Skip to main content
This guide describes how to configure individual user authentication and authorization for applications running behind a Datum gateway using datumctl. Auth0 handles Google social login and enforces an email-based allow-list — unauthorized users are blocked before a token is ever issued. The configuration uses Envoy Gateway SecurityPolicy resources and applies to Windows, macOS, and Linux.

How it works

Authentication (who are you): Auth0 handles Google social login.
Authorization (are you allowed): Auth0 checks the user against your allow-list before issuing a token. Unauthorized users never get a token — Envoy never sees them.

Prerequisites

  • datumctl installed and authenticated
  • A valid Datum Project
  • An existing HTTPProxy in the Datum UI (this provides the Gateway and HTTPRoute automatically)
  • An Auth0 account (free tier is sufficient)
  • A Google Cloud project for the social connection
Note: The HTTPProxy name is the name of the auto-generated HTTPRoute that the SecurityPolicy will target. Find it with:

Part 1: Auth0 setup

Step 1: Create an Auth0 tenant

  1. Sign up at auth0.com and create a tenant
  2. Note your tenant domain — it looks like dev-xxxxxxxx.us.auth0.com

Step 2: Create an application

  1. In the Auth0 dashboard go to ApplicationsApplicationsCreate Application
  2. Name it (e.g. datum-gateway-app)
  3. Select Regular Web Applications
  4. Select Create
  5. On the Settings tab, note your Client ID and Client Secret
  6. Under Allowed Callback URLs add:
  7. Under Allowed Logout URLs add:
  8. Select Save Changes

Step 3: Enable Google social login

  1. Go to AuthenticationSocialCreate Connection
  2. Select Google / Gmail
  3. Enter your Google OAuth Client ID and Client Secret (from Google Cloud Console → APIs & Services → Credentials)
  4. Enable the connection for your application under the Applications tab of the connection
  5. In Google Cloud Console, add Auth0’s callback URL to your OAuth client’s Authorized redirect URIs:
    This is required so Google can redirect back to Auth0 after login. Without it, Google returns Error 400: redirect_uri_mismatch.
Note: If you do not have Google OAuth credentials yet, Auth0 provides a built-in dev key for testing. Go to the Google connection settings and leave Client ID/Secret blank — Auth0 will use its own dev credentials. Create dedicated Google OAuth credentials before moving to production.

Step 4: Create an access control action

This is where individual user access is enforced. Auth0 runs this code during login — users not in the list are denied before a token is ever issued.
  1. Go to ActionsLibraryBuild Custom
  2. Name it enforce-email-allowlist
  3. Select Login / Post Login trigger
  4. Replace the default code with:
  1. Select Deploy
  2. Go to ActionsTriggerspost-login
  3. Drag your enforce-email-allowlist action from the right sidebar into the flow between Start and Complete
  4. Select Apply
To add or remove a user: edit the allowedEmails array and select Deploy. No gateway config changes required.

Part 2: Datum gateway configuration

The Datum HTTPProxy already manages the Gateway and HTTPRoute. You only need to create a Secret (to store the Auth0 client secret) and a SecurityPolicy (to attach OIDC to the route).

Step 1: Set variables

Windows (PowerShell)

macOS / Linux


Step 2: Create the Auth0 client secret

The Secret must include the gateway-sync label or the edge proxy will not receive it and all requests will return HTTP 500.

Windows (PowerShell)

macOS / Linux


Step 3: Apply the SecurityPolicy

This attaches OIDC authentication to the existing HTTPProxy route.
Warning: Use only the oidc block — do not add a jwt block, as it conflicts with the OIDC filter and causes HTTP 500.

Windows (PowerShell)

macOS / Linux

Allow 60 seconds for the policy to propagate to the edge before testing.

Verification

Unauthenticated request — redirects to Auth0

Expected:

Browser flow — allowed user

  1. Open https://your-app.example.com in a browser
  2. You are redirected to Auth0 → Google login
  3. Sign in with an email in the allow-list
  4. You are redirected back and the app loads — HTTP 200

Browser flow — denied user

  1. Sign in with an email not in the allow-list
  2. Auth0 displays: Access denied: you are not authorized to use this application.
  3. No token is issued — Envoy is never reached

Managing access

All access control is managed in the Auth0 dashboard — no gateway config changes needed. Add a user:
  1. Go to ActionsLibraryenforce-email-allowlist
  2. Add the email to allowedEmails
  3. Select Deploy
Remove a user:
  1. Remove the email from allowedEmails
  2. Select Deploy
  3. Optionally revoke any active sessions: User Management → find user → Invalidate Sessions

Cleanup

Windows (PowerShell)

macOS / Linux


Troubleshooting

Useful debug commands


Summary

Last modified on June 22, 2026