For the complete documentation index, see llms.txt. This page is also available as Markdown.

Quickstart: Auth0-Protected Route

Stand up an Auth0-backed route when you need hosted identity and token validation at the edge. This guide covers the authorizer block for Auth0, the callback

Stand up an Auth0-backed route when you need hosted identity and token validation at the edge. This guide covers the authorizer block for Auth0, the callback integration, and the environment variables you need to set. Refer to the Auth0 cluster for deeper coverage of JWKS, refresh tokens, and userinfo.

Last reviewed: 2026-03-06

When to use this

Use these quickstart guides when you are setting up Serverless API Gateway for the first time or adding a new integration pattern. Each guide walks through one isolated concern so you can deploy incrementally instead of configuring everything at once.

Key concepts

  • Every quickstart produces a deployable wrangler.toml and JSON config pair -- you can run wrangler deploy at the end of each guide.

  • Guides are ordered from simplest (health endpoint) to most complex (Auth0/Supabase passwordless), so earlier guides serve as prerequisites for later ones.

  • Config can come from a local file, Cloudflare KV, or the SAG_API_CONFIG_JSON environment variable -- choose based on your deploy workflow.

  • All guides use the same JSON config schema, so patterns you learn in one guide transfer directly to others.

Repo-grounded example

{
  "authorizer": {
    "type": "auth0",
    "domain": "$env.AUTH0_DOMAIN",
    "client_id": "$env.AUTH0_CLIENT_ID",
    "client_secret": "$secrets.AUTH0_CLIENT_SECRET",
    "redirect_uri": "https://api.example.com/api/v1/auth0/callback",
    "callback_uri": "https://app.example.com/auth/callback",
    "jwks_uri": "https://tenant.us.auth0.com/.well-known/jwks.json",
    "scope": "openid profile email"
  },
  "paths": [
    {
      "method": "GET",
      "path": "/api/v1/auth0/callback",
      "integration": { "type": "auth0_callback" }
    }
  ]
}

This snippet sets up the Auth0 authorizer with domain, client credentials, JWKS URI, and redirect/callback URIs. The callback path uses the auth0_callback integration type, which exchanges the authorization code for tokens at the edge.

Troubleshooting

  • If wrangler deploy fails with a config error, validate your JSON against the schema file (api-config.schema.json) before investigating further.

  • If the health endpoint returns 404, confirm that your wrangler.toml points to the correct main entrypoint and that the config file is being loaded.

  • If JWT or Auth0 routes return 500, check that all required environment variables and secrets are set in your Cloudflare dashboard or .dev.vars file.

  • Use wrangler tail to stream live logs from the deployed worker and see the exact error message the gateway produces.

Last updated