Connect Auth0
For centers that already run an Auth0 tenant and want staff signing in through it.
Who this is for
Centers that already operate an Auth0 tenant — usually multi-site groups with their own IT, or operators whose other systems already sit behind it. If you don't run one today, this isn't a reason to start; JumpCloud or Okta are more usual for a single center.
Setting it up
Connect your tenant from your center's integration settings: the issuer, a client ID and a client secret from an application you create in Auth0 for RoundUp. Once connected, staff see Sign in with Auth0 on the sign-in screen.
Staff email addresses must match between Auth0 and their RoundUp staff record — that's the identifier RoundUp matches on.
A connection belongs to one center, and a sign-in through it can only land in that center. A group running several centers connects each one, which is what keeps a sign-in at one site from reaching another site's roster.
One provider at a time
A center signs its staff in with one identity provider. While Auth0 is connected, the Okta and OpenID Connect tiles explain that rather than offering to connect — and the same in reverse. To switch, disconnect the one you have, then connect the new one.
A center that connected two before this restriction existed keeps working: Okta takes precedence, and disconnecting it promotes the other rather than locking anyone out.
Accounts still come from invitations
Signing in never creates an account. Someone authenticating through your tenant without a staff account at the center is refused and told to ask their director.
This is deliberate: it keeps a directory identity, on its own, from opening access to children's records. See Roles and permissions.
Troubleshooting
The button doesn't appear
The connection is incomplete. RoundUp only offers a provider it can actually complete a sign-in with, so a partial configuration falls back to the password screen rather than dead-ending your staff.
Sign-in succeeds, then RoundUp refuses
The email in Auth0 doesn't match a staff account at that center. Compare the two addresses character by character before looking anywhere else.
"This account isn't registered for this app"
The sign-in landed on a different center or a different RoundUp app than the account belongs to. Check the connection is on the center you intended.
More: All director guides