Skip to main content
Cient metadata is an optional field stored as part of the application (client) properties. It consists of customizable keys and values that you can set for each application. You might store, for example, the URL for the application’s home page (a field that Auth0 doesn’t provide by default in the application settings).

Where to store client secrets

Where to store the secret depends on the scope of the secret:
  • Is it just one secret per application? Then client_metadata would be a good place.
  • Is it the same secret for the whole system (i.e., for all applications or many)? Then the rule’s configuration values might be a better choice.
  • Is it a different secret for each user? Then storing in the user profile’s app_metadata might be better.
Claims in the ID token are not encrypted, so depending on the flow that you use, the user might be able to get the token and inspect the contents. Auth0 does not recommend storing a secret in that way.

Configure application metadata

You can set application metadata using the Auth0 Dashboard or the .
  1. Go to Dashboard > Applications > Applications and select the application.
  2. On the Settings tab, scroll to the bottom of the page and select Advanced Settings to expand the section.
    Dashboard Applications Applications Settings Tab Advanced Settings Application Metadata Tab
  3. In the Application Metadata tab, you can:
    • Add metadata by entering a key and value, then selecting + Add.
    • Update metadata by entering a key you want to update and a new value, then selecting + Add.
    • Delete metadata by selecting the trash can icon next to the key/value pair.
  4. When you’re done, select Save Changes.

View application metadata

Metadata is exposed in the Client object as client_metadata, and in Rules as context.clientMetadata. You can access application metadata in Actions:
… or in Rules:
Client metadata is also included in the responses from the Management API’s GET /api/v2/clients and GET /api/v2/client/{id} endpoints.

Limits

  • The client_metadata field can have a maximum of 10 keys.
  • client_metadata keys and values have a maximum length of 255 characters each.
  • client_metadata keys and values cannot contain UTF-8 special characters.