Hi @mike20
Your production login process is intermittently breaking since September 1st, affecting only one tenant. Login succeeds, but subsequent calls to Auth0 (token authorization or Management API user info requests) take over 2 minutes to complete, causing your web server to time out. The issue is not consistent — some logins are fast and successful — and there have been no configuration changes on your side.
This is a tenant-specific backend issue that requires Auth0 Support investigation. Intermittent 2-minute delays after successful login, with no code or configuration changes on your side, indicate either infrastructure degradation, an undocumented rate limit, or a third-party integration issue on Auth0’s side. Community members cannot access backend logs or diagnose infrastructure problems.
[Root Cause]
The intermittent nature and tenant-specific scope suggest one of these causes:
- Auth0 backend infrastructure issue — Database latency, service degradation, or regional connectivity problems affecting your tenant specifically
- Undocumented rate limiting or throttling — Auth0 may have applied automatic rate limits or throttling to your tenant (e.g., due to suspicious activity detection or resource constraints)
- Custom Action or third-party integration delay — If you have Post-Login Actions or custom database connections, Auth0 may be waiting on external services
- Management API rate limit — Repeated calls to the Management API may be hitting rate limits (typically 429 errors, but can manifest as timeouts)
- Token endpoint degradation — The
/oauth/token endpoint may be experiencing latency specific to your tenant
Why this requires Auth0 Support:
- Backend logs are not accessible to customers — Only Auth0 support engineers can view tenant-specific logs, database performance metrics, and infrastructure health
- Intermittent issues require correlation — Auth0 Support can correlate your login timestamps with backend infrastructure events, service deployments, or automated scaling events
- Rate limiting is not self-service — If Auth0 has applied rate limiting or throttling to your tenant, only Support can verify and adjust it
- Tenant-specific degradation is invisible to customers — Your application logs show timeouts, but Auth0’s internal logs show whether Auth0’s services are responding slowly
What you can do immediately:
Step 1: Verify your configuration has not changed
Navigate to Auth0 Dashboard → Applications → Your App → Settings.
Verify that:
- Callback URLs are correct
- Allowed Logout URLs are correct
- Token expiration settings are unchanged
- No new Rules, Actions, or custom database connections have been added
Step 2: Check for custom Actions or Rules that may be slow
Navigate to Auth0 Dashboard → Actions → Flows → Post-Login.
Review all attached Actions:
- Do any make external API calls?
- Do any have long-running database queries?
- Do any have timeout issues?
Temporarily disable all Actions and test if the issue persists. If it resolves, the problem is in your custom code, not Auth0’s infrastructure.
Step 3: Monitor Management API usage
If your application calls the Management API during login (e.g., to fetch user metadata), verify you are not hitting rate limits:
- Paid tenants: 15 requests per second (burst up to 50)
- Free tenants: 2 requests per second
Check your application logs for 429 (Too Many Requests) responses from the Management API. If you see these, implement exponential backoff or caching.
Step 4: Collect diagnostic information for Auth0 Support
Gather the following before contacting Support:
- Tenant name: Your Auth0 tenant domain (e.g.,
yourcompany.auth0.com)
- Affected client ID: The application experiencing the issue
- Time range: Specific dates and times when the issue occurred (e.g., “September 1st, 2024, 14:00–15:30 UTC”)
- Sample log entries: Export logs from Auth0 Dashboard showing failed logins with timestamps
- Your application logs: Show the exact timeout duration and which Auth0 endpoint was timing out (e.g.,
/oauth/token, /userinfo, Management API endpoint)
- Reproduction steps: Can you trigger the issue on demand, or is it truly random?
Step 5: Contact Auth0 Support
This issue requires direct investigation by Auth0 Support. Community members cannot access backend logs or diagnose infrastructure problems.
If you can provide more information on the issue that you are experiencing, I will gladly provide all relevant information if possible.
Kind Regards,
Nik