Skip to main content
To configure anonymous sessions, you can use the Auth0 Dashboard or the Management API.

Prerequisites

To use anonymous sessions:

Configure anonymous sessions

  1. Navigate to Dashboard > Tenant Settings > Advanced, and scroll down to the session settings. The Tenant settings page in the Auth0 Dashboard
  2. Enter a value for the Anonymous Session Lifetime in minutes.
  3. Enable or disable the Anonymous Session Cookie switch to control whether anonymous session requests return the auth0_anon cookie.

Enable anonymous sessions in your application

  1. Navigate to Dashboard > Applications > Applications, and select the application you want to configure.
  2. Scroll down to the Anonymous Sessions settings. The Applications settings page in the Auth0 Dashboard
  3. Enable the switch to Allow Anonymous Sessions.

Enable anonymous access in your API

  1. Navigate to Dashboard > Applications > APIs, and select the API you want to configure.
  2. In the Access token expiration section, set the Anonymous Access Token Lifetime in seconds. The minimum is one day (86400 seconds) and the maximum is 30 days (2592000 seconds). The API settings page in the Auth0 Dashboard
  3. Under Application Access Policy, set the Anonymous Access policy to Per-app authorization to enable anonymous sessions using this audience for their access tokens. The Application access policy settings page in the Auth0 Dashboard

Create an API Access policy for anonymous users

  1. Navigate to Dashboard > Applications > APIs, and select the API you want to configure.
  2. Select the Application Access tab.
  3. For each application you want this API to issue access tokens to in an anonymous context, select Edit. The API application access settings page in the Auth0 Dashboard
  4. Select Anonymous Access, and Configure the permissions you want to grant anonymous users when using this application. The Applications settings page in the Auth0 Dashboard
  5. Select Save.

Create an anonymous session

Once anonymous sessions are configured in your tenant, application, and API, you can create an anonymous session by making a POST request to the /anonymous/token endpoint:
The response includes a session_token and an access_token:

Configure custom claims

You can configure custom claims to map anonymous session metadata directly into the access tokens issued for a specific audience. This is useful because there is no post-login Action execution with anonymous sessions, so api.accessToken.setCustomClaim() is not available to enrich anonymous access tokens the way it is for authenticated ones. To learn more, read Configure Custom Claims for Anonymous Sessions.

Next steps

Anonymous Sessions Use Cases

Learn about anonymous sessions use cases.