FlowConsent
ServicesBlogExtensionSolutionsPricingTry FlowConsent
FlowConsent

FlowConsent is a GDPR-compliant cookie consent management platform.

Product

  • Services
  • Extension
  • Extension support
  • Solutions
  • Pricing
  • FlowConsent App

Legal

  • Privacy Policy
  • Terms of Service
  • Legal notice

© 2026 FlowConsent by BeBranded. All rights reserved.

FrancaisDeutschEspanol

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. Security
  4. Auth0 Lock
A

Auth0 Lock

EssentialWebsite

Related services

Accertify

Accertify is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. Accertify supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, Accertify ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Essential

adCAPTCHA

adCAPTCHA is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. adCAPTCHA supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, adCAPTCHA ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Essential
A

Akamai Bot Manager

Akamai Bot Manager is an AI-powered chatbot platform that enables businesses to automate customer conversations across websites, messaging apps, and social channels. It provides natural language processing, conversation flow builders, and backend integration to handle inquiries, qualify leads, and provide support. Akamai Bot Manager reduces response times and costs while maintaining high-quality conversational experiences that scale with your business needs.

Essential
A

Akamai Web Application Protector

Akamai Web Application Protector is a comprehensive web security solution that protects websites and applications from cyber threats including DDoS attacks, SQL injection, and cross-site scripting. It provides web application firewall (WAF) capabilities, real-time threat detection, and automated incident response. Akamai Web Application Protector offers SSL/TLS encryption, bot management, and security monitoring. With compliance reporting and vulnerability scanning, Akamai Web Application Protector.

Essential
A

Alibaba Cloud Verification Code

Alibaba Cloud Verification Code is a web hosting and cloud infrastructure provider delivering reliable, scalable hosting solutions for websites and applications of all sizes. It offers shared, VPS, and dedicated server options with SSD storage, global CDN, and automated backups. Alibaba Cloud Verification Code provides one-click deployment, managed databases, and 24/7 monitoring. With high uptime guarantees and developer-friendly tools, Alibaba Cloud Verification Code ensures optimal performance at scale.

Essential

Alliance Auth

Alliance Auth is an identity and authentication platform providing secure login, single sign-on (SSO), and multi-factor authentication for websites and applications. It supports social login, passwordless authentication, and user management with enterprise-grade security. Alliance Auth simplifies identity implementation for developers while ensuring compliance. With adaptive authentication and anomaly detection, Alliance Auth protects user accounts while maintaining a frictionless experience.

Essential
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does Auth0 Lock do?

Embeddable JavaScript login widget from Okta owned Auth0 that renders a configurable signup, login and MFA UI on top of an Auth0 tenant and sets authentication session cookies.

What Auth0 Lock is

Auth0 Lock is the embeddable JavaScript widget from Auth0, now part of Okta, that renders a configurable signup, login and multi factor authentication UI inside a website or single page application. It connects to an Auth0 tenant through the OAuth 2.0 and OpenID Connect protocols and delegates the heavy lifting (credential storage, MFA, anomaly detection, social federation) to the Auth0 platform.

Cookies and data collected

Once a session is established, Auth0 sets several cookies on the tenant domain (auth0, did, did_compat, auth0_compat) and possibly state cookies on the application origin during the OAuth callback. The widget also collects device fingerprinting signals, IP, user agent and geolocation hints which feed Auth0 anomaly detection, brute force protection and bot detection.

GDPR and ePrivacy implications

Authentication cookies that are strictly necessary to deliver the login service requested by the user are exempt from consent under Art. 5(3) ePrivacy. Device fingerprinting, anomaly profiling and any persistent identifier set beyond the session length do, however, fall under the consent regime, and a transparent privacy notice describing each cookie is required.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

International transfers

Auth0 tenants can be pinned to US, EU, AU or JP regions, but Okta Inc. remains a US sub processor that handles anomaly detection, telemetry and global support. Transfers rely on Standard Contractual Clauses, the EU US Data Privacy Framework, and binding corporate rules. A tenant configured in the EU region significantly reduces routine transfers but does not eliminate them.

Practical compliance steps

Pin the tenant to the EU region for European users, sign the Okta Data Processing Addendum, enable custom domains to keep cookies first party, disable optional Auth0 marketing analytics in the dashboard, document attack protection and anomaly detection in the privacy notice and the record of processing.

GDPR consent category

Essential

Websites using Auth0 Lock must obtain user consent under GDPR regulations.

Legal basisAuthentication cookies and the session needed to deliver the login service the user requested are strictly necessary and exempt from consent. However, optional features such as analytics, marketing redirects, social login persistent identifiers beyond the session, and persistent cross device tracking through device fingerprinting require either consent (Art. 6(1)(a) GDPR) or a documented legitimate interest balancing test (Art. 6(1)(f) GDPR).
Risk levelhigh
Applicable regulationsGDPR, ePrivacy Directive (Cookie Law), CCPA, HIPAA (with BAA), SOC 2

DPIA considerations

A DPIA is recommended whenever Auth0 is used as the primary identity layer for a high traffic consumer service, when MFA collects biometrics or device telemetry, or when the tenant is set up in the US region while serving EU users. Assess anomaly detection profiling, log retention, attack protection signals and any social or enterprise connections that introduce additional processors.

Sample consent text

We use Auth0 Lock from Okta to manage account creation, login and multi factor authentication. Session cookies needed to keep you signed in are set automatically. With your consent, additional optional analytics and device fingerprinting signals are processed to detect suspicious activity and improve security.

Technical details

Tracking methodEmbeddable JavaScript widget (auth0-lock and the related Auth0.js / auth0-spa-js libraries) that renders a configurable login and signup UI on top of an Auth0 tenant. The widget orchestrates redirect or popup flows to Auth0 hosted endpoints, sets authentication cookies in the Auth0 tenant domain (auth0, did, did_compat, auth0_compat) when a session is established, may set a state cookie at the application origin during the OAuth callback, and forwards device fingerprinting and bot detection signals to Auth0 anomaly detection.
Server locationUnited States (Okta, Inc., headquartered in San Francisco). Auth0 tenants can be provisioned in the US (default), EU (Frankfurt and Dublin), AU (Sydney), or JP (Tokyo) regions on AWS. Tenant region pins user database, session and log data, but anomaly detection, support, and product telemetry are processed centrally by Okta in the US.
Data transferred outside the EUEven with an EU tenant, Okta Inc. (the parent company in the United States) acts as a sub processor for anomaly detection, telemetry, support and the unified Customer Identity Cloud back office. Auth0 relies on Standard Contractual Clauses, the EU US Data Privacy Framework, and binding corporate rules. Some integrations (Auth0 Marketplace add ons, social connections) may add further transfers.

Third-party domains contacted

*.auth0.com*.eu.auth0.com*.us.auth0.comcdn.auth0.comcdn.eu.auth0.comsentry.io

Cookies placed

NameTypeDurationPurpose
auth0HTTP cookieSessionStores the Auth0 single sign on session for the tenant domain after a successful login.
didHTTP cookie1 yearDevice identifier used by Auth0 for attack protection, anomaly detection and bot detection.
did_compatHTTP cookie1 yearSame device identifier issued without the SameSite attribute for legacy browser compatibility.
auth0_compatHTTP cookieSessionLegacy SSO session cookie used by older browsers that do not handle SameSite=None correctly.
a0_stateHTTP cookie10 minutesStores the OAuth state and nonce values during the authorization code callback to prevent CSRF.
_legacy_auth0.is.authenticatedlocalStoragePersistentUsed by auth0-spa-js to mark a returning user as authenticated for silent token renewal flows.

Auth0 Lock is an essential service, but transparency matters. Manage all your consent with FlowConsent.

Get started freeScan your site

Frequently asked questions

Which cookies does Auth0 Lock set?

Auth0 sets session cookies on the tenant domain (auth0, did, did_compat, auth0_compat) plus optional state and nonce cookies on the application origin during OAuth callbacks. Custom domains let you keep these cookies first party on your own domain.

Is user consent required?

Session cookies that are strictly necessary to authenticate the user are exempt under Art. 5(3) ePrivacy. Device fingerprinting, anomaly profiling and persistent identifiers used for cross device analytics require consent.

What is the legal basis?

Contract performance (Art. 6(1)(b) GDPR) covers account creation and login itself. Anomaly detection and attack protection relies on legitimate interests (Art. 6(1)(f) GDPR) and any optional analytics requires consent (Art. 6(1)(a) GDPR).

Are there transfers to the US?

Yes. Even with an EU tenant, Okta Inc. in the United States acts as sub processor for anomaly detection, telemetry and support. Transfers rely on Standard Contractual Clauses, the EU US Data Privacy Framework and binding corporate rules.

Should we run a DPIA?

A DPIA is recommended for high traffic consumer services, biometric MFA, and any tenant pinned to the US region while serving EU users. Document profiling by anomaly detection, log retention, attack protection and any social or enterprise connection.

How do we deploy Auth0 Lock compliantly?

Choose the EU region, enable custom domains, sign the Okta DPA, integrate the widget after consent for any non essential cookies, configure log retention, and disable optional Auth0 marketing analytics in the tenant settings.

Are there alternatives?

EU based identity providers include Keycloak (self hosted, open source), Ory, FusionAuth (self hostable), Frontegg, and managed services like Microsoft Entra External ID or Curity hosted within the EU.

How should we update the cookie policy?

Add an entry for Auth0 Lock, list the session cookies (auth0, did, did_compat, auth0_compat), describe purposes (authentication, attack protection, anomaly detection), durations, US transfer details, and link to Okta's privacy notice and DPA.