
Whitelist email addresses that has access

Go to Users & Roles and Create a user with a real email address. You will use this later so remember it

  • Click on Rules -> Whitelist

  • Enter in your email address into the whitelist field (e.g. Line 8 “const whitelist = [ ‘’]; //authorized users”)

Automatic assign default roles based on conditions in rule with the new Auth0’s Core Authorization

Its nice to be able to give the users default roles on Signup. Its possible by using the management API from Auth0 in a Rule to do custom roles logic on signup.

Found in Auth0 Community forum



function (user, context, callback) {
  // Roles should only be set to verified users.
  if (! || !user.email_verified) {
    return callback(null, user, context);
  // short-circuit if the user signed up already or is using a refresh token
  if (context.stats.loginsCount > 1 || context.protocol === 'oauth2-refresh-token') {
    return callback(null, user, context);
  const getRolesForUser = (user) => {
    const roles = [
      '<default role id assign to all users on signup eg. something like "rol_?????">' // default
    try {
      const emailDomain ='@')[1].toLowerCase();
      switch (emailDomain) {
        case '':
          roles.push('<default role id assign to users from domain on signup eg. something like "rol_?????">');
        // More custom rules here
      return roles;
    } catch (e) {
      return [];
  const roles = getRolesForUser(user);
  var ManagementClient = require('auth0@2.17.0').ManagementClient;
  var management = new ManagementClient({
    token: auth0.accessToken,
    domain: auth0.domain
  // Update the user's roles
  management.assignRolestoUser({ id : user.user_id }, { roles: roles }, (err) => {
    if (!err) {
      console.log('Roles [' + roles.join(', ') + '] assigned to user [' + + ']');
    } else {
    return callback(err, user, context);