---
title: "For Developers"
manual: "Auth0 for TYPO3"
version: "main"
permalink: "https://docs.typo3.org/permalink/leuchtfeuer/auth0:developer@main"
source: "Developer/Index.rst"
rendered: "2026-09-25T07:01:43+00:00"
---

# For Developers {#developer}

Support for frontend users has been removed from version 13.

## API Notes {#developer-api}

This section documents public APIs that extension developers may use or override.

### ApplicationFactory {#developer-api-applicationfactory}

`ApplicationFactory::build(int $applicationId, string $context, ?ServerRequestInterface $request = null): Auth0`

Pass the current PSR-7 request as the third argument whenever one is available. The factory uses
the request to derive the OAuth redirect URI via `NormalizedParams`. If no request is passed (e.g.
in CLI commands or early-boot contexts), `$_SERVER` is used as a last resort — the redirect URI
is constructed but never used in an actual OAuth flow in those contexts.

The returned `Auth0` instance is wired with `Auth0SDKStoreCookieStore` for both
session and transient storage. `cookieSecret` defaults to TYPO3's encryption key, `cookieSecure`
follows `$GLOBALS['TYPO3_CONF_VARS']['BE']['lockSSL']`, and `cookieSameSite` is `Lax`.
Subclasses overriding `build()` to provide a custom `Auth0SDKContractStoreInterface` must
not call `session_start()` directly or indirectly — doing so re-introduces the conflict with
the TYPO3 Install Tool's `FileSessionHandler` (see [Session Storage](https://docs.typo3.org/permalink/leuchtfeuer/auth0:admin-sessionstorage@main)).

### TokenUtility {#developer-api-tokenutility}

`TokenUtility::buildToken(string $issuer): UnencryptedToken`

Builds a signed JWT for the OAuth state callback. The issuer (request host) must be passed
explicitly. Derive it from the request: `$request->getAttribute('normalizedParams')->getRequestHost()`.

`TokenUtility::verifyToken(string $token, string $issuer): bool`

Verifies a callback token. Pass the same issuer that was used when the token was built.

> [!NOTE]
> The former `getIssuer()` / `setIssuer()` methods have been removed in version 14.0.0.
> The issuer is no longer stored as object state; pass it at call time instead.

### ModeUtility {#developer-api-modeutility}

`ModeUtility::getModeFromRequest(ServerRequestInterface $request): string`

Returns `ModeUtility::BACKEND_MODE` when the request is a backend request, otherwise
`ModeUtility::UNKNOWN_MODE`. The method no longer reads from `$GLOBALS['TYPO3_REQUEST']`;
pass the request explicitly.

`ModeUtility::isBackend(?string $mode = null, ?ServerRequestInterface $request = null): bool`

When `$mode` is `null` and a `$request` is provided, the mode is derived from the request.
When neither is provided, the method returns `false` (unknown mode is not backend).

> [!NOTE]
> The constant `UNKONWN_MODE` (typo) was renamed to `UNKNOWN_MODE` in version 14.0.0.

### UserRepository {#developer-api-userrepository}

`UserRepository::insertUser(array $values): int`

Inserts a user record into the database. Starting with version 14.0.0, this method returns the
`uid` of the newly created record. Custom implementations overriding this method must update
their return type to `int`.
