> ## Documentation Index
> Fetch the complete documentation index at: https://auth0-chore-events-autoupdate.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Configure Anonymous Sessions

> Learn how to configure anonymous sessions using the Auth0 Dashboard or Management API.

export const ReleaseStageNotice = ({feature, stage, plans, contact, terms}) => {
  const stageTextMap = {
    "beta": "Beta",
    "ea": "Early Access"
  };
  const stageText = stageTextMap[stage] || "a product release stage";
  const prsLink = "/docs/troubleshoot/product-lifecycle/product-release-stages";
  const linkify = (text, url) => {
    return <a href={url} target="_blank" rel="noreferrer" class="link">{text}</a>;
  };
  const includeDetails = (plans, contact, terms) => {
    const hasDetails = terms || plans || contact;
    if (!hasDetails) return null;
    return <span data-as="p">
            {plans && <>This feature is available for {linkify(`${plans} plans`, "https://auth0.com/pricing")}. </>}
            {contact && "To participate, contact " + contact + ". "}
            {terms && <>By using this feature, you agree to the applicable Free Trial terms in Okta's {linkify("Master Subscription Agreement", "https://www.okta.com/legal")}.</>}
        </span>;
  };
  return <Warning>
            <span data-as="p">
                <strong>The {feature} feature is in {linkify(stageText, prsLink)}.</strong>
            </span>

            {includeDetails(plans, contact, terms)}
        </Warning>;
};

<ReleaseStageNotice feature="Anonymous Sessions" stage="ea" plans="Enterprise" contact="your Account Executive" />

To configure anonymous sessions, you can use the [Auth0 Dashboard](/docs/get-started/auth0-overview/dashboard) or the [Management API](/docs/api/management/v2).

## Prerequisites

To use anonymous sessions:

* You must [have an Auth0 account](https://auth0.com/).
* [Register your Auth0 application](/docs/get-started/auth0-overview/create-applications). If you do not have an Auth0 application, you can get started with the Auth0 React or Next.js [Quickstarts](https://auth0.com/docs/quickstart/spa/react).
* [Register an API (resource server)](/docs/get-started/auth0-overview/set-up-apis).

## Configure anonymous sessions

<Tabs>
  <Tab title="Auth0 Dashboard">
    1. Navigate to [**Dashboard > Tenant Settings > Advanced**](https://manage.auth0.com/#/tenant/advanced), and scroll down to the session settings.

           <img src="https://mintlify.s3.us-west-1.amazonaws.com/auth0-chore-events-autoupdate/docs/images/sessions/anonymous_sessions/anonymous_sessions.png" alt="The Tenant settings page in the Auth0 Dashboard" />

    2. Enter a value for the **Anonymous Session Lifetime** in minutes.

    3. Enable or disable the **Anonymous Session Cookie** switch to control whether anonymous session requests return the `auth0_anon` cookie.
  </Tab>

  <Tab title="Management API">
    To configure the anonymous session lifetime and cookie behavior, make a `PATCH` request to the [`/api/v2/tenants/settings`](/docs/api/management/v2/tenants/patch-settings) endpoint:

    ```json theme={null}
    {
      "sessions": {
        "anonymous": {
          "lifetime_in_minutes": 144000,
          "activate_cookie": true
        }
      }
    }
    ```

    * `lifetime_in_minutes` sets how long a session is valid for.
    * `activate_cookie` sets whether to issue the `auth0_anon` cookie in anonymous flows. Set this to `false` if you plan to use the [cookieless transfer-ticket mechanism](/docs/manage-users/sessions/anonymous-sessions#transfer-a-session-through-a-transfer-ticket) instead.
  </Tab>
</Tabs>

## Enable anonymous sessions in your application

<Tabs>
  <Tab title="Auth0 Dashboard">
    1. Navigate to [**Dashboard > Applications > Applications**](https://manage.auth0.com/#/applications), and select the application you want to configure.

    2. Scroll down to the **Anonymous Sessions** settings.

           <img src="https://mintlify.s3.us-west-1.amazonaws.com/auth0-chore-events-autoupdate/docs/images/sessions/anonymous_sessions/anonymous_sessions_application.png" alt="The Applications settings page in the Auth0 Dashboard" />

    3. Enable the switch to **Allow Anonymous Sessions**.
  </Tab>

  <Tab title="Management API">
    To enable anonymous sessions in your Auth0 application, make a `PATCH` request to the [`/api/v2/clients/{id}`](/docs/api/management/v2/clients/patch-clients-by-id) endpoint:

    ```json theme={null}
    {
      "anonymous_sessions": {
        "active": true
      }
    }
    ```
  </Tab>
</Tabs>

## Enable anonymous access in your API

<Tabs>
  <Tab title="Auth0 Dashboard">
    1. Navigate to [**Dashboard > Applications > APIs**](https://manage.auth0.com/#/apis), and select the API you want to configure.

    2. In the **Access token expiration** section, set the **Anonymous Access Token Lifetime** in seconds. The minimum is one day (86400 seconds) and the maximum is 30 days (2592000 seconds).

           <img src="https://mintlify.s3.us-west-1.amazonaws.com/auth0-chore-events-autoupdate/docs/images/sessions/anonymous_sessions/anonymous_sessions_api.png" alt="The API settings page in the Auth0 Dashboard" />

    3. Under **Application Access Policy**, set the **Anonymous Access** policy to **Per-app authorization** to enable anonymous sessions using this audience for their access tokens.

           <img src="https://mintlify.s3.us-west-1.amazonaws.com/auth0-chore-events-autoupdate/docs/images/sessions/anonymous_sessions/anonymous_sessions_api_policy.png" alt="The Application access policy settings page in the Auth0 Dashboard" />
  </Tab>

  <Tab title="Management API">
    To enable anonymous sessions in your API, make a `PATCH` request to the [`/api/v2/resource-servers/{id}`](/docs/api/management/v2/resource-servers/patch-resource-servers-by-id) endpoint:

    ```json theme={null}
    {
      "token_lifetime_for_anonymous_access_tokens": 86400,
      "subject_type_authorization": {
        "user":           { "policy": "allow_all" },
        "client":         { "policy": "deny_all" },
        "anonymous_user": { "policy": "require_client_grant" }
      }
    }
    ```

    * `token_lifetime_for_anonymous_access_tokens` sets the expiration time, in seconds, of access tokens this API issues in an anonymous session context.
    * `subject_type_authorization.anonymous_user` sets whether individual applications can use this API in anonymous sessions (based on policies) or whether this API disallows issuing anonymous access tokens at all.
  </Tab>
</Tabs>

## Create an API Access policy for anonymous users

<Tabs>
  <Tab title="Auth0 Dashboard">
    1. Navigate to [**Dashboard > Applications > APIs**](https://manage.auth0.com/#/apis), and select the API you want to configure.

    2. Select the **Application Access** tab.

    3. For each application you want this API to issue access tokens to in an anonymous context, select **Edit**.

           <img src="https://mintlify.s3.us-west-1.amazonaws.com/auth0-chore-events-autoupdate/docs/images/sessions/anonymous_sessions/anonymous_sessions_api_application_access.png" alt="The API application access settings page in the Auth0 Dashboard" />

    4. Select **Anonymous Access**, and **Configure** the permissions you want to grant anonymous users when using this application.

           <img src="https://mintlify.s3.us-west-1.amazonaws.com/auth0-chore-events-autoupdate/docs/images/sessions/anonymous_sessions/anonymous_sessions_api_anonymous_access_drawer.png" alt="The Applications settings page in the Auth0 Dashboard" />

    5. Select **Save**.
  </Tab>

  <Tab title="Management API">
    Once anonymous sessions are enabled in your API, make a `POST` request to the [`/api/v2/client-grants`](/docs/api/management/v2/client-grants/post-client-grants) endpoint:

    ```json theme={null}
    {
      "audience": "YOUR_AUDIENCE",
      "client_id": "YOUR_CLIENT_ID",
      "scope": [ "read", "write", "delete" ],
      "subject_type": "anonymous_user"
    }
    ```
  </Tab>
</Tabs>

## Create an anonymous session

Once anonymous sessions are configured in your tenant, application, and API, you can create an anonymous session by making a `POST` request to the `/anonymous/token` endpoint:

```json theme={null}
{
  "client_id": "YOUR_CLIENT_ID",
  "client_secret": "YOUR_CLIENT_SECRET", // for confidential clients
  "audience": "YOUR_AUDIENCE",
  "scope": "anon"
}
```

The response includes a `session_token` and an `access_token`:

```json theme={null}
{
  "session_token": "eyJhbGciOiJkaXIiLCJlbmMiOiJBMjU2R0NNIn0...",
  "access_token": "eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCJ9...",
  "token_type": "Bearer",
  "expires_in": 86400
}
```

## Configure custom claims

You can configure custom claims to map anonymous session metadata directly into the access tokens issued for a specific audience.

This is useful because there is no [`post-login`](/docs/customize/actions/explore-triggers/post-login) Action execution with anonymous sessions, so `api.accessToken.setCustomClaim()` is not available to enrich anonymous access tokens the way it is for authenticated ones. To learn more, read [Configure Custom Claims for Anonymous Sessions](/docs/manage-users/sessions/anonymous-sessions/configure-custom-claims-for-anonymous-sessions).

## Next steps

<Card title="Anonymous Sessions Use Cases" icon="lightbulb" href="/docs/manage-users/sessions/anonymous-sessions/anonymous-sessions-use-cases" horizontal>
  Learn about anonymous sessions use cases.
</Card>
