Linking Auth0 as a source
Let AI connect your sources for you
Skip the manual setup — run this in your project and the wizard auto-detects your databases and APIs and connects them to PostHog.

The Auth0 connector syncs your identity and access management data – users, tenant logs, organizations, roles, clients, connections, actions, log streams, and resource servers – into PostHog, so you can analyze authentication activity alongside your product data.
Prerequisites
You need an Auth0 account with a machine-to-machine (M2M) application authorized for the Auth0 Management API. No PostHog OAuth app is required – Auth0 uses the client credentials grant to issue tokens directly.
To create one:
- In the Auth0 dashboard, go to Applications > Applications and click Create Application.
- Select Machine to Machine Applications and click Create.
- Select Auth0 Management API as the API to authorize.
- Grant the read scopes for each table you want to sync (see required scopes below).
- Click Authorize, then copy the Domain, Client ID, and Client Secret from the application's Settings tab.
Required scopes
Grant the M2M application the read scopes for the tables you plan to sync:
| Table | Scope |
|---|---|
| users | read:users |
| logs | read:logs |
| organizations | read:organizations |
| roles | read:roles |
| clients | read:clients |
| connections | read:connections |
| actions | read:actions |
| log_streams | read:log_streams |
| resource_servers | read:resource_servers |
You only need to grant scopes for the tables you want to sync. If a scope is missing, PostHog reports which one is needed when the sync runs.
Adding a data source
- In PostHog, go to the Sources tab of the data pipeline section.
- Click + New source and click Link next to this source.
- Enter your credentials (see Configuration below) and click Next.
- Select the tables you want to sync, choose a sync method and frequency, then click Import.
Once the syncs are complete, you can start querying this data in PostHog.
When linking Auth0, you'll need:
- Auth0 domain – your canonical tenant domain, for example
your-tenant.us.auth0.com. Use the canonical domain, not a custom domain, because Auth0 only issues Management API tokens for the canonical one. - Client ID – the client ID of your M2M application.
- Client secret – the client secret of your M2M application.
Sync modes
Each table can be synced in one of several modes, depending on what the source supports:
- Webhook (when available) – the source pushes changes to PostHog in real time. Fastest freshness, lowest ongoing cost, and the only mode that reliably captures updates and deletes.
- Incremental – only new or updated rows are synced on each run, using a cursor field (such as an
updated_attimestamp). Cheaper than a full refresh, but deletes aren't captured. - Append only – new rows are appended using a cursor field; existing rows are never updated. Ideal for immutable, append-only tables like event logs.
- Full refresh – the whole table is reloaded on every sync. Use it when a table has no reliable cursor or when you need deletions reflected.
See sync methods for a full explanation of how each mode works and how to choose between them.
The users and logs tables support incremental sync. All other tables use full refresh only.
Configuration
| Option | Type | Required |
|---|---|---|
Auth0 domain | text | Yes |
Client ID | text | Yes |
Client secret | password | Yes |
Supported tables
| Table | Description | Sync method | Incremental field | Primary key |
|---|---|---|---|---|
users | End users of the Auth0 tenant, across every enabled connection (database, social, and enterprise). | Incremental, Full refresh | updated_at, created_at | — |
logs | Tenant log events, covering authentication attempts, Management API calls, and administrative changes. Retention depends on the Auth0 subscription. | Incremental, Full refresh | date | — |
clients | Applications registered in the tenant, each representing something that authenticates users through Auth0. | Full refresh | — | — |
connections | Identity sources enabled in the tenant, such as database, social, and enterprise connections. | Full refresh | — | — |
roles | Roles defined in the tenant's role-based access control settings. | Full refresh | — | — |
organizations | Organizations in the tenant, used to represent business customers and partners in a B2B setup. | Full refresh | — | — |
resource_servers | APIs registered in the tenant, each defining an audience that access tokens can be issued for. | Full refresh | — | — |
actions | Actions defined in the tenant: custom Node.js functions bound to points in the Auth0 authentication and authorization pipelines. | Full refresh | — | — |
log_streams | Log streams configured in the tenant, each forwarding tenant log events to an external sink. | Full refresh | — | — |
Troubleshooting
If your sync is failing or data looks wrong, see the Data warehouse troubleshooting guide. If that doesn't help, contact support – we're happy to help.