Importing Users from Auth0
Import your users from an Auth0 tenant into a Skycloak realm, optionally with their existing passwords.
Imported entities
For each Auth0 user:
| Auth0 | Skycloak |
|---|---|
| Email and whether it is verified | Email, email verified |
| Username (or the email when there is none) | Username |
| Given and family name (or the full name when those are empty) | First and last name |
| Blocked | The user is created disabled |
| Creation date | Kept as the user’s creation date |
| Password | The existing password, if you upload Auth0’s password file (see below) |
| Auth0 user ID | The attribute auth0_user_id, always kept so you can trace a user back |
user_metadata and app_metadata
|
The attributes auth0_user_metadata and auth0_app_metadata, as JSON |
Users who already exist in the realm, with the same username or email, are skipped and never changed.
Only users are imported. Your applications, roles, connections, organizations, Actions, Rules, branding and sessions are not.
Plan requirements
Importing from Auth0 is available on Launch, Business, and Enterprise plans.
Before you start
You need:
-
Your Auth0 tenant domain, for example
acme.us.auth0.com. -
A Management API access token with the
read:usersscope. In the Auth0 dashboard, open Applications, then APIs, then Auth0 Management API, then API Explorer, and copy the token. Note that it expires after 24 hours. - Optionally, Auth0’s password file. Auth0 does not let you export password hashes yourself: you ask Auth0 support for a password hash export, which can take a few days.
Skycloak uses the token only for this import and deletes it as soon as the import finishes. It is never shown again, and it is not kept in your browser.
Importing
You can start an import from two places:
- Into a new realm: on a cluster’s page, open Import above the realms and choose Import from Auth0. Skycloak creates the realm for you.
- Into an existing realm: open the realm and choose Import from Auth0, or use Actions, then Import from Auth0, on the realm’s Users page.
Passwords
Auth0 stores passwords as bcrypt hashes, and Skycloak’s Keycloak needs a bcrypt password-hash provider to verify them. On a dedicated cluster, install it from the cluster’s Extensions first.
Auth0 sends the password file PGP-encrypted. Decrypt it on your own machine before uploading it: Skycloak never sees your private key. The file is checked in full before anything is written, and it is deleted when the import finishes.
Passwords are matched to users by their Auth0 identity.
Users imported without a password need to set one before they can sign in. Forgot password does that, once you turn it on in the realm’s login settings.
Good to know
- Auth0’s export is a snapshot. Users who sign up or change their password after it starts are not included. Pause sign-ups, or run the import again before you switch over.
- Metadata attributes can only be seen and edited by administrators, not by the users themselves. Skycloak turns on unmanaged attributes for the realm if it is not already.
- Importing into the
masterrealm is not possible.