Hi @rdechiara,
Welcome to the Auth0 Community!
I understand you are asking how to securely propagate authentication from App A to App B, whether SSO is feasible in an iframe context given modern browser restrictions, what the recommended architecture is for this use case, and which patterns to avoid.
Root Cause:
The primary challenge is that when App B is embedded in an iframe on a different domain, its requests to Auth0 are treated as third-party requests. Browsers block third-party cookies by default, which prevents the SSO session cookie from being accessible to the iframe, causing silent authentication to fail.
Solution:
Do not propagate tokens from App A to App B. Instead, App B must independently and silently acquire its own token from Auth0 by leveraging the central SSO session created when the user logged into App A. This is achieved through Silent Authentication, a standard OIDC protocol mechanism that Auth0 supports.
Addressing browser restrictions with a Custom Domain:
Yes, SSO in an iframe is entirely feasible, but you must address third-party cookie blocking. The official and robust solution is to use Auth0’s Custom Domains feature. By configuring a custom domain (for example, login.your-company.com), you make the Auth0 authentication endpoint appear to be on the same primary domain as your applications. This transforms the SSO cookie into a first-party cookie, which browsers do not block.
Recommended architecture:
Follow these steps to implement secure cross-domain SSO with iframes:
-
Register both applications. Register both App A and App B as separate applications within your Auth0 Dashboard.
-
User authenticates to App A. The user navigates to App A and is redirected to the Auth0 Universal Login page. Upon successful authentication, Auth0 sets a secure, encrypted SSO session cookie on your custom domain and redirects the user back to App A with their tokens.
-
App B requests a token silently. When the user accesses the page in App A containing the iframe, App B loads. App B’s code then uses an Auth0 SDK (for example, the Auth0 SPA JS SDK) to call a method like getTokenSilently().
-
Hidden iframe handles the session check. The SDK creates a hidden, non-interactive iframe that points to Auth0’s /authorize endpoint with the prompt=none parameter. This iframe operates transparently to the user.
-
Auth0 issues tokens for App B. Auth0 checks for the first-party SSO cookie, finds the active session, and issues a new set of tokens specifically for App B without any user interaction. The SDK delivers these tokens to your App B code.
-
Handle logout gracefully. The iframed app should check frequently (for example, upon page reload) whether the session is still active. If the session has ended, clear the local storage and prompt the user to re-authenticate through App A.
Patterns to avoid:
To prevent security risks, avoid the following anti-patterns:
-
Do not use Auth0 login pages inside an iframe. Auth0 discourages embedding the Auth0 login page (or any identity provider login page) inside an iframe due to inherent security risks. The parent application must always orchestrate the primary login; the iframe should never handle initial authentication.
-
Do not send tokens between applications via URL parameters or client-side mechanisms. App B must request its own token directly from Auth0, not receive it from App A through URL parameters, query strings, or any other client-side channel.
-
Account for silent authentication failures. Silent authentication may fail if Auth0 cannot find a valid session for the user. You must be prepared to fall back to regular authentication on App A when getTokenSilently() fails, and prompt the user to log in again if necessary.
I hope this clear things up, let us know if you have any other questions!
Kind regards,
Remus