Skip to main content
This guide describes how to configure individual user authentication and authorization for applications running behind a Datum gateway using datumctl. Auth0 handles Google social login and enforces an email-based allow-list β€” unauthorized users are blocked before a token is ever issued. The configuration uses Envoy Gateway SecurityPolicy resources and applies to Windows, macOS, and Linux.

How it works

Authentication (who are you): Auth0 handles Google social login.
Authorization (are you allowed): Auth0 checks the user against your allow-list before issuing a token. Unauthorized users never get a token β€” Envoy never sees them.

Prerequisites

  • datumctl installed and authenticated
  • A valid Datum Project
  • An existing HTTPProxy in the Datum UI (this provides the Gateway and HTTPRoute automatically)
  • An Auth0 account (free tier is sufficient)
  • A Google Cloud project for the social connection
Note: The HTTPProxy name is the name of the auto-generated HTTPRoute that the SecurityPolicy will target. Find it with:

Part 1: Auth0 setup

Step 1: Create an Auth0 tenant

  1. Sign up at auth0.com and create a tenant
  2. Note your tenant domain β€” it looks like dev-xxxxxxxx.us.auth0.com

Step 2: Create an application

  1. In the Auth0 dashboard go to Applications β†’ Applications β†’ Create Application
  2. Name it (e.g. datum-gateway-app)
  3. Select Regular Web Applications
  4. Select Create
  5. On the Settings tab, note your Client ID and Client Secret
  6. Under Allowed Callback URLs add:
  7. Under Allowed Logout URLs add:
  8. Select Save Changes

Step 3: Enable Google social login

  1. Go to Authentication β†’ Social β†’ Create Connection
  2. Select Google / Gmail
  3. Enter your Google OAuth Client ID and Client Secret (from Google Cloud Console β†’ APIs & Services β†’ Credentials)
  4. Enable the connection for your application under the Applications tab of the connection
  5. In Google Cloud Console, add Auth0’s callback URL to your OAuth client’s Authorized redirect URIs:
    This is required so Google can redirect back to Auth0 after login. Without it, Google returns Error 400: redirect_uri_mismatch.
Note: If you do not have Google OAuth credentials yet, Auth0 provides a built-in dev key for testing. Go to the Google connection settings and leave Client ID/Secret blank β€” Auth0 will use its own dev credentials. Create dedicated Google OAuth credentials before moving to production.

Step 4: Create an access control action

This is where individual user access is enforced. Auth0 runs this code during login β€” users not in the list are denied before a token is ever issued.
  1. Go to Actions β†’ Library β†’ Build Custom
  2. Name it enforce-email-allowlist
  3. Select Login / Post Login trigger
  4. Replace the default code with:
  1. Select Deploy
  2. Go to Actions β†’ Triggers β†’ post-login
  3. Drag your enforce-email-allowlist action from the right sidebar into the flow between Start and Complete
  4. Select Apply
To add or remove a user: edit the allowedEmails array and select Deploy. No gateway config changes required.

Part 2: Datum gateway configuration

The Datum HTTPProxy already manages the Gateway and HTTPRoute. You only need to create a Secret (to store the Auth0 client secret) and a SecurityPolicy (to attach OIDC to the route).

Step 1: Set variables

Windows (PowerShell)

macOS / Linux


Step 2: Create the Auth0 client secret

The Secret must include the gateway-sync label or the edge proxy will not receive it and all requests will return HTTP 500.

Windows (PowerShell)

macOS / Linux


Step 3: Apply the SecurityPolicy

This attaches OIDC authentication to the existing HTTPProxy route.
Warning: Use only the oidc block β€” do not add a jwt block, as it conflicts with the OIDC filter and causes HTTP 500.

Windows (PowerShell)

macOS / Linux

Allow 60 seconds for the policy to propagate to the edge before testing.

Verification

Unauthenticated request β€” redirects to Auth0

Expected:

Browser flow β€” allowed user

  1. Open https://your-app.example.com in a browser
  2. You are redirected to Auth0 β†’ Google login
  3. Sign in with an email in the allow-list
  4. You are redirected back and the app loads β€” HTTP 200

Browser flow β€” denied user

  1. Sign in with an email not in the allow-list
  2. Auth0 displays: Access denied: you are not authorized to use this application.
  3. No token is issued β€” Envoy is never reached

Managing access

All access control is managed in the Auth0 dashboard β€” no gateway config changes needed. Add a user:
  1. Go to Actions β†’ Library β†’ enforce-email-allowlist
  2. Add the email to allowedEmails
  3. Select Deploy
Remove a user:
  1. Remove the email from allowedEmails
  2. Select Deploy
  3. Optionally revoke any active sessions: User Management β†’ find user β†’ Invalidate Sessions

Cleanup

Windows (PowerShell)

macOS / Linux


Troubleshooting

Useful debug commands


Summary

Last modified on July 6, 2026