> ## Documentation Index
> Fetch the complete documentation index at: https://auth0.generaltranslation.app/llms.txt
> Use this file to discover all available pages before exploring further.

> Learn to enable Organization connections using the Auth0 Dashboard and Management API.

# Enable Organization Connections

export const AuthCodeGroup = ({children, dropdown}) => {
  const [processedChildren, setProcessedChildren] = useState(children);
  useEffect(() => {
    let unsubscribe = null;
    function init() {
      unsubscribe = window.autorun(() => {
        const processChildren = node => {
          if (typeof node === "string") {
            let processedNode = node;
            for (const [key, value] of window.rootStore.variableStore.values.entries()) {
              processedNode = processedNode.replace(new RegExp(key, "g"), value);
            }
            return processedNode;
          } else if (Array.isArray(node)) {
            return node.map(processChildren);
          } else if (node && node.props && node.props.children) {
            return {
              ...node,
              props: {
                ...node.props,
                children: processChildren(node.props.children)
              }
            };
          }
          return node;
        };
        setProcessedChildren(processChildren(children));
      });
    }
    if (window.rootStore) {
      init();
    } else {
      window.addEventListener("adu:storeReady", init);
    }
    return () => {
      window.removeEventListener("adu:storeReady", init);
      unsubscribe?.();
    };
  }, [children]);
  return <CodeGroup dropdown={dropdown}>{processedChildren}</CodeGroup>;
};

You can enable specific connections for each [organization](/docs/manage-users/organizations/organizations-overview) to provide users with different login options. After you enable a connection, it is added to the organization login prompt, and users can authenticate through that connection to access your applications.

To enable a connection for an organization, the connection **must** already exist in your tenant. Supported connections include [database connections](/docs/authenticate/database-connections), [social connections](/docs/authenticate/identity-providers/social-identity-providers), and [enterprise connections](/docs/authenticate/identity-providers/enterprise-identity-providers).

## Organization Properties

When using organizations, some connections have additional properties that you can configure:

<table>
  <thead>
    <tr>
      <th><strong>Property</strong></th>
      <th><strong>Connection Types</strong></th>
      <th><strong>Description</strong></th>
    </tr>
  </thead>

  <tbody>
    <tr>
      <td>Membership On Authentication</td>
      <td>All connection types</td>

      <td>
        When enabled, this property automatically assigns organization membership to end-users the first time they authenticate with the connection. <br /><br />
        Membership on Authentication is useful in scenarios where all users with the ability to authenticate with a specific connection can be assumed to be members of an organization.
      </td>
    </tr>

    <tr>
      <td>Organization Signup</td>
      <td>Database connections only</td>

      <td>
        This property determines whether or not end-users can access a signup link on the login prompt that allows them to gain membership to an Organization. To use Organization Signup, you must also enable Membership On Authentication.<br /><br />
        Organization Signup is useful is scenarios where users need self-service access to join Organizations, such as:

        <ul>
          <li>When Organizations are used to model open-membership user populations such as workspaces.</li>
          <li>In business-to-business-to-consumer (B2B2C) use cases where users can freely sign up for accounts.</li>
        </ul>
      </td>
    </tr>

    <tr>
      <td>Display connection as a button</td>
      <td>Enterprise connections only</td>

      <td>
        This optional property determines whether or not a specific connection displays as an option on the organization login prompt. <br /><br />
        <strong>Note</strong>: If this option is disabled for a connection, end-users can still authenticate via the connection and log in to applications in the context of the organization by sending the connection parameter directly in the authorization request. <br /><br />
        They can also authenticate with this connection if you are using the <a href="/docs/authenticate/login/auth0-universal-login/identifier-first">Identifier First with Home Realm Discovery</a> authentication profile in combination with the <a href="/docs/manage-users/organizations/login-flows-for-organizations#configure-the-login-flow-for-your-application">Prompt for Credentials</a> organization login flow. <br /><br />
        This only works if you do <b>not</b> provide an <code>org\_id</code> with the authorization request.
      </td>
    </tr>
  </tbody>
</table>

<Warning>
  End-users can only log in to applications in the context of a specific organization through connections that have been enabled for that organization.
</Warning>

## Configure Organization Connections

You can configure connections for organizations using either the <Tooltip tip="Auth0 Dashboard: Auth0's main product to configure your services." cta="View Glossary" href="/docs/glossary?term=Auth0+Dashboard">Auth0 Dashboard</Tooltip> or the <Tooltip tip="Management API: A product to allow customers to perform administrative tasks." cta="View Glossary" href="/docs/glossary?term=Management+API">Management API</Tooltip>.

<Tabs>
  <Tab title="Auth0 Dashboard">
    #### Auth0 Dashboard

    To enable a connection via the Auth0 Dashboard:

    1. Navigate to [Auth0 Dashboard > Organizations](https://manage.auth0.com/#/organizations), and select the organization for which you want to configure connections.
    2. Select the **Connections** view, then select **Enable Connections**.
    3. Choose the connection you want to enable, and select **Enable Connection**.
    4. In the Authentication section, locate **Membership On Authentication** and choose whether to enable or disable auto-membership. When enabled, auto-membership automatically adds all users logging in with the connection as members of the organization.
    5. **For Database connections only**: In the Organization Signup section, choose whether to enable or disable self-service signups. When enabled, users can access a signup link on the login prompt to create their account and automatically gain membership to the organization.

       * To enable this property, you must first enable **Membership on Authentication**.
       * **Note**: Organization Signup takes priority over the Database connection’s signup configuration. When Organization Signup is enabled, users can still sign up to an Organization or accept an Organization invite, even if signups are disabled at the Database connection level.
    6. **For Enterprise connections only**: In the Connection button section, optionally enable the **Display connection as a button** property to display the connection as an option on the organization login prompt.

           <Callout icon="file-lines" color="#0EA5E9" iconType="regular">
             If all enabled connections within the Organization are enterprise connections, and all connections are hidden, Auth0 returns an error that reads `Message: no connections enabled for the organization are visible` when users access the application.
           </Callout>
    7. Select **Save**.
  </Tab>

  <Tab title="Management API">
    #### Management API

    To enable a connection via the Management API:

    Make a `POST` call to the `Create Organization Connections` endpoint. Ensure you update the following placeholder values with the appropriate information:

    * Replace `{orgId}` with your organization ID.
    * Replace `{mgmtApiAccessToken}` with your Management API access token.
    * Replace `{connectionId}` with a specific connection ID.
    * Replace `{assignMembershipOption}` with `true` or `false` with respect to your Membership on Authentication selection.
    * **For Database connections only**: Replace `{isSignupEnabled}` with `true` or `false` with respect to your signup selection.
    * **For Enterprise connections only**: Replace `{showAsButtonOption}` with `true` or `false` with respect to your Connection Button selection.

    <AuthCodeGroup>
      ```bash cURL lines theme={null}
      curl --request POST \
        --url https://%7ByourAuth0Domain%7D/api/v2/organizations/%7BorgId%7D/enabled_connections \
        --header 'authorization: Bearer {yourMgmtApiAccessToken}' \
        --header 'cache-control: no-cache' \
        --header 'content-type: application/json' \
        --data '{ "connection_id": "{connectionId}", "assign_membership_on_login": "{assignMembershipOption}","is_signup_enabled","{isSignupEnabled}", "show_as_button": "{showAsButtonOption}" }'
      ```

      ```csharp C# lines theme={null}
      var client = new RestClient("https://%7ByourAuth0Domain%7D/api/v2/organizations/%7BorgId%7D/enabled_connections");
      var request = new RestRequest(Method.POST);
      request.AddHeader("content-type", "application/json");
      request.AddHeader("authorization", "Bearer {yourMgmtApiAccessToken}");
      request.AddHeader("cache-control", "no-cache");
      request.AddParameter("application/json", "{ \"connection_id\": \"{connectionId}\", \"assign_membership_on_login\": \"{assignMembershipOption}\",\"is_signup_enabled\",\"{isSignupEnabled}\", \"show_as_button\": \"{showAsButtonOption}\" }", ParameterType.RequestBody);
      IRestResponse response = client.Execute(request);
      ```

      ```go Go lines expandable theme={null}
      package main

      import (
      	"fmt"
      	"strings"
      	"net/http"
      	"io/ioutil"
      )

      func main() {

      	url := "https://%7ByourAuth0Domain%7D/api/v2/organizations/%7BorgId%7D/enabled_connections"

      	payload := strings.NewReader("{ \"connection_id\": \"{connectionId}\", \"assign_membership_on_login\": \"{assignMembershipOption}\",\"is_signup_enabled\",\"{isSignupEnabled}\", \"show_as_button\": \"{showAsButtonOption}\" }")

      	req, _ := http.NewRequest("POST", url, payload)

      	req.Header.Add("content-type", "application/json")
      	req.Header.Add("authorization", "Bearer {yourMgmtApiAccessToken}")
      	req.Header.Add("cache-control", "no-cache")

      	res, _ := http.DefaultClient.Do(req)

      	defer res.Body.Close()
      	body, _ := ioutil.ReadAll(res.Body)

      	fmt.Println(res)
      	fmt.Println(string(body))

      }
      ```

      ```java Java lines theme={null}
      HttpResponse<String> response = Unirest.post("https://%7ByourAuth0Domain%7D/api/v2/organizations/%7BorgId%7D/enabled_connections")
        .header("content-type", "application/json")
        .header("authorization", "Bearer {yourMgmtApiAccessToken}")
        .header("cache-control", "no-cache")
        .body("{ \"connection_id\": \"{connectionId}\", \"assign_membership_on_login\": \"{assignMembershipOption}\",\"is_signup_enabled\",\"{isSignupEnabled}\", \"show_as_button\": \"{showAsButtonOption}\" }")
        .asString();
      ```

      ```javascript Node.JS lines theme={null}
      var axios = require("axios").default;

      var options = {
        method: 'POST',
        url: 'https://%7ByourAuth0Domain%7D/api/v2/organizations/%7BorgId%7D/enabled_connections',
        headers: {
          'content-type': 'application/json',
          authorization: 'Bearer {yourMgmtApiAccessToken}',
          'cache-control': 'no-cache'
        },
        data: '{ "connection_id": "{connectionId}", "assign_membership_on_login": "{assignMembershipOption}","is_signup_enabled","{isSignupEnabled}", "show_as_button": "{showAsButtonOption}" }'
      };

      axios.request(options).then(function (response) {
        console.log(response.data);
      }).catch(function (error) {
        console.error(error);
      });
      ```

      ```objc Obj-C lines expandable theme={null}
      #import <Foundation/Foundation.h>

      NSDictionary *headers = @{ @"content-type": @"application/json",
                                 @"authorization": @"Bearer {yourMgmtApiAccessToken}",
                                 @"cache-control": @"no-cache" };

      NSData *postData = [[NSData alloc] initWithData:[@"{ "connection_id": "{connectionId}", "assign_membership_on_login": "{assignMembershipOption}","is_signup_enabled","{isSignupEnabled}", "show_as_button": "{showAsButtonOption}" }" dataUsingEncoding:NSUTF8StringEncoding]];

      NSMutableURLRequest *request = [NSMutableURLRequest requestWithURL:[NSURL URLWithString:@"https://%7ByourAuth0Domain%7D/api/v2/organizations/%7BorgId%7D/enabled_connections"]
                                                             cachePolicy:NSURLRequestUseProtocolCachePolicy
                                                         timeoutInterval:10.0];
      [request setHTTPMethod:@"POST"];
      [request setAllHTTPHeaderFields:headers];
      [request setHTTPBody:postData];

      NSURLSession *session = [NSURLSession sharedSession];
      NSURLSessionDataTask *dataTask = [session dataTaskWithRequest:request
                                                  completionHandler:^(NSData *data, NSURLResponse *response, NSError *error) {
                                                      if (error) {
                                                          NSLog(@"%@", error);
                                                      } else {
                                                          NSHTTPURLResponse *httpResponse = (NSHTTPURLResponse *) response;
                                                          NSLog(@"%@", httpResponse);
                                                      }
                                                  }];
      [dataTask resume];
      ```

      ```php PHP lines expandable theme={null}
      $curl = curl_init();

      curl_setopt_array($curl, [
        CURLOPT_URL => "https://%7ByourAuth0Domain%7D/api/v2/organizations/%7BorgId%7D/enabled_connections",
        CURLOPT_RETURNTRANSFER => true,
        CURLOPT_ENCODING => "",
        CURLOPT_MAXREDIRS => 10,
        CURLOPT_TIMEOUT => 30,
        CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
        CURLOPT_CUSTOMREQUEST => "POST",
        CURLOPT_POSTFIELDS => "{ \"connection_id\": \"{connectionId}\", \"assign_membership_on_login\": \"{assignMembershipOption}\",\"is_signup_enabled\",\"{isSignupEnabled}\", \"show_as_button\": \"{showAsButtonOption}\" }",
        CURLOPT_HTTPHEADER => [
          "authorization: Bearer {yourMgmtApiAccessToken}",
          "cache-control: no-cache",
          "content-type: application/json"
        ],
      ]);

      $response = curl_exec($curl);
      $err = curl_error($curl);

      curl_close($curl);

      if ($err) {
        echo "cURL Error #:" . $err;
      } else {
        echo $response;
      }
      ```

      ```python Python lines theme={null}
      import http.client

      conn = http.client.HTTPSConnection("")

      payload = "{ \"connection_id\": \"{connectionId}\", \"assign_membership_on_login\": \"{assignMembershipOption}\",\"is_signup_enabled\",\"{isSignupEnabled}\", \"show_as_button\": \"{showAsButtonOption}\" }"

      headers = {
          'content-type': "application/json",
          'authorization': "Bearer {yourMgmtApiAccessToken}",
          'cache-control': "no-cache"
          }

      conn.request("POST", "%7ByourAuth0Domain%7D/api/v2/organizations/%7BorgId%7D/enabled_connections", payload, headers)

      res = conn.getresponse()
      data = res.read()

      print(data.decode("utf-8"))
      ```

      ```ruby Ruby lines theme={null}
      require 'uri'
      require 'net/http'
      require 'openssl'

      url = URI("https://%7ByourAuth0Domain%7D/api/v2/organizations/%7BorgId%7D/enabled_connections")

      http = Net::HTTP.new(url.host, url.port)
      http.use_ssl = true
      http.verify_mode = OpenSSL::SSL::VERIFY_NONE

      request = Net::HTTP::Post.new(url)
      request["content-type"] = 'application/json'
      request["authorization"] = 'Bearer {yourMgmtApiAccessToken}'
      request["cache-control"] = 'no-cache'
      request.body = "{ \"connection_id\": \"{connectionId}\", \"assign_membership_on_login\": \"{assignMembershipOption}\",\"is_signup_enabled\",\"{isSignupEnabled}\", \"show_as_button\": \"{showAsButtonOption}\" }"

      response = http.request(request)
      puts response.read_body
      ```

      ```swift Swift lines expandable theme={null}
      import Foundation

      let headers = [
        "content-type": "application/json",
        "authorization": "Bearer {yourMgmtApiAccessToken}",
        "cache-control": "no-cache"
      ]

      let postData = NSData(data: "{ "connection_id": "{connectionId}", "assign_membership_on_login": "{assignMembershipOption}","is_signup_enabled","{isSignupEnabled}", "show_as_button": "{showAsButtonOption}" }".data(using: String.Encoding.utf8)!)

      let request = NSMutableURLRequest(url: NSURL(string: "https://%7ByourAuth0Domain%7D/api/v2/organizations/%7BorgId%7D/enabled_connections")! as URL,
                                              cachePolicy: .useProtocolCachePolicy,
                                          timeoutInterval: 10.0)
      request.httpMethod = "POST"
      request.allHTTPHeaderFields = headers
      request.httpBody = postData as Data

      let session = URLSession.shared
      let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in
        if (error != nil) {
          print(error)
        } else {
          let httpResponse = response as? HTTPURLResponse
          print(httpResponse)
        }
      })

      dataTask.resume()
      ```
    </AuthCodeGroup>

    <Callout icon="file-lines" color="#0EA5E9" iconType="regular">
      **Find Your Auth0 Domain**

      If your Auth0 domain is your tenant name, your regional subdomain (unless your tenant is in the US region and was created before June 2020), plus `.auth0.com`. For example, if your tenant name were `travel0`, your Auth0 domain name would be `travel0.us.auth0.com`. (If your tenant were in the US and created before June 2020, then your domain name would be `https://travel0.auth0.com`.)

      If you are using custom domains, this should be your custom domain name.
    </Callout>

    <table class="table">
      <thead>
        <tr>
          <th><strong>Value</strong></th>
          <th><strong>Description</strong></th>
        </tr>
      </thead>

      <tbody>
        <tr>
          <td>
            <code>
              {"{orgId}"}
            </code>
          </td>

          <td>ID of the organization for which you want to enable a connection.</td>
        </tr>

        <tr>
          <td>
            <code>
              {"{mgmtApiAccessToken}"}
            </code>
          </td>

          <td><a href="/docs/secure/tokens/access-tokens/management-api-access-tokens">Access Token for the Management API</a> with the scope <code>create:organization\_connections</code>.</td>
        </tr>

        <tr>
          <td>
            <code>
              {"{connectionId}"}
            </code>
          </td>

          <td>ID of the connection you want to enable for the specified organization.</td>
        </tr>

        <tr>
          <td>
            <code>
              {"{assignMembershipOption}"}
            </code>
          </td>

          <td>Indicates whether you want users that log in with this connection to automatically be granted membership in the organization. When set to <code>true</code>, users will automatically be granted membership. When set to <code>false</code>, they will not automatically be granted membership.</td>
        </tr>

        <tr>
          <td>
            <code>
              {"{isSignupEnabled}"}
            </code>
          </td>

          <td>
            Determines whether users can access a self-service signup link on the login prompt. When set to <code>true</code>, the signup link displays on the prompt. When set to <code>false</code>, the link remains hidden.<br /><br />
            <strong>Note</strong>: To enable this option, you must also set <code>{"{assignMembershipOption}"}</code> to <code>true</code>.
          </td>
        </tr>

        <tr>
          <td>
            <code>
              {"{showAsButtonOption}"}
            </code>
          </td>

          <td>Indicates whether you want a specific Enterprise connection to display as an option on the organization login prompt. When set to <code>true</code>, the connection displays as a button on the prompt. When set to <code>false</code>, the connection is hidden on the prompt.</td>
        </tr>
      </tbody>
    </table>

    ##### Response status codes

    Possible response status codes are as follows:

    | **Status code** | **Error code**       | **Message**                                                                                          | **Cause**                                                                          |
    | --------------- | -------------------- | ---------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------- |
    | `201`           |                      | Connection successfully added to organization.                                                       |                                                                                    |
    | `401`           |                      | Invalid token.                                                                                       |                                                                                    |
    | `401`           |                      | Invalid signature received for JSON Web Token validation.                                            |                                                                                    |
    | `401`           |                      | Client is not global.                                                                                |                                                                                    |
    | `403`           | `insufficient_scope` | Insufficient scope; expected any of: `create:organizations_connections`.                             | Tried to read/write a field that is not allowed with provided bearer token scopes. |
    | `429`           |                      | Too many requests. Check the X-RateLimit-Limit, X-RateLimit-Remaining and X-RateLimit-Reset headers. |                                                                                    |
  </Tab>
</Tabs>
