Optionalchange_Optionaldevice_Device Flow configuration.
Optionalguardian_Optionaldefault_Default audience for API Authorization.
Optionaldefault_Name of connection used for password grants at the /token endpoint. The following connection types are supported: LDAP, AD, Database Connections, Passwordless, Windows Azure Active Directory, ADFS.
Optionalerror_Optionaldefault_OptionalflagsOptionalfriendly_Friendly name for this tenant.
Optionalpicture_URL of logo to be shown for this tenant (recommended size: 150x150)
Optionalsupport_End-user support email.
Optionalsupport_End-user support url.
Optionalallowed_URLs that are valid to redirect to after logout from Auth0.
Optionalsession_Number of hours a session will stay valid.
Optionalsession_Number of minutes a session will stay valid. Cannot be specified together with session_lifetime.
Optionalidle_Number of hours for which a session can be inactive before the user must log in again.
Optionalidle_Number of minutes a session can be inactive before the user must log in again. Cannot be specified together with idle_session_lifetime.
Optionalephemeral_Number of hours an ephemeral (non-persistent) session will stay valid.
Optionalidle_Number of hours for which an ephemeral (non-persistent) session can be inactive before the user must log in again.
Optionalephemeral_Number of minutes an ephemeral (non-persistent) session will stay valid. Cannot be specified together with ephemeral_session_lifetime.
Optionalidle_Number of minutes an ephemeral (non-persistent) session can be inactive before the user must log in again. Cannot be specified together with idle_ephemeral_session_lifetime.
Optionalsandbox_Selected sandbox version for the extensibility environment
Optionallegacy_Selected legacy sandbox version for the extensibility environment
Optionaldefault_The default absolute redirection uri, must be https
Optionalenabled_Supported locales for the user interface
Optionalsecurity_Optionalsession_OptionalsessionsOptionaloidc_Optionalcustomize_Whether to enable flexible factors for MFA in the PostLogin action
Optionalallow_Whether to accept an organization name instead of an ID on auth endpoints
Optionalacr_Supported ACR values
OptionalmtlsOptionalpushed_Enables the use of Pushed Authorization Requests
Optionalauthorization_Supports iss parameter in authorization responses
Optionalskip_Controls whether a confirmation prompt is shown during login flows when the redirect URI uses non-verifiable callback URIs (for example, a custom URI schema such as myapp://, or localhost).
If set to true, a confirmation prompt will not be shown. We recommend that this is set to false for improved protection from malicious apps.
See https://auth0.com/docs/secure/security-guidance/measures-against-app-impersonation for more information.
Optionalresource_Optionalclient_Whether the authorization server supports retrieving client metadata from a client_id URL.
Optionalenable_Whether Auth0 Guide (AI-powered assistance) is enabled for this tenant.
Optionalphone_Whether Phone Consolidated Experience is enabled for this tenant.
Optionalinclude_Whether session metadata is included in specific tenant logs (slo, oidc_backchannel_logout_failed, oidc_backchannel_logout_succeeded).
Optionaldynamic_Optionalcountry_
Example