (see below)
Auth0 user ID The attribute auth0_user_id, always kept so you can trace a user back
user_metadata and app_metadata The attributes auth0_user_metadata and auth0_app_metadata, as JSON

Users who already exist in the realm, with the same username or email, are skipped and never changed.

Only users are imported. Your applications, roles, connections, organizations, Actions, Rules, branding and sessions are not.

Plan requirements

Importing from Auth0 is available on Launch, Business, and Enterprise plans.

Before you start

You need:

  • Your Auth0 tenant domain, for example acme.us.auth0.com.
  • A Management API access token with the read:users scope. In the Auth0 dashboard, open Applications, then APIs, then Auth0 Management API, then API Explorer, and copy the token. Note that it expires after 24 hours.
  • Optionally, Auth0’s password file. Auth0 does not let you export password hashes yourself: you ask Auth0 support for a password hash export, which can take a few days.

Skycloak uses the token only for this import and deletes it as soon as the import finishes. It is never shown again, and it is not kept in your browser.

Importing

You can start an import from two places:

  • Into a new realm: on a cluster’s page, open Import above the realms and choose Import from Auth0. Skycloak creates the realm for you.
  • Into an existing realm: open the realm and choose Import from Auth0, or use Actions, then Import from Auth0, on the realm’s Users page.

Passwords

Auth0 stores passwords as bcrypt hashes, and Skycloak’s Keycloak needs a bcrypt password-hash provider to verify them. On a dedicated cluster, install it from the cluster’s Extensions first.

Auth0 sends the password file PGP-encrypted. Decrypt it on your own machine before uploading it: Skycloak never sees your private key. The file is checked in full before anything is written, and it is deleted when the import finishes.

Passwords are matched to users by their Auth0 identity.

Users imported without a password need to set one before they can sign in. Forgot password does that, once you turn it on in the realm’s login settings.

Good to know

  • Auth0’s export is a snapshot. Users who sign up or change their password after it starts are not included. Pause sign-ups, or run the import again before you switch over.
  • Metadata attributes can only be seen and edited by administrators, not by the users themselves. Skycloak turns on unmanaged attributes for the realm if it is not already.
  • Importing into the master realm is not possible.
Last updated on