PageSourceSearch

https://www.rabbitmq.com/assets/js/d1bb5b4e.547c9f6f.js

js rabbitmq.com collected 2026-09-24 06:05:30 UTC 13,418 bytes, 1 lines download raw bytes

1"use strict";(self.webpackChunkrabbitmq_website=self.webpackChunkrabbitmq_website||[]).push([["15235"],{76475(e,i,n){n.r(i),n.d(i,{metadata:()=>t,default:()=>d,frontMatter:()=>r,contentTitle:()=>l,toc:()=>c,assets:()=>o});var t=JSON.parse('{"id":"oauth2-examples-auth0","title":"Use auth0.com as OAuth 2.0 Server","description":"\x3c!--","source":"@site/versioned_docs/version-4.2/oauth2-examples-auth0.md","sourceDirName":".","slug":"/oauth2-examples-auth0","permalink":"/docs/4.2/oauth2-examples-auth0","draft":false,"unlisted":false,"editUrl":"https://github.com/rabbitmq/rabbitmq-website/tree/main/versioned_docs/version-4.2/oauth2-examples-auth0.md","tags":[],"version":"4.2","frontMatter":{"title":"Use auth0.com as OAuth 2.0 Server","displayed_sidebar":"docsSidebar"},"sidebar":"docsSidebar","previous":{"title":"OAuth 2.0 Authentication Examples","permalink":"/docs/4.2/oauth2-examples/"},"next":{"title":"Microsoft Entra ID","permalink":"/docs/4.2/oauth2-examples-entra-id/"}}'),s=n(74848),a=n(28453);let r={title:"Use auth0.com as OAuth 2.0 Server",displayed_sidebar:"docsSidebar"},l="Use auth0.com as OAuth 2.0 server",o={},c=[{value:"Prerequisites to follow this guide",id:"prerequisites-to-follow-this-guide",level:2},{value:"Create RabbitMQ API",id:"create-rabbitmq-api",level:2},{value:"Configure permissions in RabbitMQ API",id:"configure-permissions-in-rabbitmq-api",level:3},{value:"Create an OAuth client for the Management UI",id:"create-an-oauth-client-for-the-management-ui",level:3},{value:"Create Application rabbitmq-management",id:"create-application-rabbitmq-management",level:2},{value:"Create a User for Management UI Access",id:"create-a-user-for-management-ui-access",level:2},{value:"Create user",id:"create-user",level:3},{value:"Create permissions and grant them",id:"create-permissions-and-grant-them",level:3},{value:"Configure RabbitMQ to authenticate with Auth0",id:"configure-rabbitmq-to-authenticate-with-auth0",level:2},{value:"Start RabbitMQ",id:"start-rabbitmq",level:2},{value:"Verify Management UI flows",id:"verify-management-ui-flows",level:2}];function h(e){let i={a:"a",admonition:"admonition",code:"code",em:"em",h1:"h1",h2:"h2",h3:"h3",header:"header",li:"li",ol:"ol",p:"p",pre:"pre",strong:"strong",ul:"ul",...(0,a.R)(),...e.components};return(0,s.jsxs)(s.Fragment,{children:[(0,s.jsx)(i.header,{children:(0,s.jsxs)(i.h1,{id:"use-auth0com-as-oauth-20-server",children:["Use ",(0,s.jsx)(i.a,{href:"https://auth0.com",children:"auth0.com"})," as OAuth 2.0 server"]})}),"\n",(0,s.jsx)(i.p,{children:"This guide explains how to set up OAuth 2.0 for RabbitMQ\nand Auth0 as Authorization Server using the following flows:"}),"\n",(0,s.jsxs)(i.ul,{children:["\n",(0,s.jsxs)(i.li,{children:["Access ",(0,s.jsx)(i.a,{href:"./management/",children:"management UI"})," via a browser"]}),"\n",(0,s.jsx)(i.li,{children:"Access management HTTP API"}),"\n",(0,s.jsx)(i.li,{children:"Application authentication and authorization"}),"\n"]}),"\n",(0,s.jsx)(i.h2,{id:"prerequisites-to-follow-this-guide",children:"Prerequisites to follow this guide"}),"\n",(0,s.jsxs)(i.ul,{children:["\n",(0,s.jsxs)(i.li,{children:["Have an ",(0,s.jsx)(i.a,{href:"https://auth0.com/",children:"Auth0"})," account"]}),"\n",(0,s.jsx)(i.li,{children:"Docker"}),"\n",(0,s.jsxs)(i.li,{children:["A local clone of a ",(0,s.jsx)(i.a,{href:"https://github.com/rabbitmq/rabbitmq-oauth2-tutorial/tree/next",children:"GitHub repository"})," for branch ",(0,s.jsx)(i.code,{children:"next"})," that contains all the configuration files and scripts used on this example."]}),"\n"]}),"\n",(0,s.jsx)(i.h2,{id:"create-rabbitmq-api",children:"Create RabbitMQ API"}),"\n",(0,s.jsx)(i.p,{children:"In Auth0, resources are mapped to Application APIs."}),"\n",(0,s.jsxs)(i.ol,{children:["\n",(0,s.jsxs)(i.li,{children:["After logging into the Auth0 account, go to ",(0,s.jsx)(i.strong,{children:"dashboard > Applications > APIs > Create an API"}),"."]}),"\n",(0,s.jsxs)(i.li,{children:["Give it the name ",(0,s.jsx)(i.code,{children:"rabbitmq"}),". The important thing here is the ",(0,s.jsx)(i.code,{children:"identifier"})," which must have the name of the ",(0,s.jsx)(i.em,{children:"resource_server_id"}
1)," we configured in RabbitMQ. This ",(0,s.jsx)(i.code,{children:"identifier"})," goes into the ",(0,s.jsx)(i.code,{children:"audience"})," JWT field. In our case, it is called ",(0,s.jsx)(i.code,{children:"rabbitmq"}),"."]}),"\n",(0,s.jsxs)(i.li,{children:["Choose ",(0,s.jsx)(i.code,{children:"RS256"})," as the signing algorithm."]}),"\n",(0,s.jsxs)(i.li,{children:["Enable ",(0,s.jsx)(i.strong,{children:"RBAC"}),"."]}),"\n",(0,s.jsxs)(i.li,{children:["Enable ",(0,s.jsx)(i.strong,{children:"Add Permissions in the Access Token"}),"."]}),"\n"]}),"\n",(0,s.jsx)(i.h3,{id:"configure-permissions-in-rabbitmq-api",children:"Configure permissions in RabbitMQ API"}),"\n",(0,s.jsxs)(i.ol,{children:["\n",(0,s.jsxs)(i.li,{children:["\n",(0,s.jsxs)(i.p,{children:["Edit the API we just created with the name ",(0,s.jsx)(i.code,{children:"rabbitmq"}),"."]}),"\n"]}),"\n",(0,s.jsxs)(i.li,{children:["\n",(0,s.jsx)(i.p,{children:"Go into Permissions and add the permissions (scope) this api can grant. You are going to add the following scopes:"}),"\n",(0,s.jsxs)(i.ul,{children:["\n",(0,s.jsx)(i.li,{children:(0,s.jsx)(i.code,{children:"rabbitmq.read:*/*"})}),"\n",(0,s.jsx)(i.li,{children:(0,s.jsx)(i.code,{children:"rabbitmq.write:*/*"})}),"\n",(0,s.jsx)(i.li,{children:(0,s.jsx)(i.code,{children:"rabbitmq.configure:*/*"})}),"\n",(0,s.jsx)(i.li,{children:(0,s.jsx)(i.code,{children:"rabbitmq.tag:administrator"})}),"\n"]}),"\n"]}),"\n"]}),"\n",(0,s.jsx)(i.h3,{id:"create-an-oauth-client-for-the-management-ui",children:"Create an OAuth client for the Management UI"}),"\n",(0,s.jsxs)(i.p,{children:["By default, for every API we create, an ",(0,s.jsx)(i.em,{children:"Application"})," gets created using the API's ",(0,s.jsx)(i.code,{children:"identifier"})," as its name.\nAn ",(0,s.jsx)(i.em,{children:"Application"})," requests an ",(0,s.jsx)(i.strong,{children:"OAuth client"}),"."]}),"\n",(0,s.jsxs)(i.p,{children:["Go to ",(0,s.jsx)(i.strong,{children:"dashboard > Applications"}),", and you should see your application listed. An application gives us a ",(0,s.jsx)(i.em,{children:"client_id"}),", a ",(0,s.jsx)(i.em,{children:"client_secret"})," and a http endpoint called ",(0,s.jsx)(i.em,{children:"Domain"})," where to claim a token."]}),"\n",(0,s.jsx)(i.h2,{id:"create-application-rabbitmq-management",children:"Create Application rabbitmq-management"}),"\n",(0,s.jsx)(i.p,{children:"An application gives us the client-id and client-secret for the management UI to authenticate on behalf\nof the end user."}),"\n",(0,s.jsx)(i.p,{children:"In the settings, choose:"}),"\n",(0,s.jsxs)(i.ul,{children:["\n",(0,s.jsxs)(i.li,{children:["Application type : ",(0,s.jsx)(i.code,{children:"Single Page applications"})]}),"\n",(0,s.jsxs)(i.li,{children:["Allowed Callback URLs: ",(0,s.jsx)(i.code,{children:"https://localhost:15671/js/oidc-oauth/login-callback.html"})]}),"\n",(0,s.jsxs)(i.li,{children:["Allowed Web Origins: ",(0,s.jsx)(i.code,{children:"https://localhost:15671"})]}),"\n",(0,s.jsxs)(i.li,{children:["Allowed Origins (CORS): ",(0,s.jsx)(i.code,{children:"https://localhost:15671"})]}),"\n"]}),"\n",(0,s.jsx)(i.h2,{id:"create-a-user-for-management-ui-access",children:"Create a User for Management UI Access"}),"\n",(0,s.jsx)(i.h3,{id:"create-user",children:"Create user"}),"\n",(0,s.jsxs)(i.ol,{children:["\n",(0,s.jsxs)(i.li,{children:["Go to ",(0,s.jsx)(i.strong,{children:"User Management"})," > ",(0,s.jsx)(i.strong,{children:"Users"}),"."]}),"\n",(0,s.jsx)(i.li,{children:"Create a user. This is the user you will use to login via the management UI."}),"\n"]}),"\n",(0,s.jsx)(i.h3,{id:"create-permissions-and-grant-them",children:"Create permissions and grant them"}),"\n",(0,s.jsxs)(i.ol,{children:["\n",(0,s.jsxs)(i.li,{children:["Go to ",(0,s.jsx)(i.strong,{children:"Roles"}),"."]}),"\n",(0,s.jsxs)(i.li,{children:["Create the role called ",(0,s.jsx)(i.code,{children:"rabbitmq.tag:administrator"}),"."]}),"\n",(0,s.jsxs)(i.li,{children:["Go to ",(0,s.jsx)(i.strong,{children:"Permissions"})," and select all the permissions."]}),"\n",(0,s.jsxs)(i.li,{children:["Go to ",(0,s.jsx)(i.strong,{children:"Users"})," and make sure our user is listed else add our user to the\nlist of users which have this role."]}),"\n"]}),"\n",(0,s.jsx)(i.h2,{id:"configure-rabbitmq-to-authenticate-with-auth0",children:"Configure RabbitMQ to authenticate with Auth0"}),"\n",(0,s.jsx)(i.p,{children:"To configure RabbitMQ you need to gather the following information from Auth0:"}),"\n",(0,s.jsxs)(i.ol,{children:["\n",(0,s.jsxs)(i.li,{children:["Go to ",(0,s.jsx)(i.strong,{children:"dashboard > Applications > Applications"}),"."]}),"\n",(0,s.jsxs)(i.li,{children:["Click on the application ",(0,s.jsx)(i.co
1de,{children:"rabbitmq-management"}),"."]}),"\n",(0,s.jsxs)(i.li,{children:["Take note of the ",(0,s.jsx)(i.em,{children:"Client ID"})," value"]}),"\n",(0,s.jsxs)(i.li,{children:["And take note of the ",(0,s.jsx)(i.em,{children:"Domain"})," value"]}),"\n",(0,s.jsxs)(i.li,{children:["Use the last values in ",(0,s.jsx)(i.em,{children:"Client ID"})," and ",(0,s.jsx)(i.em,{children:"Domain"})," fields in the RabbitMQ configuration file"]}),"\n"]}),"\n",(0,s.jsxs)(i.p,{children:["Clone the configuration file ",(0,s.jsx)(i.a,{href:"https://github.com/rabbitmq/rabbitmq-oauth2-tutorial/blob/main/conf/auth0/rabbitmq.conf.tmpl",children:"conf/auth0/rabbitmq.conf.tmpl"})," as ",(0,s.jsx)(i.code,{children:"rabbitmq.conf"})," (in the same folder as ",(0,s.jsx)(i.code,{children:"rabbitmq.conf.tmpl"}),")."]}),"\n",(0,s.jsxs)(i.p,{children:["Edit ",(0,s.jsx)(i.code,{children:"rabbitmq.conf"})," and proceed as follows:"]}),"\n",(0,s.jsxs)(i.ol,{children:["\n",(0,s.jsxs)(i.li,{children:["Replace ",(0,s.jsx)(i.code,{children:"{Client ID}"})," with the values you gathered above."]}),"\n",(0,s.jsxs)(i.li,{children:["Same for ",(0,s.jsx)(i.code,{children:"{Domain}"})]}),"\n"]}),"\n",(0,s.jsxs)(i.admonition,{type:"important",children:[(0,s.jsxs)(i.p,{children:["Starting with RabbitMQ 4.1.x, you must configure RabbitMQ to include a URI parameter\ncalled ",(0,s.jsx)(i.code,{children:"audience"})," whose value matches the value of ",(0,s.jsx)(i.code,{children:"auth_oauth2.resource_server_id"}),"."]}),(0,s.jsx)(i.p,{children:'Earlier RabbitMQ versions always sent this URI parameter. If this additional URI parameter is not configured,\nAuth0 will consider the token invalid and RabbitMQ will display "No authorized" for error.'}),(0,s.jsxs)(i.p,{children:["These ",(0,s.jsx)(i.a,{href:"https://github.com/rabbitmq/rabbitmq-oauth2-tutorial/blob/next/conf/auth0/rabbitmq.conf.tmpl#L8-L9",children:"two configuration lines"}),"\nconfigure the ",(0,s.jsx)(i.code,{children:"audience"})," parameter with the value ",(0,s.jsx)(i.code,{children:"rabbitmq"}),"."]})]}),"\n",(0,s.jsx)(i.h2,{id:"start-rabbitmq",children:"Start RabbitMQ"}),"\n",(0,s.jsx)(i.p,{children:"Run the following commands to start RabbitMQ:"}),"\n",(0,s.jsx)(i.pre,{children:(0,s.jsx)(i.code,{className:"language-bash",children:"export MODE=auth0\nmake start-rabbitmq\n"})}),"\n",(0,s.jsx)(i.h2,{id:"verify-management-ui-flows",children:"Verify Management UI flows"}),"\n",(0,s.jsxs)(i.ol,{children:["\n",(0,s.jsxs)(i.li,{children:["Go to management UI ",(0,s.jsx)(i.code,{children:"https://localhost:15671"}),"."]}),"\n",(0,s.jsx)(i.li,{children:"Click on the single button, authenticate with your secondary Auth0 user. You should be redirected back to the management UI."}),"\n"]}),"\n",(0,s.jsxs)(i.p,{children:[(0,s.jsx)(i.strong,{children:"Auth0"})," issues an access token like this one below. It has in the ",(0,s.jsx)(i.code,{children:"scope"})," claim\nthe requested scopes configured in ",(0,s.jsx)(i.code,{children:"management.oauth_scopes"}),", and in the ",(0,s.jsx)(i.code,{children:"permissions"})," claim all the scopes you configured for this user in Auth0. RabbitMQ read the scopes from the ",(0,s.jsx)(i.code,{children:"scope"})," claim but also from the claim name configured in ",(0,s.jsx)(i.code,{children:"auth_oauth2.additional_scopes_key"})," whose value is ",(0,s.jsx)(i.code,{children:"permissions"}),"."]}),"\n",(0,s.jsx)(i.pre,{children:(0,s.jsx)(i.code,{className:"language-javascript",children:'{\n  "iss": "https://dev-tm5ebsbbdcbqddcj.us.auth0.com/",\n  "sub": "auth0|66d980b862efcd9f5144f42a",\n  "aud": [\n    "rabbitmq",\n    "https://dev-tm5ebsbbdcbqddcj.us.auth0.com/userinfo"\n  ],\n  "iat": 1725533554,\n  "exp": 1725619954,\n  "scope": "openid profile rabbitmq.tag:administrator",\n  "azp": "IC1fqsSjkQq2cVsYyHUuQyq30OAYuUv2",\n  "permissions": [\n    "rabbitmq.configure:*/*",\n    "rabbitmq.read:*/*",\n    "rabbitmq.tag:administrator",\n    "rabbitmq.write:*/*"\n  ]\n}\n'})})]})}function d(e={}){let{wrapper:i}={...(0,a.R)(),...e.components};return i?(0,s.jsx)(i,{...e,children:(0,s.jsx)(h,{...e})}):h(e)}},28453(e,i,n){n.d(i,{R:()=>r,x:()=>l});var t=n(96540);let s={},a=t.createContext(s);function r(e){let i=t.useContext(a);return t.useMemo(function(){return"function"==typeof e?e(i):{...i,...e}},[i,e])}function l(e){let i;return i=e.disableParentContext?"function"==typeof e.components?e.components(s):e.components||s:r(e.components),t.createElement(a.Provider,{value:i},e.children)}}}]);

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.