Introduction
Dossier uses Auth0 for authentication. Users sign in through Auth0 using the login methods configured for your tenant — password login, Google OAuth, or a custom SSO connection. After authentication, the API issues a JWT access token and refresh token to maintain the session.
Access is account-based, not domain-based. A user must be created or invited in Dossier before they can sign in. Auth0 accounts that are not linked to a Dossier user record are rejected at login.
This section covers:
- How sign-in, sign-out, and session refresh work
- The invitation flow for new users
- How tenant administrators configure authentication methods