First of all, I am new to Auth0 and I don't have a good knowledge when it comes to security.
I have an application that uses React as the client and Dotnet Core as the back end API. I have successfully integrated the Auth0 with both client and server sides. From the client, I can successfully log in using Auth0 and get the access token, and call to a protected route in backend API.
From the API I want to get the user profile corresponding to the access token.
I followed this tutorial but I am getting null for all as well as claims.
Apart from that, I have decoded the access token from JWT.IO then I noticed that there are no values in the payload that I'm looking for.
From another tutorial, they said that I have to include scopes of the request from the client. But that didn't help either.
auth0 = new auth0.WebAuth({
domain: AUTH_CONFIG.domain,
clientID: AUTH_CONFIG.clientID,
redirectUri: AUTH_CONFIG.redirectUri,
audience: AUTH_CONFIG.audience,
responseType: 'token id_token',
scope: 'openid profile email name'
});
On the client, I am getting 2 tokens after a successful login.
- Identity Token: Which includes all the information that I need. But can't use as a bearer token to call my endpoint
- Access Token: Which I can use as a bearer token to call to the endpoint, But there is no useful information in the payload.
I don't know the way I am following is wrong or not. If there is any other way please help me.