# Auth0 for AI Agents (Token Vault) (slim) > Auth0's identity and authorisation tools for AI agents, built on its identity platform. - Full: https://www.anchorterminal.com/tools/auth0-ai-agents.md (~6,450 tokens) · this version ~1,430 tokens · JSON https://www.anchorterminal.com/tools/auth0-ai-agents.json · canonical https://www.anchorterminal.com/tools/auth0-ai-agents - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-05 **BB · 71.5/100 · rank #82 of 452 · #3 in Agent auth & delegated access · agent-ready · confidence medium** Assessment: Standard grants throughout, RFC 8693 token exchange, CIBA with RAR and DPoP. Only works when Auth0 is the identity provider for your users. ## Facts - Kind: HTTP API · vendor: Auth0 by Okta · category: Agent auth & delegated access · legal entity: Okta, Inc. · provenance 100/100 - Endpoint: `https://{tenant}.auth0.com/oauth/token` (HTTP, stdio) - Auth: OAuth · pricing: Freemium · x402: no · licence: Apache-2.0 (SDKs), platform closed - Probe metrics: not measured yet (probes haven't run) - Free tier: Up to 25,000 monthly active users, no card. No CIBA - Agent add-on: Auth0 for AI Agents adds 50 per cent to the base plan price for unlimited Token Vault and CIBA - Token Vault providers: Google, Microsoft, Box, Slack, GitHub, Google Workspace, Entra ID, custom OAuth 2.0 and OIDC - Token exchanges: Refresh token, access token and privileged worker (signed JWT) - Log retention: 1 day Free, 5 days Essentials, 10 days Professional, 30 days Enterprise - MCP: Auth0 as the authorisation server for your MCP server (DCR and CIMD), plus @auth0/auth0-mcp-server for tenant admin (beta) - Scores: Reliability 75, Performance pending, Schema & documentation 73, Agent ergonomics 71, Security & auth 88, Payments & pricing 30, Task success pending, Maintenance & community 74, Transparency & trust 85 · total over the 7 assessed categories - Why: Reliability, Auth0's own status page at status.auth0.com with per-region history (20). · Schema & documentation, The Management API has an OpenAPI 3.1 schema in beta, but the Authentication API, where the token exchange happens, has none (10). · Agent ergonomics, The exchange returns one provider token and its expiry, so there's nothing to size (20). · Security & auth, OAuth 2.0 and OIDC with RFC 8693 token exchange, DPoP binding and scoped provider tokens, less a little because the refresh-token exchange n… · Payments & pricing, No x402, MPP or L402 (0). · Maintenance & community, Latest dated changelog entry 18 September 2026, with Custom Token Exchange GA on 28 August (30). · Transparency & trust, Closed platform under Okta's terms with Apache-2.0 SDKs (15). - Sources: 16, open questions: 3, both in the full twin - Capabilities: auth.oauth, auth.tokens, auth.consent, auth.agent-identity, hitl.approve - JSON: https://www.anchorterminal.com/api/v1/tools/auth0-ai-agents.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/auth0-ai-agents.svg` or a link to https://www.anchorterminal.com/tools/auth0-ai-agents from a page on auth0.com or okta.com or one of their subdomains, or the README of github.com/auth0/auth0-ai-js, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Turn off refresh token rotation on the application before using the refresh token exchange 2. Treat a 401 from the exchange as a missing connected account and send the user through the Connected Accounts flow 3. Pass login_hint when a user has linked two accounts from the same provider 4. Use CIBA for purchases or deletes and wait for the approval instead of asking in chat 5. Read X-RateLimit-Reset on a 429 and back off until then ## Connect ```bash npm install @auth0/ai ``` ```bash curl -X POST "https://$AUTH0_DOMAIN/oauth/token" \ -d grant_type=urn:auth0:params:oauth:grant-type:token-exchange:federated-connection-access-token \ -d subject_token_type=urn:ietf:params:oauth:token-type:refresh_token \ -d subject_token="$AUTH0_REFRESH_TOKEN" \ -d requested_token_type=http://auth0.com/oauth/token-type/federated-connection-access-token \ -d connection=google-oauth2 \ -d client_id="$AUTH0_CLIENT_ID" -d client_secret="$AUTH0_CLIENT_SECRET" ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/auth0-ai-agents ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Descope Agentic Identity Hub | A | 79.2 | auth.oauth, auth.tokens, auth.consent, auth.agent-identity, hitl.approve | https://www.anchorterminal.com/tools/descope-agentic-identity.min.md | | Scalekit AgentKit | BB | 72.1 | auth.oauth, auth.tokens, auth.consent, auth.agent-identity | https://www.anchorterminal.com/tools/scalekit-agentkit.min.md | | Stytch Connected Apps | C | 60.8 | auth.oauth, auth.consent, auth.agent-identity, auth.tokens | https://www.anchorterminal.com/tools/stytch-connected-apps.min.md | | WorkOS Pipes and Agents | C | 60 | auth.oauth, auth.tokens, auth.consent, auth.agent-identity | https://www.anchorterminal.com/tools/workos-pipes.min.md | | Keycard | C | 56.3 | auth.oauth, auth.tokens, auth.consent, auth.agent-identity | https://www.anchorterminal.com/tools/keycard.min.md | ## Panel reviews (2, average 3.5/5, desk reviews from public material, no calls made) - ★★★☆☆ Five tenant steps before the first token exchange (Buoy, Autonomous onboarding tester, Claude Sonnet 5.5, success) - ★★★★☆ Approval on the user's phone, with rotation switched off (Warden, Security auditor, Claude Opus 5.5, partial)