Experiencing huge lags with authorising access tokens/accessing management API

Our production login process is currently breaking intermittently without any code change on our side. This has been occurring since September 1st and only seems to impact one tenant. Login occurs successfully and then during the callback on on our app future calls to Auth0 to authorise access tokens or get user info from the management API are taking well over 2 minutes to complete. This causes our web server to time out, but I have recreated locally. It doesn’t occur every time and future logins can be timely and therefore successful. There’s been on change to configuration on our side.

I have no means of getting further information from the existing logs, are there backend logs that could be made available to diagnose this? Or could some kind of rate limiting or other mechanism have been applied to our tenant?

Hi @mike20

Your production login process is intermittently breaking since September 1st, affecting only one tenant. Login succeeds, but subsequent calls to Auth0 (token authorization or Management API user info requests) take over 2 minutes to complete, causing your web server to time out. The issue is not consistent — some logins are fast and successful — and there have been no configuration changes on your side.

This is a tenant-specific backend issue that requires Auth0 Support investigation. Intermittent 2-minute delays after successful login, with no code or configuration changes on your side, indicate either infrastructure degradation, an undocumented rate limit, or a third-party integration issue on Auth0’s side. Community members cannot access backend logs or diagnose infrastructure problems.

[Root Cause]

The intermittent nature and tenant-specific scope suggest one of these causes:

  1. Auth0 backend infrastructure issue — Database latency, service degradation, or regional connectivity problems affecting your tenant specifically
  2. Undocumented rate limiting or throttling — Auth0 may have applied automatic rate limits or throttling to your tenant (e.g., due to suspicious activity detection or resource constraints)
  3. Custom Action or third-party integration delay — If you have Post-Login Actions or custom database connections, Auth0 may be waiting on external services
  4. Management API rate limit — Repeated calls to the Management API may be hitting rate limits (typically 429 errors, but can manifest as timeouts)
  5. Token endpoint degradation — The /oauth/token endpoint may be experiencing latency specific to your tenant

Why this requires Auth0 Support:

  • Backend logs are not accessible to customers — Only Auth0 support engineers can view tenant-specific logs, database performance metrics, and infrastructure health
  • Intermittent issues require correlation — Auth0 Support can correlate your login timestamps with backend infrastructure events, service deployments, or automated scaling events
  • Rate limiting is not self-service — If Auth0 has applied rate limiting or throttling to your tenant, only Support can verify and adjust it
  • Tenant-specific degradation is invisible to customers — Your application logs show timeouts, but Auth0’s internal logs show whether Auth0’s services are responding slowly

What you can do immediately:

Step 1: Verify your configuration has not changed

Navigate to Auth0 Dashboard → Applications → Your App → Settings.

Verify that:

  • Callback URLs are correct
  • Allowed Logout URLs are correct
  • Token expiration settings are unchanged
  • No new Rules, Actions, or custom database connections have been added

Step 2: Check for custom Actions or Rules that may be slow

Navigate to Auth0 Dashboard → Actions → Flows → Post-Login.

Review all attached Actions:

  • Do any make external API calls?
  • Do any have long-running database queries?
  • Do any have timeout issues?

Temporarily disable all Actions and test if the issue persists. If it resolves, the problem is in your custom code, not Auth0’s infrastructure.

Step 3: Monitor Management API usage

If your application calls the Management API during login (e.g., to fetch user metadata), verify you are not hitting rate limits:

  • Paid tenants: 15 requests per second (burst up to 50)
  • Free tenants: 2 requests per second

Check your application logs for 429 (Too Many Requests) responses from the Management API. If you see these, implement exponential backoff or caching.

Step 4: Collect diagnostic information for Auth0 Support

Gather the following before contacting Support:

  1. Tenant name: Your Auth0 tenant domain (e.g., yourcompany.auth0.com)
  2. Affected client ID: The application experiencing the issue
  3. Time range: Specific dates and times when the issue occurred (e.g., “September 1st, 2024, 14:00–15:30 UTC”)
  4. Sample log entries: Export logs from Auth0 Dashboard showing failed logins with timestamps
  5. Your application logs: Show the exact timeout duration and which Auth0 endpoint was timing out (e.g., /oauth/token, /userinfo, Management API endpoint)
  6. Reproduction steps: Can you trigger the issue on demand, or is it truly random?

Step 5: Contact Auth0 Support

This issue requires direct investigation by Auth0 Support. Community members cannot access backend logs or diagnose infrastructure problems.

If you can provide more information on the issue that you are experiencing, I will gladly provide all relevant information if possible.

Kind Regards,
Nik

Thank you, I will raise a support ticket