---
title: "Extension Configuration"
manual: "Auth0 for TYPO3"
version: "main"
permalink: "https://docs.typo3.org/permalink/leuchtfeuer/auth0:admin-extensionconfiguration@main"
source: "Admin/ExtensionConfiguration/Index.rst"
rendered: "2026-09-25T07:01:43+00:00"
---

# Extension Configuration {#admin-extensionconfiguration}

All configuration is made in the "Extension Configuration" section of the "Settings" module beneath the "Admin Tools".

![Extension Configuration](../../Images/extension-configuration.png)

## Properties {#admin-extensionconfiguration-properties}

| Property | Tab | Type |
| --- | --- | --- |
| [enableBackendLogin](https://docs.typo3.org/permalink/leuchtfeuer/auth0:enablebackendlogin@main) | Backend | boolean |
| [backendConnection](https://docs.typo3.org/permalink/leuchtfeuer/auth0:backendconnection@main) | Backend | positive integer |
| [reactivateDisabledBackendUsers](https://docs.typo3.org/permalink/leuchtfeuer/auth0:reactivatedisabledbackendusers@main) | Backend | boolean |
| [reactivateDeletedBackendUsers](https://docs.typo3.org/permalink/leuchtfeuer/auth0:reactivatedeletedbackendusers@main) | Backend | boolean |
| [softLogout](https://docs.typo3.org/permalink/leuchtfeuer/auth0:softlogout@main) | Backend | boolean |
| [additionalAuthorizeParameters](https://docs.typo3.org/permalink/leuchtfeuer/auth0:additionalauthorizeparameters@main) | Backend | string |
| [disableSudoModeBypass](https://docs.typo3.org/permalink/leuchtfeuer/auth0:disablesudomodebypass@main) | Backend | boolean |
| [mergeUsersByEmailAndUsername](https://docs.typo3.org/permalink/leuchtfeuer/auth0:mergeusersbyemailandusername@main) | Backend | boolean |
| genericCallback | Token | boolean |
| [privateKeyFile](https://docs.typo3.org/permalink/leuchtfeuer/auth0:privatekeyfile@main) | Token | string |
| [publicKeyFile](https://docs.typo3.org/permalink/leuchtfeuer/auth0:publickeyfile@main) | Token | string |
| [userIdentifier](https://docs.typo3.org/permalink/leuchtfeuer/auth0:useridentifier@main) | Token | string |

### enableBackendLogin {#admin-extensionconfiguration-properties-secureddirs}

-   **Property**

    enableBackendLogin

-   **Data type**

    boolean

-   **Default**

    `false`

-   **Description**

    Enable Auth0 login for TYPO3 backend.

### backendConnection {#admin-extensionconfiguration-properties-backendconnection}

-   **Property**

    backendConnection

-   **Data type**

    positive integer

-   **Default**

    `1`

-   **Description**

    Application identifier for backend login.

### reactivateDisabledBackendUsers {#admin-extensionconfiguration-properties-reactivatedisabledbackendusers}

-   **Property**

    reactivateDisabledBackendUsers

-   **Data type**

    boolean

-   **Default**

    `false`

-   **Description**

    Allow log in for disabled backend users.

### reactivateDeletedBackendUsers {#admin-extensionconfiguration-properties-reactivatedeletedbackendusers}

-   **Property**

    reactivateDeletedBackendUsers

-   **Data type**

    boolean

-   **Default**

    `false`

-   **Description**

    Allow log in for deleted backend users.

### softLogout {#admin-extensionconfiguration-properties-softlogout}

-   **Property**

    softLogout

-   **Data type**

    boolean

-   **Default**

    `false`

-   **Description**

    Log off from TYPO3 only (not from Auth0).

### additionalAuthorizeParameters {#admin-extensionconfiguration-properties-additionalauthorizeparameters}

-   **Property**

    additionalAuthorizeParameters

-   **Data type**

    string

-   **Default**

    unset

-   **Description**

    Additional query parameters for backend authentication (e.g. `access_type=offline&connection=google-oauth2`).

### disableSudoModeBypass {#admin-extensionconfiguration-properties-disablesudomodebypass}

-   **Property**

    disableSudoModeBypass

-   **Data type**

    boolean

-   **Default**

    `false`

-   **Description**

    Controls whether Auth0-authenticated users with a valid session can bypass TYPO3's sudo mode password
    confirmation dialog when accessing Admin Tools modules.

    When disabled (default), Auth0 users with a valid session will not be prompted for password confirmation
    when accessing protected Admin Tools modules, providing a smoother user experience for externally
    authenticated users.

    When enabled, the standard TYPO3 sudo mode behavior is enforced, requiring password confirmation
    regardless of Auth0 session status.

    > [!NOTE]
    > This setting only applies to TYPO3 13.4.13 and higher (including TYPO3 14), where sudo mode bypassing is available.

### mergeUsersByEmailAndUsername {#admin-extensionconfiguration-properties-mergeusersbyemailandusername}

-   **Property**

    mergeUsersByEmailAndUsername

-   **Data type**

    boolean

-   **Default**

    `false`

-   **Description**

    When enabled and no backend user with a matching `auth0_user_id` is found, the extension
    attempts to locate an existing user by email address and username. If a match is found,
    the stored `auth0_user_id` is updated to the new value so subsequent logins use the
    standard lookup path.

    This is useful when a user switches their **login method within Auth0** — for example from
    a Google social connection to an email/password account. Even within the same Auth0 tenant,
    each connection type produces a different `sub` claim (e.g. `google-oauth2|…` vs.
    `auth0|…`). Without this option, TYPO3 would create a second backend user record,
    severing the original user's edit history and permissions.

    The username is resolved via the YAML property mapping (`databaseField: username`).
    If no such mapping is configured, Auth0's `nickname` claim is used as a fallback.

    > [!NOTE]
    > Disable this option again once all affected users have logged in at least once, to
    > avoid unintended account merges. The option has no effect if either the email or the
    > username cannot be determined from the Auth0 token.

### privateKeyFile {#admin-extensionconfiguration-properties-privatekeyfile}

-   **Property**

    privateKeyFile

-   **Data type**

    string

-   **Default**

    unset

-   **Description**

    The absolute path to your private key file on your server. If set, this key will be used for signing the generated
    tokens. Otherwise, TYPO3's encryption key will be used. Only RSA keys are supported for now.

### publicKeyFile {#admin-extensionconfiguration-properties-publickeyfile}

-   **Property**

    publicKeyFile

-   **Data type**

    string

-   **Default**

    unset

-   **Description**

    The absolute path to your public key file on your server.

### userIdentifier {#admin-extensionconfiguration-properties-useridentifier}

-   **Property**

    userIdentifier

-   **Data type**

    string

-   **Default**

    `sub`

-   **Description**

    The property of the ID token containing the unique user ID.
