One final question: how can we make sure the application has no access to management API? What should we disable or what should we check to be absolutely sure?
Related topics
Topic | Replies | Views | Activity | |
---|---|---|---|---|
Question re: Client Credentials | 3 | 3815 | August 26, 2019 | |
How to authorise an API user without using client secret | 4 | 6885 | December 8, 2021 | |
What use is the client secret of an OIDC compliant SPA | 2 | 18 | May 14, 2025 | |
How to implement API keys using Auth0? | 11 | 34024 | March 2, 2018 | |
REST Api auth0 realm log in | 1 | 2345 | May 9, 2023 |