Enhancing security and flexibility with runtime API keys
What is our primary use case?
We use the solution for API security and management. We implement our solution with almost ten to fifteen vendors' APIs, like Salesforce and HubSpot.
It involves generating leads, invites, adding contacts, and opportunities, mostly challenging with Salesforce integration due to limited documentation.
How has it helped my organization?
The solution is cost-effective and beneficial in terms of security. It enhances secure API requests, improving user management efficiency.
What is most valuable?
It offers stronger security and flexibility with API keys, which are generated on runtime. This is valuable as they are reusable and can be used for confidential applications.
What needs improvement?
There is no immediate need for improvement. However, better documentation for Salesforce integration is suggested. Multi-factor authentication could be considered for future research.
For how long have I used the solution?
I've been working with the solution since 2017, which is approximately seven to eight years.
What do I think about the stability of the solution?
There have been no issues with performance or stability.
What do I think about the scalability of the solution?
I haven't explored scalability extensively, as it hasn't been required.
How are customer service and support?
We haven't escalated any questions to customer support.
How would you rate customer service and support?
Which solution did I use previously and why did I switch?
Google Authenticator and Duo are used for multi-factor authentication.
How was the initial setup?
The initial setup was simple and not complex, involving key or username authorization.
What was our ROI?
The solution brings security benefits and efficiency.
What other advice do I have?
I recommend the solution as it provides strong security with more control over access. It supports various authentication methods.
I'd rate the solution ten out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
MFA Using OKTA
What do you like best about the product?
Auth0 provides secure and simple access to organization and people everywhere.
What do you dislike about the product?
Multi factor authentication is bit slow special for SMS.
What problems is the product solving and how is that benefiting you?
Now a days security is major concern for the entire world by introducing MFA AuthO by Okta is making things more secure for end user
Consultant
What do you like best about the product?
Auth0 by Okta makes it super easy to add secure authentication to app. Plus, it saves a ton of time by offering built-in integrations. The dashboard is user-friendly.
What do you dislike about the product?
Auth0 by Okta can get pricey as your user base grows, which might be tough for small businesses.
What problems is the product solving and how is that benefiting you?
It handles things like login, password management, multi-factor authentication, and social logins, so I don’t have to code that from scratch.
Benifit of using Auth0 by Okta
What do you like best about the product?
One thing I really like about Auth0 recently is its support for passkey and biometric authentication.
What do you dislike about the product?
One area where Auth0 can improve is pricing transparency and scalability for startups or smaller teams.
What problems is the product solving and how is that benefiting you?
It is saving us time when it comes to authentication and multi-factor security review.
Customer support is abysmal
What do you like best about the product?
They have a free startup plan that gets you up and running pretty quickly.
What do you dislike about the product?
The customer support is truly abysmal. You should assume that unless you need to talk to a sales rep you won't be able to interact with a support team.
What problems is the product solving and how is that benefiting you?
IAM for our enterprise customers
Integrates well with other tools and services, scales well and maintenance is managed by AuthO
What is our primary use case?
We have user management, role management, and tenant concepts for multi-tenant applications. We use organizations in Auth0. For Okta, we mostly use it for internal SSO to provision users to internal tools.
How has it helped my organization?
What is most valuable?
Auth0’s multifactor authentication enhances our security posture. They are GDPR compliant, and they provide us with a way to host in multiple regions. We use a European region to be GDPR compliant.
For performance, we can also choose different regions, like China or North America. They are also HIPAA compliant, but we don’t deal with HIPAA. They are ISO certified, so it’s easy for us to convince our security team. They manage key rotation and things like that on their end in the backend, which helps us.
What needs improvement?
Auth0 doesn’t have a great way of providing self-managed user management tools. If I have to provision my customers to manage their tenants, they don’t do it out of the box.
We are wrapping a solution around it to make that happen. There are some marketplace plugins available, but they are not so great. We have developed our own custom solution to expose user management to our customers.
For how long have I used the solution?
I have been using it for around seven years. I use the latest version.
What do I think about the scalability of the solution?
It’s highly scalable. We just have to pay more for more users.
How are customer service and support?
For enterprise, I would rate technical support a nine out of ten.
For any kind of lower starter package, I would rate the technical support somewhere around six out of ten.
So, on an average it is an eight out of ten.
How would you rate customer service and support?
Which solution did I use previously and why did I switch?
Within our organization, we use only Okta. We have hooked it up to Active Directory. That’s our single sign-on here.
Okta is mostly provisioned and used through DevOps. Role management and user grouping are mostly easy. There are directional integrations as well, including Azure AD and other tools. We get out-of-the-box solutions to integrate with actionable tools that we are using.
It's straight out of the box. So, the deployment time is almost half an hour to an hour in our case.
It will probably take one day to integrate. We also use IAC for automation. Once that is done, we mostly forget about it.
We have to do user management, like provisioning the users, de-provisioning, when they leave the organization and so on.
How was the initial setup?
It’s easy to integrate and deploy.
We use the cloud solution. We don’t deploy anything. We use the cloud solution, and we have automated the configuration. That is the deployment that goes on. Like, if we are adding a new tenant and things like that, it all happens through infrastructure as code.
The general deployment and integration took us around one day. Probably one day because we requested it from the DevOps team, and they have to get in touch with someone from the tooling side, and they get it done. So we usually hear back within a day that it’s done.
The point is that we did all the heavy lifting in the initial days. After that, we hardly notice anything. It’s all working well together. The only thing is that we have to wrap up a solution for user management. Other than that, I don’t see any issues.
We don't do the maintenance. It's Auth0 that manages the maintenance. We don’t usually do anything. They have great availability SLAs. We don’t even notice if there are any updates and things like that.
What was our ROI?
It’s definitely beneficial. If we had to develop our own and manage it, it would take years of development and maintenance. In those terms, it’s definitely beneficial.
But once you cross that barrier of being a startup and growing, and if you have to move to an enterprise solution, that’s where it becomes expensive. But at that point, I think you’ll be okay to pay anyway.
What's my experience with pricing, setup cost, and licensing?
The pricing depends on the tier you are in. If you’re in enterprise support, there’s always someone who can support you. But if you’re in lower tiers or starter tiers, we have crossed that barrier anyway.
In the initial days, if you’re not aware of how the OpenID solutions work, it’s probably hard to get started. Once you cross that barrier, it becomes easy.
But you have to pay extra for technical support, which makes sense, but adoption might become harder for people who might not have experience with either Auth0 or Okta before.
What other advice do I have?
As a developer, I would rate it at nine out of ten. That’s because it’s very flexible. Developers can easily learn the system and get used to developing on it, like configuring automation, configuring integration, and things like that.
But, again, it’s for developers. You should know how the API integrations work and things like that. But if you are a user in general, I think I would rate it at six or seven, probably seven, because if you’re not a developer, you need to spend time exploring more.
Also, the scoped user management for a specific customer is not available out of the box with Auth0. So that’s something which, if you are a product manager, you would definitely look at. But if you’re a developer, that’s just an opportunity to build something on top of that.
Which deployment model are you using for this solution?
Public Cloud
Good for easy social login integration
What do you like best about the product?
I like parts of the social login setup/connection guide because it gives me step-by-step instructions to set it up and it is quite simple to then integrate that into my website and mobile apps. The branding features are much better on Auth0's free plan than other authentication solutions. I have used Auth0 for a few months now.
What do you dislike about the product?
In my experience. The lack of images in order to simplify the setup process and their lack of in-depth guides for less main stream integrations.
What problems is the product solving and how is that benefiting you?
The annoying and tedious of configuring social login's with my site and services
Terrible Customer Support
What do you like best about the product?
* Ability to authenticate through a variety of methods
What do you dislike about the product?
* Customer Support is terrible - they took a month to respond to our request for a new admin when our CTO left, with our team being handed off to 5 different individuals (to date) who each asked for the same information we had provided the previous individual.
* System is clunky with poor UI for developing a customised login screen
What problems is the product solving and how is that benefiting you?
User authentication into our web app
Auth0 is a proven entity
What do you like best about the product?
I like that Auth0 is reliable, and real-world tested. Many companies use it, and it has a very good track-record.
What do you dislike about the product?
The pricing structure is complex, and for some things, is too expensive.
What problems is the product solving and how is that benefiting you?
Authentication/Authorization is not something that many organizations have the capacity to do themselves--it can introduce a lot of overhead. Auth0 takes that off our plate.
Seamless authentication and authorization solution
What do you like best about the product?
i like the new advanced universal login customization capabilities
What do you dislike about the product?
need improvement in real time event streaming for user lifecycle changes
What problems is the product solving and how is that benefiting you?
We leveverage Auth0 for a range of security features, including MFA, anomaly detection, and breach detection, to help protect user accounts and sensitive data.