# Vendor facets — Auth0 (Okta). Developer-first CIAM whose tenant serves a root discovery document with # issuer, authorization_code and registration_endpoint (fetched live from samples.auth0.com), and serves # it on a custom domain with the custom-domain issuer. Auth for MCP went GA 2026-05-06 (CIMD, resource # identifiers, on-behalf-of exchange). Where it cannot reach: the MCP/API server's own RFC 9728 document, # every OpenAPI check, and consent_identity; FAPI is an Enterprise add-on and regime-conditional. vendor: auth0 name: Auth0 website: https://auth0.com areas: - identity registry_keys: - auth0 rubric_schema_version: 0.22.0 generated: '2026-09-25' features_refreshed: '2026-09-25' basis: capability summary: >- Auth0 moves the identity dimensions of agent readiness when the provider serves its tenant on a custom domain it owns and that host is on its record: served auth (0.9), served delegated identity, and dynamic client registration once the tenant's DCR flag is switched on (open registration, which Auth0 itself warns lets anyone create applications). It does not serve the provider's protected-resource metadata, does not write the provider's OpenAPI, and its FAPI certification is Auth0's, not the provider's. features: - id: custom-domains name: Custom domains description: >- Serves the tenant, Universal Login and the discovery metadata on the customer's domain; tokens issued through it carry the custom-domain iss. Free with a card on file; self-managed certificates need Enterprise. source: https://auth0.com/docs/customize/custom-domains tier: all - id: root-discovery-document name: Tenant discovery document at the host root description: >- /.well-known/openid-configuration at the host root with issuer, authorization_code, client_credentials, token-exchange and registration_endpoint (/oidc/register). source: https://samples.auth0.com/.well-known/openid-configuration tier: all - id: dynamic-client-registration name: Dynamic Client Registration description: >- OIDC Dynamic Client Registration, off by default and enabled per tenant; open (no token), creates third-party apps limited to authorization_code and refresh_token with PKCE, 5 requests/second. source: https://auth0.com/docs/get-started/applications/dynamic-client-registration tier: all - id: auth-for-mcp name: Auth for MCP description: >- GA 2026-05-06 — Auth0 as the MCP authorization server with CIMD client registration, MCP resource identifiers and on-behalf-of token exchange for downstream APIs. source: https://auth0.com/blog/auth0-auth-for-mcp-servers-generally-available/ tier: unknown - id: mcp-dcr-guide name: MCP client registration guide description: >- Documents enabling DCR for MCP clients, default permissions, and that the MCP server must expose its own /.well-known/oauth-protected-resource pointing at the tenant. source: >- https://auth0.com/ai/docs/mcp/guides/registering-your-mcp-client-application/dynamic-client-registration tier: all - id: universal-login name: Universal Login description: Hosted login and sign-up pages on the tenant or custom domain. source: https://auth0.com/docs/authenticate/login/auth0-universal-login tier: all - id: highly-regulated-identity name: Highly Regulated Identity (FAPI) description: >- Certified FAPI 1 Advanced provider with PAR, JAR, mTLS, private_key_jwt, token binding and SCA; Enterprise plan add-on. source: https://auth0.com/docs/secure/highly-regulated-identity tier: enterprise maps: - feature: root-discovery-document check: auth_clarity layer: agent_readiness grade: served provider_must: >- Serve the tenant on a custom domain on its own namespace and get that host on its record. The harvest probes the root of hosts the provider owns; a yourtenant.auth0.com host is not on a normal record, and a document whose issuer is on a different registrable domain from the probed host is recorded as the platform's. points: 10 baseline_pass_rate: 0.474 - feature: root-discovery-document check: delegated_identity layer: agent_readiness grade: served provider_must: Same custom-domain host on record; authorization_code is in grant_types_supported. points: 6 baseline_pass_rate: 0.209 - feature: dynamic-client-registration check: dynamic_client_registration layer: agent_readiness provider_must: >- Same host on record, and enable the tenant DCR flag with default permissions configured. Auth0 now recommends CIMD over DCR for MCP in production, which the rubric does not read. points: 6 baseline_pass_rate: 0.134 - feature: universal-login check: sign_up_present layer: composite provider_must: Declare the hosted login/sign-up URL as a Login or SignUp pointer in apis.yml. catalog_pass_rate: 0.19 facet: access_clarity points: 5 baseline_pass_rate: 0.463 - feature: auth-for-mcp check: oauth_scopes_enumerated layer: composite conditional: true condition: >- Only if the provider's own OpenAPI declares oauth2 and enumerates the API scopes it defined in Auth0. catalog_pass_rate: 0.866 facet: contract_quality points: 4 baseline_pass_rate: 0.902 saturated: true saturated_note: >- 90% of providers with a contract, docs and a reference already earn this; the vendor cannot move it for most of its buyers. - feature: auth-for-mcp check: reg_oauth_scopes layer: composite conditional: true condition: >- Regulated regime only, and only when the provider publishes its scopes as a pointer or scopes artifact. catalog_pass_rate: 0.11 facet: regulatory points: 10 baseline_pass_rate: 0.29 - feature: highly-regulated-identity check: reg_fapi_profile layer: composite conditional: true condition: >- Banking/open-finance regime, the Enterprise add-on bought, and the provider's own auth docs stating FAPI, PAR, private_key_jwt or mTLS-bound tokens. catalog_pass_rate: 0.196 facet: regulatory points: 6 baseline_pass_rate: 0.463 earns_nothing: - feature: root-discovery-document check: well_known_published why: >- An openid-configuration is not one of the documents that check reads (api-catalog, security.txt, protected-resource, AAuth). - feature: highly-regulated-identity check: reg_certification_signal why: The FAPI certification is held by Auth0; the check wants a certification the provider holds. - feature: mcp-dcr-guide check: protected_resource_metadata layer: agent_readiness why: >- The guide tells the provider to serve the document; Auth0 does not serve it and no Auth0 library that serves it was found on the fetched pages. out_of_reach: checks: - security_schemes_defined - oauth_flows_current - consent_identity - well_known_catalog note: >- The provider's OpenAPI and its apis.yml pointers are its own writing; consent/bot-identity signals are not an IdP product. unscored_practice: - feature: auth-for-mcp why: >- CIMD (client ID metadata documents), Auth0's recommended MCP registration path, is not read by any dimension; only RFC 7591 registration_endpoint is. - feature: root-discovery-document why: The served document advertises implicit and password grants; oauth_flows_current reads only OpenAPI. surface: contract_quality: reachable: 4.0 total: 211 access_clarity: reachable: 5.0 total: 38 regulatory: reachable: 16.0 total: 108 agent_readiness: reachable: 21.0 total: 139 hard_rule: >- A model, not a score. Adopting this vendor changes a provider's Kin Score only when the provider publishes the resulting artifacts on its own surface; nothing here writes a score, and no sponsorship or partnership can. method: searched source: - >- https://auth0.com/ai/docs/mcp/guides/registering-your-mcp-client-application/dynamic-client-registration - https://auth0.com/blog/auth0-auth-for-mcp-servers-generally-available/ - https://auth0.com/docs/authenticate/login/auth0-universal-login - https://auth0.com/docs/customize/custom-domains - https://auth0.com/docs/get-started/applications/dynamic-client-registration - https://auth0.com/docs/secure/highly-regulated-identity - https://samples.auth0.com/.well-known/openid-configuration measured: cohort: method: vendors-catalog.json detections (CNAME / header / URL shape / markup), never a name match detected: 0 in_baseline: 0 control: basis: providers earning contract_present + documentation_present + api_reference_present, minus the cohort n: 5216 metric: >- cohort_pct / control_pct = mean share of the check's points earned (derived and platform credit weighted), x100 measured_on: '2026-09-25' status: 'not measurable: 0 detected customers clear the baseline (need 20)' simulation: simulated_on: '2026-09-25' rubric: 0.23.0 population: providers publishing a contract (contract_present earned), replayable exactly providers: 8977 providers_unreplayable: 987 providers_moved: 8574 conditional_rows: excluded (they depend on what the API already does) composite_lift: median: 2.4 p75: 2.6 p90: 2.7 max: 2.7 mean_among_movers: 2.3 agent_readiness_lift: median: 12.6 p75: 12.6 p90: 14.6 max: 17.6 mean_among_movers: 12.3 facet_lift_median_among_movers: access_clarity: 13.1 composite_band_moves: thin -> developing: 679 developing -> strong: 189 emerging -> thin: 167 strong -> exemplar: 48 minimal -> emerging: 1 agent_readiness_band_moves: agent-aware -> agent-ready: 4886 agent-ready -> agent-native: 314 agent-aware -> agent-native: 43 method: >- each provider's own kin/checks file, the vendor's maps at their stated credit, the scorer's composite formula; from -> to, nothing written