Auth0 Tenant Comparator
UI v2.13.2
Compare two Auth0 tenants via the Management API. The simplest path: paste a short-lived Management API token for each tenant in the Management API tokens panel below (session-only, never stored), pick it per slot, then run Compare tenants. Saved Tenant Admin Access profiles also work.
Advanced (optional): provision a dedicated M2M app instead of pasting a token
Most users should just paste a short-lived Management API token above. If you instead want a dedicated machine-to-machine credential, this Read Tenant Settings wizard provisions or fixes the M2M app in your tenant, then Save Read Tenant Settings profile adds credentials to your saved configuration list on the main page — load that profile into Tenant A or Tenant B when you are ready to compare. When Tenant Admin Access has a valid Management domain and credentials, the wizard can use it (no pasted bearer). Otherwise click Do it for me and paste a temporary token. Same phased flow as Configure Tenant Admin Access → Auth0 Read Access wizard. If you are not using Tenant Admin Access, enter a full Management Auth0 Domain on Tenant A or B first so planned URLs can resolve. Optional dashboard and copy-paste JSON are collapsed under Manual at the bottom — expand only if you need them.
Read Tenant Settings
Read Tenant Settings — automated setup
Click Do it for me below to paste a temporary Management API bearer token (not stored by this wizard). Then use Check configuration. New creates use Private Key JWT — the private key is written into Active Tenant Admin Access on the server (encrypted app storage or Azure Key Vault) and never returned to the browser.
To run Check configuration, provide a full Management hostname: save one under ⚙️ Tenant Admin Access, enter Auth0 Domain on this tenant card, or use a Management API token whose iss is a full hostname (e.g. https://tenant.us.auth0.com/).
Manual: Auth0 Dashboard & copy-paste API (optional)
Create a Machine to Machine application, authorize the Auth0 Management API with the scopes below, then use its Client ID and Client Secret here or under Tenant Admin Access. For client credentials, the audience is https://YOUR_TENANT.auth0.com/api/v2/ (use your tenant domain from the dashboard).
Auth0 Dashboard
- Open manage.auth0.com and sign in.
- Select the tenant you want (tenant switcher, upper left).
- In the left sidebar, open Applications → Applications.
- Click Create Application (or + Create Application) to open the create dialog.
- Enter name Read Tenant Settings, choose type Machine to Machine, then click Create.
- On Authorize Machine to Machine Application, select Auth0 Management API and continue to the scope list.
- Enable every scope in the list below, then click Authorize.
- Open the application → Settings. Under Application URIs, set Allowed Callback URLs to
https://auth0-tools.idpify.comand save.
Auth0 Management API — scopes
For the M2M app, authorize Auth0 Management API with the read-only scopes below (no read:client_keys or key/secret scopes). When this tool exchanges client credentials, it requests only these scopes on the token. Pasted API Explorer bearers must use the same read-only set.
read:client_grantsread:clientsread:connectionsread:resource_serversread:rulesread:hooksread:actionsread:email_providerread:tenant_settingsread:triggersread:guardian_factorsread:custom_domainsread:email_templatesread:mfa_policiesread:rolesread:promptsread:brandingread:log_streamsread:attack_protectionread:organizationsread:organization_connectionsread:phone_providersread:phone_templatesread:formsread:flowsread:connection_profilesread:group_rolesread:network_acls
POST /api/v2/clients (copy-paste body)
Call POST https://YOUR_TENANT.auth0.com/api/v2/clients with a Management API access token that is allowed to create clients. Request body:
{
"name": "Read Tenant Settings",
"app_type": "non_interactive",
"grant_types": [
"client_credentials"
],
"callbacks": [
"https://auth0-tools.idpify.com"
]
}POST /api/v2/client-grants (after the client exists)
The create-client call does not grant Management API permissions. Use the client_id from the create response and POST to https://YOUR_TENANT.auth0.com/api/v2/client-grants (token needs permission to create client grants). scope must be a JSON array of strings (not one space-separated string). If a grant already exists, use PATCH …/client-grants/{id} with the same scope shape. Body:
{
"client_id": "YOUR_NEW_CLIENT_ID",
"audience": "https://YOUR_TENANT.auth0.com/api/v2/",
"scope": [
"read:client_grants",
"read:clients",
"read:connections",
"read:resource_servers",
"read:rules",
"read:hooks",
"read:actions",
"read:email_provider",
"read:tenant_settings",
"read:triggers",
"read:guardian_factors",
"read:custom_domains",
"read:email_templates",
"read:mfa_policies",
"read:roles",
"read:prompts",
"read:branding",
"read:log_streams",
"read:attack_protection",
"read:organizations",
"read:organization_connections",
"read:phone_providers",
"read:phone_templates",
"read:forms",
"read:flows",
"read:connection_profiles",
"read:group_roles",
"read:network_acls"
]
}Compare tenant configuration
Saved profiles store domain and credentials only. Drag a tile onto Tenant A or Tenant B to load it, or use the edit icon to rename. Run Compare tenants for fresh Management API data.
No saved profiles yet. Expand Tenant A or B, enter credentials, and click Save as profile, or use Save Read Tenant Settings profile above.