Hi everyone. I'm still pretty new to Auth0 and was tasked with documenting our tenant setup. The config got complex fast with all the connections, rules, and client settings.
I ended up building a simple internal tool that generates a visual diagram. It pulls the basic structure (clients, connections, rules) via the Management API and draws a flowchart. It helped us spot a redundant rule and see which apps used which social logins.
Has anyone else built something like this? I'm curious about what others find most useful to track visually. I used Python and Graphviz, but it's pretty basic.
Still learning...
Trying to figure it out.
Nice, I've been down that road. Visualizing the tenant setup really does help, especially when onboarding new team members.
One thing I'd add is that mapping the rule execution order can be just as valuable as seeing the connections. Sometimes rules have dependencies on each other, and a flowchart showing that sequence saved us from a weird race condition.
Did you find the Management API straightforward for pulling everything? I remember the pagination being a bit finicky on the first try.
Oh man, visualizing Auth0 configs is such a rite of passage. I remember building something similar a few years back when we had a spaghetti situation of social connections. The Graphviz route is solid for a quick win.
> spot a redundant rule
That's the best feeling, right? Finding that one rule everyone forgot about that was adding latency to every login. For me, the visual "aha" moment was seeing which clients were still pointing to a legacy database connection we thought we'd deprecated. The diagram made the cleanup ticket impossible to ignore 😄
Keep iterating on it. Next time you're on call and get paged for an auth issue, you'll be glad you have a map.
it worked on my machine
Love that you started with Python and Graphviz - that's exactly how I started too. Spotting a redundant rule right away is a huge win for simplicity and performance.
One thing that bit us later was not including API audience/resource identifiers in those diagrams. When we started adding machine-to-machine flows, seeing which client could talk to which API became a huge visual gap. Maybe something to consider for v2!
The social logins map is super useful. We used a similar view to justify deprecating a lesser-used social connection, which trimmed our support surface area. Great work!
cost first, then scale
Exactly, that feeling when a diagram makes the cleanup ticket "impossible to ignore" is so real. It's like the tech debt becomes visible to the whole team, not just the person who knows the config.
Your point about being on call reminds me of another benefit: having that map lets you quickly rule out configuration issues during an incident. If the diagram shows the flow is correct, you can pivot faster to checking logs or third-party outages.
Did you find your visual tool needed constant updating as the tenant changed, or was it more of a periodic documentation snapshots?
ship early, test often