# auth0 Dialect

See which types this Dialect interprets and which architectural facts its Rules can establish.

<!-- Generated by scripts/generate-provider-coverage.ts from official Dialect sources. -->

<details>
<summary>Version and compatibility</summary>

**Version:** `0.1.0`.

**Provider bindings and declared compatibility**

- `auth0/auth0`: `= 1.56.0`.

[All official Dialects](https://docs.rootform.dev/reference/provider-coverage/)

</details>

## Interpreted types

Each row identifies a type and instance kind. Conditional Rules retain their individual conditions in the details below.

| Terraform type | Kind | Classification | Rules |
| --- | --- | --- | --- |
| `auth0_action_module` | `data` | [`extension-configuration`](#auth0-concept-extension-configuration) | [`action-module-lookup`](#rule-action-module-lookup) |
| `auth0_action_module` | `resource` | [`extension-configuration`](#auth0-concept-extension-configuration) | [`action-module`](#rule-action-module) |
| `auth0_action` | `data` | [`identity-extension`](#auth0-concept-identity-extension) | [`action-lookup`](#rule-action-lookup) |
| `auth0_action` | `resource` | [`identity-extension`](#auth0-concept-identity-extension) | [`action`](#rule-action) |
| `auth0_attack_protection` | `data` | [`authentication-configuration`](#auth0-concept-authentication-configuration) | [`attack-protection-lookup`](#rule-attack-protection-lookup) |
| `auth0_attack_protection` | `resource` | [`authentication-configuration`](#auth0-concept-authentication-configuration) | [`attack-protection`](#rule-attack-protection) |
| `auth0_client_cimd` | `resource` | [`identity-application`](#auth0-concept-identity-application) | [`client-cimd`](#rule-client-cimd) |
| `auth0_client_credentials` | `resource` | [`application-configuration`](#auth0-concept-application-configuration) | [`client-credentials`](#rule-client-credentials) |
| `auth0_client_grant` | `resource` | [`application-configuration`](#auth0-concept-application-configuration) | [`client-grant`](#rule-client-grant) |
| `auth0_client` | `data` | [`identity-application`](#auth0-concept-identity-application) | [`client-lookup`](#rule-client-lookup) |
| `auth0_client` | `resource` | [`identity-application`](#auth0-concept-identity-application) | [`client`](#rule-client) |
| `auth0_connection_client` | `resource` | [`connection-configuration`](#auth0-concept-connection-configuration) | [`connection-client`](#rule-connection-client) |
| `auth0_connection_clients` | `resource` | [`connection-configuration`](#auth0-concept-connection-configuration) | [`connection-clients`](#rule-connection-clients) |
| `auth0_connection_directory_synchronized_groups` | `data` | [`connection-configuration`](#auth0-concept-connection-configuration) | [`connection-directory-synchronized-groups-lookup`](#rule-connection-directory-synchronized-groups-lookup) |
| `auth0_connection_directory_synchronized_groups` | `resource` | [`connection-configuration`](#auth0-concept-connection-configuration) | [`connection-directory-synchronized-groups`](#rule-connection-directory-synchronized-groups) |
| `auth0_connection_directory` | `data` | [`directory-sync`](#auth0-concept-directory-sync) | [`connection-directory-lookup`](#rule-connection-directory-lookup) |
| `auth0_connection_directory` | `resource` | [`directory-sync`](#auth0-concept-directory-sync) | [`connection-directory`](#rule-connection-directory) |
| `auth0_connection_keys` | `data` | [`connection-configuration`](#auth0-concept-connection-configuration) | [`connection-keys-lookup`](#rule-connection-keys-lookup) |
| `auth0_connection_keys` | `resource` | [`connection-configuration`](#auth0-concept-connection-configuration) | [`connection-keys`](#rule-connection-keys) |
| `auth0_connection_profile` | `data` | [`self-service-configuration`](#auth0-concept-self-service-configuration) | [`connection-profile-lookup`](#rule-connection-profile-lookup) |
| `auth0_connection_profile` | `resource` | [`self-service-configuration`](#auth0-concept-self-service-configuration) | [`connection-profile`](#rule-connection-profile) |
| `auth0_connection_scim_configuration` | `data` | [`connection-configuration`](#auth0-concept-connection-configuration) | [`connection-scim-configuration-lookup`](#rule-connection-scim-configuration-lookup) |
| `auth0_connection_scim_configuration` | `resource` | [`connection-configuration`](#auth0-concept-connection-configuration) | [`connection-scim-configuration`](#rule-connection-scim-configuration) |
| `auth0_connection` | `data` | [`identity-connection`](#auth0-concept-identity-connection) | [`connection-lookup`](#rule-connection-lookup) |
| `auth0_connection` | `resource` | [`identity-connection`](#auth0-concept-identity-connection) | [`connection`](#rule-connection) |
| `auth0_custom_domain_default` | `resource` | [`domain-configuration`](#auth0-concept-domain-configuration) | [`custom-domain-default`](#rule-custom-domain-default) |
| `auth0_custom_domain_verification` | `resource` | [`domain-configuration`](#auth0-concept-domain-configuration) | [`custom-domain-verification`](#rule-custom-domain-verification) |
| `auth0_custom_domain` | `data` | [`identity-domain`](#auth0-concept-identity-domain) | [`custom-domain-lookup`](#rule-custom-domain-lookup) |
| `auth0_custom_domain` | `resource` | [`identity-domain`](#auth0-concept-identity-domain) | [`custom-domain`](#rule-custom-domain) |
| `auth0_email_provider` | `resource` | [`notification-provider`](#auth0-concept-notification-provider) | [`email-provider`](#rule-email-provider) |
| `auth0_encryption_key_manager` | `resource` | [`authentication-configuration`](#auth0-concept-authentication-configuration) | [`encryption-key-manager`](#rule-encryption-key-manager) |
| `auth0_event_stream` | `data` | [`identity-event-stream`](#auth0-concept-identity-event-stream) | [`event-stream-lookup`](#rule-event-stream-lookup) |
| `auth0_event_stream` | `resource` | [`identity-event-stream`](#auth0-concept-identity-event-stream) | [`event-stream`](#rule-event-stream) |
| `auth0_flow_vault_connection` | `data` | [`flow-vault-connection`](#auth0-concept-flow-vault-connection) | [`flow-vault-connection-lookup`](#rule-flow-vault-connection-lookup) |
| `auth0_flow_vault_connection` | `resource` | [`flow-vault-connection`](#auth0-concept-flow-vault-connection) | [`flow-vault-connection`](#rule-flow-vault-connection) |
| `auth0_flow` | `data` | [`identity-workflow`](#auth0-concept-identity-workflow) | [`flow-lookup`](#rule-flow-lookup) |
| `auth0_flow` | `resource` | [`identity-workflow`](#auth0-concept-identity-workflow) | [`flow`](#rule-flow) |
| `auth0_form` | `data` | [`identity-workflow`](#auth0-concept-identity-workflow) | [`form-lookup`](#rule-form-lookup) |
| `auth0_form` | `resource` | [`identity-workflow`](#auth0-concept-identity-workflow) | [`form`](#rule-form) |
| `auth0_guardian` | `resource` | [`authentication-configuration`](#auth0-concept-authentication-configuration) | [`guardian`](#rule-guardian) |
| `auth0_hook` | `resource` | [`identity-extension`](#auth0-concept-identity-extension) | [`hook`](#rule-hook) |
| `auth0_network_acl` | `data` | [`authentication-boundary`](#auth0-concept-authentication-boundary) | [`network-acl-lookup`](#rule-network-acl-lookup) |
| `auth0_network_acl` | `resource` | [`authentication-boundary`](#auth0-concept-authentication-boundary) | [`network-acl`](#rule-network-acl) |
| `auth0_organization_client_grant` | `resource` | [`connection-configuration`](#auth0-concept-connection-configuration) | [`organization-client-grant`](#rule-organization-client-grant) |
| `auth0_organization_client` | `data` | [`connection-configuration`](#auth0-concept-connection-configuration) | [`organization-client-lookup`](#rule-organization-client-lookup) |
| `auth0_organization_client` | `resource` | [`connection-configuration`](#auth0-concept-connection-configuration) | [`organization-client`](#rule-organization-client) |
| `auth0_organization_clients` | `resource` | [`connection-configuration`](#auth0-concept-connection-configuration) | [`organization-clients`](#rule-organization-clients) |
| `auth0_organization_connection` | `resource` | [`connection-configuration`](#auth0-concept-connection-configuration) | [`organization-connection`](#rule-organization-connection) |
| `auth0_organization_connections` | `resource` | [`connection-configuration`](#auth0-concept-connection-configuration) | [`organization-connections`](#rule-organization-connections) |
| `auth0_organization_discovery_domain` | `resource` | [`connection-configuration`](#auth0-concept-connection-configuration) | [`organization-discovery-domain`](#rule-organization-discovery-domain) |
| `auth0_organization_discovery_domains` | `resource` | [`connection-configuration`](#auth0-concept-connection-configuration) | [`organization-discovery-domains`](#rule-organization-discovery-domains) |
| `auth0_organization` | `data` | [`customer-organization`](#auth0-concept-customer-organization) | [`organization-lookup`](#rule-organization-lookup) |
| `auth0_organization` | `resource` | [`customer-organization`](#auth0-concept-customer-organization) | [`organization`](#rule-organization) |
| `auth0_phone_provider` | `data` | [`notification-provider`](#auth0-concept-notification-provider) | [`phone-provider-lookup`](#rule-phone-provider-lookup) |
| `auth0_phone_provider` | `resource` | [`notification-provider`](#auth0-concept-notification-provider) | [`phone-provider`](#rule-phone-provider) |
| `auth0_rate_limit_policy` | `data` | [`authentication-configuration`](#auth0-concept-authentication-configuration) | [`rate-limit-policy-lookup`](#rule-rate-limit-policy-lookup) |
| `auth0_rate_limit_policy` | `resource` | [`authentication-configuration`](#auth0-concept-authentication-configuration) | [`rate-limit-policy`](#rule-rate-limit-policy) |
| `auth0_resource_server_scope` | `resource` | [`application-configuration`](#auth0-concept-application-configuration) | [`resource-server-scope`](#rule-resource-server-scope) |
| `auth0_resource_server_scopes` | `resource` | [`application-configuration`](#auth0-concept-application-configuration) | [`resource-server-scopes`](#rule-resource-server-scopes) |
| `auth0_resource_server` | `data` | [`api-resource-server`](#auth0-concept-api-resource-server) | [`resource-server-lookup`](#rule-resource-server-lookup) |
| `auth0_resource_server` | `resource` | [`api-resource-server`](#auth0-concept-api-resource-server) | [`resource-server`](#rule-resource-server) |
| `auth0_risk_assessments_new_device` | `resource` | [`authentication-configuration`](#auth0-concept-authentication-configuration) | [`risk-assessments-new-device`](#rule-risk-assessments-new-device) |
| `auth0_risk_assessments` | `resource` | [`authentication-configuration`](#auth0-concept-authentication-configuration) | [`risk-assessments`](#rule-risk-assessments) |
| `auth0_rule` | `resource` | [`identity-extension`](#auth0-concept-identity-extension) | [`rule`](#rule-rule) |
| `auth0_self_service_profile` | `data` | [`self-service-sso-profile`](#auth0-concept-self-service-sso-profile) | [`self-service-profile-lookup`](#rule-self-service-profile-lookup) |
| `auth0_self_service_profile` | `resource` | [`self-service-sso-profile`](#auth0-concept-self-service-sso-profile) | [`self-service-profile`](#rule-self-service-profile) |
| `auth0_supplemental_signals` | `resource` | [`authentication-configuration`](#auth0-concept-authentication-configuration) | [`supplemental-signals`](#rule-supplemental-signals) |
| `auth0_tenant` | `data` | [`identity-tenant`](#auth0-concept-identity-tenant) | [`tenant-lookup`](#rule-tenant-lookup) |
| `auth0_tenant` | `resource` | [`identity-tenant`](#auth0-concept-identity-tenant) | [`tenant`](#rule-tenant) |
| `auth0_token_exchange_profile` | `data` | [`token-exchange-profile`](#auth0-concept-token-exchange-profile) | [`token-exchange-profile-lookup`](#rule-token-exchange-profile-lookup) |
| `auth0_token_exchange_profile` | `resource` | [`token-exchange-profile`](#auth0-concept-token-exchange-profile) | [`token-exchange-profile`](#rule-token-exchange-profile) |
| `auth0_trigger_action` | `resource` | [`extension-configuration`](#auth0-concept-extension-configuration) | [`trigger-action`](#rule-trigger-action) |
| `auth0_trigger_actions` | `resource` | [`extension-configuration`](#auth0-concept-extension-configuration) | [`trigger-actions`](#rule-trigger-actions) |
| `auth0_user_attribute_profile` | `data` | [`self-service-configuration`](#auth0-concept-self-service-configuration) | [`user-attribute-profile-lookup`](#rule-user-attribute-profile-lookup) |
| `auth0_user_attribute_profile` | `resource` | [`self-service-configuration`](#auth0-concept-self-service-configuration) | [`user-attribute-profile`](#rule-user-attribute-profile) |

## Local vocabulary

### Concepts

<dl>

<div>
<dt id="auth0-concept-api-resource-server"><code>auth0.concept.api-resource-server</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/auth0/applications/clients-apis.rf.hcl#L1-L3">Source</a></dt>
<dd>

An API registered as an Auth0 resource server for authorized applications.

</dd>
<dd>


<details>
<summary>Used by 6 Rules</summary>

- [`client`](#rule-client)
- [`client-lookup`](#rule-client-lookup)
- [`resource-server`](#rule-resource-server)
- [`resource-server-lookup`](#rule-resource-server-lookup)
- [`resource-server-scope`](#rule-resource-server-scope)
- [`resource-server-scopes`](#rule-resource-server-scopes)

</details>

</dd>
</div>

<div>
<dt id="auth0-concept-application-configuration"><code>auth0.concept.application-configuration</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/auth0/applications/configuration.rf.hcl#L1-L3">Source</a></dt>
<dd>

Credentials, grants, or associations supporting an Auth0 Application.

</dd>
<dd>


<details>
<summary>Used by 4 Rules</summary>

- [`client-credentials`](#rule-client-credentials)
- [`client-grant`](#rule-client-grant)
- [`resource-server-scope`](#rule-resource-server-scope)
- [`resource-server-scopes`](#rule-resource-server-scopes)

</details>

</dd>
</div>

<div>
<dt id="auth0-concept-authentication-boundary"><code>auth0.concept.authentication-boundary</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/auth0/security/authentication-boundaries.rf.hcl#L1-L3">Source</a></dt>
<dd>

An Auth0 Network ACL bounding authentication or management traffic.

</dd>
<dd>

Used by [`network-acl`](#rule-network-acl), [`network-acl-lookup`](#rule-network-acl-lookup).

</dd>
</div>

<div>
<dt id="auth0-concept-authentication-configuration"><code>auth0.concept.authentication-configuration</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/auth0/security/authentication-boundaries.rf.hcl#L5-L7">Source</a></dt>
<dd>

Attack protection, MFA, risk, rate-limit, or encryption configuration supporting Auth0.

</dd>
<dd>


<details>
<summary>Used by 9 Rules</summary>

- [`attack-protection`](#rule-attack-protection)
- [`attack-protection-lookup`](#rule-attack-protection-lookup)
- [`encryption-key-manager`](#rule-encryption-key-manager)
- [`guardian`](#rule-guardian)
- [`rate-limit-policy`](#rule-rate-limit-policy)
- [`rate-limit-policy-lookup`](#rule-rate-limit-policy-lookup)
- [`risk-assessments`](#rule-risk-assessments)
- [`risk-assessments-new-device`](#rule-risk-assessments-new-device)
- [`supplemental-signals`](#rule-supplemental-signals)

</details>

</dd>
</div>

<div>
<dt id="auth0-concept-connection-configuration"><code>auth0.concept.connection-configuration</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/auth0/connections/configuration.rf.hcl#L1-L3">Source</a></dt>
<dd>

Client enablement, SCIM, keys, or synchronization supporting an Auth0 Connection.

</dd>
<dd>


<details>
<summary>Used by 16 Rules</summary>

- [`connection-client`](#rule-connection-client)
- [`connection-clients`](#rule-connection-clients)
- [`connection-directory-synchronized-groups`](#rule-connection-directory-synchronized-groups)
- [`connection-directory-synchronized-groups-lookup`](#rule-connection-directory-synchronized-groups-lookup)
- [`connection-keys`](#rule-connection-keys)
- [`connection-keys-lookup`](#rule-connection-keys-lookup)
- [`connection-scim-configuration`](#rule-connection-scim-configuration)
- [`connection-scim-configuration-lookup`](#rule-connection-scim-configuration-lookup)
- [`organization-client`](#rule-organization-client)
- [`organization-client-grant`](#rule-organization-client-grant)
- [`organization-client-lookup`](#rule-organization-client-lookup)
- [`organization-clients`](#rule-organization-clients)
- [`organization-connection`](#rule-organization-connection)
- [`organization-connections`](#rule-organization-connections)
- [`organization-discovery-domain`](#rule-organization-discovery-domain)
- [`organization-discovery-domains`](#rule-organization-discovery-domains)

</details>

</dd>
</div>

<div>
<dt id="auth0-concept-customer-organization"><code>auth0.concept.customer-organization</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/auth0/tenancy/tenants-organizations.rf.hcl#L1-L3">Source</a></dt>
<dd>

An Auth0 Organization representing a customer or business audience inside a tenant.

</dd>
<dd>


<details>
<summary>Used by 13 Rules</summary>

- [`client`](#rule-client)
- [`client-cimd`](#rule-client-cimd)
- [`client-lookup`](#rule-client-lookup)
- [`organization`](#rule-organization)
- [`organization-client`](#rule-organization-client)
- [`organization-client-grant`](#rule-organization-client-grant)
- [`organization-client-lookup`](#rule-organization-client-lookup)
- [`organization-clients`](#rule-organization-clients)
- [`organization-connection`](#rule-organization-connection)
- [`organization-connections`](#rule-organization-connections)
- [`organization-discovery-domain`](#rule-organization-discovery-domain)
- [`organization-discovery-domains`](#rule-organization-discovery-domains)
- [`organization-lookup`](#rule-organization-lookup)

</details>

</dd>
</div>

<div>
<dt id="auth0-concept-directory-sync"><code>auth0.concept.directory-sync</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/auth0/connections/directory-sync.rf.hcl#L1-L3">Source</a></dt>
<dd>

An Auth0 Directory Sync integration attached to an enterprise Connection.

</dd>
<dd>


<details>
<summary>Used by 4 Rules</summary>

- [`connection-directory`](#rule-connection-directory)
- [`connection-directory-lookup`](#rule-connection-directory-lookup)
- [`connection-directory-synchronized-groups`](#rule-connection-directory-synchronized-groups)
- [`connection-directory-synchronized-groups-lookup`](#rule-connection-directory-synchronized-groups-lookup)

</details>

</dd>
</div>

<div>
<dt id="auth0-concept-domain-configuration"><code>auth0.concept.domain-configuration</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/auth0/domains/custom-domains.rf.hcl#L1-L3">Source</a></dt>
<dd>

Default-domain or verification configuration supporting an Auth0 custom domain.

</dd>
<dd>

Used by [`custom-domain-default`](#rule-custom-domain-default), [`custom-domain-verification`](#rule-custom-domain-verification).

</dd>
</div>

<div>
<dt id="auth0-concept-extension-configuration"><code>auth0.concept.extension-configuration</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/auth0/extensibility/configuration.rf.hcl#L1-L3">Source</a></dt>
<dd>

A module or trigger binding supporting Auth0 identity extensions.

</dd>
<dd>


<details>
<summary>Used by 4 Rules</summary>

- [`action-module`](#rule-action-module)
- [`action-module-lookup`](#rule-action-module-lookup)
- [`trigger-action`](#rule-trigger-action)
- [`trigger-actions`](#rule-trigger-actions)

</details>

</dd>
</div>

<div>
<dt id="auth0-concept-flow-vault-connection"><code>auth0.concept.flow-vault-connection</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/auth0/workflows/integrations.rf.hcl#L1-L3">Source</a></dt>
<dd>

A Forms and Flows Vault connection to an external integration.

</dd>
<dd>

Used by [`flow-vault-connection`](#rule-flow-vault-connection), [`flow-vault-connection-lookup`](#rule-flow-vault-connection-lookup).

</dd>
</div>

<div>
<dt id="auth0-concept-identity-application"><code>auth0.concept.identity-application</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/auth0/vocabulary.rf.hcl#L1-L3">Source</a></dt>
<dd>

An application or relying-party client registered with an identity platform.

</dd>
<dd>


<details>
<summary>Used by 8 Rules</summary>

- [`client`](#rule-client)
- [`client-cimd`](#rule-client-cimd)
- [`client-credentials`](#rule-client-credentials)
- [`client-grant`](#rule-client-grant)
- [`client-lookup`](#rule-client-lookup)
- [`connection-client`](#rule-connection-client)
- [`organization-client`](#rule-organization-client)
- [`organization-client-lookup`](#rule-organization-client-lookup)

</details>

</dd>
</div>

<div>
<dt id="auth0-concept-identity-connection"><code>auth0.concept.identity-connection</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/auth0/connections/identity-connections.rf.hcl#L1-L3">Source</a></dt>
<dd>

An Auth0 Connection sourcing identities from an enterprise provider, social provider, database, or passwordless method.

</dd>
<dd>


<details>
<summary>Used by 11 Rules</summary>

- [`connection`](#rule-connection)
- [`connection-client`](#rule-connection-client)
- [`connection-clients`](#rule-connection-clients)
- [`connection-directory`](#rule-connection-directory)
- [`connection-directory-lookup`](#rule-connection-directory-lookup)
- [`connection-keys`](#rule-connection-keys)
- [`connection-keys-lookup`](#rule-connection-keys-lookup)
- [`connection-lookup`](#rule-connection-lookup)
- [`connection-scim-configuration`](#rule-connection-scim-configuration)
- [`connection-scim-configuration-lookup`](#rule-connection-scim-configuration-lookup)
- [`organization-connection`](#rule-organization-connection)

</details>

</dd>
</div>

<div>
<dt id="auth0-concept-identity-domain"><code>auth0.concept.identity-domain</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/auth0/domains/custom-domains.rf.hcl#L5-L7">Source</a></dt>
<dd>

A custom domain exposing an Auth0-hosted identity endpoint.

</dd>
<dd>


<details>
<summary>Used by 4 Rules</summary>

- [`custom-domain`](#rule-custom-domain)
- [`custom-domain-default`](#rule-custom-domain-default)
- [`custom-domain-lookup`](#rule-custom-domain-lookup)
- [`custom-domain-verification`](#rule-custom-domain-verification)

</details>

</dd>
</div>

<div>
<dt id="auth0-concept-identity-event-stream"><code>auth0.concept.identity-event-stream</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/auth0/eventing-observability/event-streams.rf.hcl#L1-L3">Source</a></dt>
<dd>

An Auth0 Event Stream publishing tenant events to an external destination or Action.

</dd>
<dd>

Used by [`event-stream`](#rule-event-stream), [`event-stream-lookup`](#rule-event-stream-lookup).

</dd>
</div>

<div>
<dt id="auth0-concept-identity-extension"><code>auth0.concept.identity-extension</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/auth0/extensibility/actions-hooks.rf.hcl#L1-L3">Source</a></dt>
<dd>

An Auth0 Action, Rule, or Hook executing custom identity logic.

</dd>
<dd>


<details>
<summary>Used by 9 Rules</summary>

- [`action`](#rule-action)
- [`action-lookup`](#rule-action-lookup)
- [`event-stream`](#rule-event-stream)
- [`event-stream-lookup`](#rule-event-stream-lookup)
- [`hook`](#rule-hook)
- [`rule`](#rule-rule)
- [`token-exchange-profile`](#rule-token-exchange-profile)
- [`token-exchange-profile-lookup`](#rule-token-exchange-profile-lookup)
- [`trigger-action`](#rule-trigger-action)

</details>

</dd>
</div>

<div>
<dt id="auth0-concept-identity-tenant"><code>auth0.concept.identity-tenant</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/auth0/tenancy/tenants-organizations.rf.hcl#L5-L7">Source</a></dt>
<dd>

An existing Auth0 tenant acting as an identity and authorization boundary.

</dd>
<dd>

Used by [`tenant`](#rule-tenant), [`tenant-lookup`](#rule-tenant-lookup).

</dd>
</div>

<div>
<dt id="auth0-concept-identity-workflow"><code>auth0.concept.identity-workflow</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/auth0/workflows/forms-flows.rf.hcl#L1-L3">Source</a></dt>
<dd>

An Auth0 Form or Flow orchestrating an identity journey.

</dd>
<dd>


<details>
<summary>Used by 4 Rules</summary>

- [`flow`](#rule-flow)
- [`flow-lookup`](#rule-flow-lookup)
- [`form`](#rule-form)
- [`form-lookup`](#rule-form-lookup)

</details>

</dd>
</div>

<div>
<dt id="auth0-concept-notification-provider"><code>auth0.concept.notification-provider</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/auth0/communications/notification-providers.rf.hcl#L1-L3">Source</a></dt>
<dd>

An email or phone provider delivering Auth0 identity notifications.

</dd>
<dd>

Used by [`email-provider`](#rule-email-provider), [`phone-provider`](#rule-phone-provider), [`phone-provider-lookup`](#rule-phone-provider-lookup).

</dd>
</div>

<div>
<dt id="auth0-concept-self-service-configuration"><code>auth0.concept.self-service-configuration</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/auth0/connections/self-service-sso.rf.hcl#L1-L3">Source</a></dt>
<dd>

A connection or user-attribute profile supporting Self-Service SSO.

</dd>
<dd>


<details>
<summary>Used by 4 Rules</summary>

- [`connection-profile`](#rule-connection-profile)
- [`connection-profile-lookup`](#rule-connection-profile-lookup)
- [`user-attribute-profile`](#rule-user-attribute-profile)
- [`user-attribute-profile-lookup`](#rule-user-attribute-profile-lookup)

</details>

</dd>
</div>

<div>
<dt id="auth0-concept-self-service-sso-profile"><code>auth0.concept.self-service-sso-profile</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/auth0/connections/self-service-sso.rf.hcl#L5-L7">Source</a></dt>
<dd>

An Auth0 profile governing customer self-service enterprise SSO onboarding.

</dd>
<dd>

Used by [`self-service-profile`](#rule-self-service-profile), [`self-service-profile-lookup`](#rule-self-service-profile-lookup).

</dd>
</div>

<div>
<dt id="auth0-concept-token-exchange-profile"><code>auth0.concept.token-exchange-profile</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/auth0/extensibility/token-exchange.rf.hcl#L1-L3">Source</a></dt>
<dd>

An Auth0 Custom Token Exchange profile delegating validation to an Action.

</dd>
<dd>

Used by [`token-exchange-profile`](#rule-token-exchange-profile), [`token-exchange-profile-lookup`](#rule-token-exchange-profile-lookup).

</dd>
</div>

</dl>

### Relations

<dl>

<div>
<dt id="auth0-relation-defaults-to-organization"><code>auth0.relation.defaults-to-organization</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/auth0/applications/clients-apis.rf.hcl#L21-L31">Source</a></dt>
<dd>

Introduced by a labeled emission.
Used by [`client`](#rule-client), [`client-cimd`](#rule-client-cimd), [`client-lookup`](#rule-client-lookup).

</dd>
</div>

<div>
<dt id="auth0-relation-delivers-to-action"><code>auth0.relation.delivers-to-action</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/auth0/eventing-observability/event-streams.rf.hcl#L12-L22">Source</a></dt>
<dd>

Introduced by a labeled emission.
Used by [`event-stream`](#rule-event-stream), [`event-stream-lookup`](#rule-event-stream-lookup).

</dd>
</div>

<div>
<dt id="auth0-relation-executes-action"><code>auth0.relation.executes-action</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/auth0/extensibility/token-exchange.rf.hcl#L12-L22">Source</a></dt>
<dd>

Introduced by a labeled emission.
Used by [`token-exchange-profile`](#rule-token-exchange-profile), [`token-exchange-profile-lookup`](#rule-token-exchange-profile-lookup).

</dd>
</div>

<div>
<dt id="auth0-relation-synchronizes-connection"><code>auth0.relation.synchronizes-connection</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/auth0/connections/directory-sync.rf.hcl#L21-L31">Source</a></dt>
<dd>

Introduced by a labeled emission.
Used by [`connection-directory`](#rule-connection-directory), [`connection-directory-lookup`](#rule-connection-directory-lookup).

</dd>
</div>

<div>
<dt id="auth0-relation-uses-api"><code>auth0.relation.uses-api</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/auth0/applications/clients-apis.rf.hcl#L33-L43">Source</a></dt>
<dd>

Introduced by a labeled emission.
Used by [`client`](#rule-client), [`client-lookup`](#rule-client-lookup).

</dd>
</div>

</dl>

## Rule details

Open a Rule for its declared behavior and source. [Matching](https://docs.rootform.dev/language/reference/rules/#eligibility-pipeline), [emission resolution](https://docs.rootform.dev/language/reference/emissions/) and [composition](https://docs.rootform.dev/language/reference/composition/) define how evidence can establish it.

<details>
<summary><code>auth0.rule.action-module-lookup</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/auth0/extensibility/configuration.rf.hcl#L13-L20">Source</a></summary>

<div id="rule-action-module-lookup"></div>

Matches `data` instances of `auth0_action_module`.

**Classification:** [`auth0.concept.extension-configuration`](#auth0-concept-extension-configuration).

</details>

<details>
<summary><code>auth0.rule.action-module</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/auth0/extensibility/configuration.rf.hcl#L5-L11">Source</a></summary>

<div id="rule-action-module"></div>

Matches `resource` instances of `auth0_action_module`.

**Classification:** [`auth0.concept.extension-configuration`](#auth0-concept-extension-configuration).

</details>

<details>
<summary><code>auth0.rule.action-lookup</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/auth0/extensibility/actions-hooks.rf.hcl#L22-L38">Source</a></summary>

<div id="rule-action-lookup"></div>

Matches `data` instances of `auth0_action`.

**Classification:** [`auth0.concept.identity-extension`](#auth0-concept-identity-extension).

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id"]`

</details>

</details>

<details>
<summary><code>auth0.rule.action</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/auth0/extensibility/actions-hooks.rf.hcl#L5-L20">Source</a></summary>

<div id="rule-action"></div>

Matches `resource` instances of `auth0_action`.

**Classification:** [`auth0.concept.identity-extension`](#auth0-concept-identity-extension).

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id"]`

</details>

</details>

<details>
<summary><code>auth0.rule.attack-protection-lookup</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/auth0/security/authentication-boundaries.rf.hcl#L17-L24">Source</a></summary>

<div id="rule-attack-protection-lookup"></div>

Matches `data` instances of `auth0_attack_protection`.

**Classification:** [`auth0.concept.authentication-configuration`](#auth0-concept-authentication-configuration).

</details>

<details>
<summary><code>auth0.rule.attack-protection</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/auth0/security/authentication-boundaries.rf.hcl#L9-L15">Source</a></summary>

<div id="rule-attack-protection"></div>

Matches `resource` instances of `auth0_attack_protection`.

**Classification:** [`auth0.concept.authentication-configuration`](#auth0-concept-authentication-configuration).

</details>

<details>
<summary><code>auth0.rule.client-cimd</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/auth0/applications/clients-apis.rf.hcl#L46-L73">Source</a></summary>

<div id="rule-client-cimd"></div>

Matches `resource` instances of `auth0_client_cimd`.

**Classification:** [`auth0.concept.identity-application`](#auth0-concept-identity-application).

**Relations**

- [`auth0.relation.defaults-to-organization`](#auth0-relation-defaults-to-organization): targets [`auth0.concept.customer-organization`](#auth0-concept-customer-organization) through `source.default_organization[0].organization_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id"]`

**Relation through `source.default_organization[0].organization_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>auth0.rule.client-credentials</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/auth0/applications/configuration.rf.hcl#L5-L23">Source</a></summary>

<div id="rule-client-credentials"></div>

Matches `resource` instances of `auth0_client_credentials`.

**Classification:** [`auth0.concept.application-configuration`](#auth0-concept-application-configuration).

**Contributions**

- targets [`auth0.concept.identity-application`](#auth0-concept-identity-application) through `source.client_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.client_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>auth0.rule.client-grant</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/auth0/applications/configuration.rf.hcl#L25-L43">Source</a></summary>

<div id="rule-client-grant"></div>

Matches `resource` instances of `auth0_client_grant`.

**Classification:** [`auth0.concept.application-configuration`](#auth0-concept-application-configuration).

**Contributions**

- targets [`auth0.concept.identity-application`](#auth0-concept-identity-application) through `source.client_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.client_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>auth0.rule.client-lookup</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/auth0/applications/clients-apis.rf.hcl#L75-L115">Source</a></summary>

<div id="rule-client-lookup"></div>

Matches `data` instances of `auth0_client`.

**Classification:** [`auth0.concept.identity-application`](#auth0-concept-identity-application).

**Relations**

- [`auth0.relation.defaults-to-organization`](#auth0-relation-defaults-to-organization): targets [`auth0.concept.customer-organization`](#auth0-concept-customer-organization) through `source.default_organization[0].organization_id`.
- [`auth0.relation.uses-api`](#auth0-relation-uses-api): targets [`auth0.concept.api-resource-server`](#auth0-concept-api-resource-server) through `source.resource_server_identifier`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id"]`

**Relation through `source.default_organization[0].organization_id`**

- `on_null`: `"indeterminate"`
- `on_empty`: `"indeterminate"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

**Relation through `source.resource_server_identifier`**

- `on_null`: `"indeterminate"`
- `on_empty`: `"indeterminate"`
- `match.by`: `target.identifier`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>auth0.rule.client</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/auth0/applications/clients-apis.rf.hcl#L5-L44">Source</a></summary>

<div id="rule-client"></div>

Matches `resource` instances of `auth0_client`.

**Classification:** [`auth0.concept.identity-application`](#auth0-concept-identity-application).

**Relations**

- [`auth0.relation.defaults-to-organization`](#auth0-relation-defaults-to-organization): targets [`auth0.concept.customer-organization`](#auth0-concept-customer-organization) through `source.default_organization[0].organization_id`.
- [`auth0.relation.uses-api`](#auth0-relation-uses-api): targets [`auth0.concept.api-resource-server`](#auth0-concept-api-resource-server) through `source.resource_server_identifier`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id"]`

**Relation through `source.default_organization[0].organization_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

**Relation through `source.resource_server_identifier`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.identifier`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>auth0.rule.connection-client</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/auth0/connections/configuration.rf.hcl#L5-L35">Source</a></summary>

<div id="rule-connection-client"></div>

Matches `resource` instances of `auth0_connection_client`.

**Classification:** [`auth0.concept.connection-configuration`](#auth0-concept-connection-configuration).

**Contributions**

- targets [`auth0.concept.identity-connection`](#auth0-concept-identity-connection) through `source.connection_id`.
- targets [`auth0.concept.identity-application`](#auth0-concept-identity-application) through `source.client_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.connection_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

**Contribution through `source.client_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>auth0.rule.connection-clients</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/auth0/connections/configuration.rf.hcl#L37-L55">Source</a></summary>

<div id="rule-connection-clients"></div>

Matches `resource` instances of `auth0_connection_clients`.

**Classification:** [`auth0.concept.connection-configuration`](#auth0-concept-connection-configuration).

**Contributions**

- targets [`auth0.concept.identity-connection`](#auth0-concept-identity-connection) through `source.connection_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.connection_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>auth0.rule.connection-directory-synchronized-groups-lookup</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/auth0/connections/configuration.rf.hcl#L77-L96">Source</a></summary>

<div id="rule-connection-directory-synchronized-groups-lookup"></div>

Matches `data` instances of `auth0_connection_directory_synchronized_groups`.

**Classification:** [`auth0.concept.connection-configuration`](#auth0-concept-connection-configuration).

**Contributions**

- targets [`auth0.concept.directory-sync`](#auth0-concept-directory-sync) through `source.connection_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.connection_id`**

- `on_null`: `"indeterminate"`
- `on_empty`: `"indeterminate"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>auth0.rule.connection-directory-synchronized-groups</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/auth0/connections/configuration.rf.hcl#L57-L75">Source</a></summary>

<div id="rule-connection-directory-synchronized-groups"></div>

Matches `resource` instances of `auth0_connection_directory_synchronized_groups`.

**Classification:** [`auth0.concept.connection-configuration`](#auth0-concept-connection-configuration).

**Contributions**

- targets [`auth0.concept.directory-sync`](#auth0-concept-directory-sync) through `source.connection_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.connection_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>auth0.rule.connection-directory-lookup</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/auth0/connections/directory-sync.rf.hcl#L34-L62">Source</a></summary>

<div id="rule-connection-directory-lookup"></div>

Matches `data` instances of `auth0_connection_directory`.

**Classification:** [`auth0.concept.directory-sync`](#auth0-concept-directory-sync).

**Relations**

- [`auth0.relation.synchronizes-connection`](#auth0-relation-synchronizes-connection): targets [`auth0.concept.identity-connection`](#auth0-concept-identity-connection) through `source.connection_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id"]`

**Relation through `source.connection_id`**

- `on_null`: `"indeterminate"`
- `on_empty`: `"indeterminate"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>auth0.rule.connection-directory</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/auth0/connections/directory-sync.rf.hcl#L5-L32">Source</a></summary>

<div id="rule-connection-directory"></div>

Matches `resource` instances of `auth0_connection_directory`.

**Classification:** [`auth0.concept.directory-sync`](#auth0-concept-directory-sync).

**Relations**

- [`auth0.relation.synchronizes-connection`](#auth0-relation-synchronizes-connection): targets [`auth0.concept.identity-connection`](#auth0-concept-identity-connection) through `source.connection_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id"]`

**Relation through `source.connection_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>auth0.rule.connection-keys-lookup</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/auth0/connections/configuration.rf.hcl#L118-L137">Source</a></summary>

<div id="rule-connection-keys-lookup"></div>

Matches `data` instances of `auth0_connection_keys`.

**Classification:** [`auth0.concept.connection-configuration`](#auth0-concept-connection-configuration).

**Contributions**

- targets [`auth0.concept.identity-connection`](#auth0-concept-identity-connection) through `source.connection_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.connection_id`**

- `on_null`: `"indeterminate"`
- `on_empty`: `"indeterminate"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>auth0.rule.connection-keys</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/auth0/connections/configuration.rf.hcl#L98-L116">Source</a></summary>

<div id="rule-connection-keys"></div>

Matches `resource` instances of `auth0_connection_keys`.

**Classification:** [`auth0.concept.connection-configuration`](#auth0-concept-connection-configuration).

**Contributions**

- targets [`auth0.concept.identity-connection`](#auth0-concept-identity-connection) through `source.connection_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.connection_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>auth0.rule.connection-profile-lookup</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/auth0/connections/self-service-sso.rf.hcl#L17-L24">Source</a></summary>

<div id="rule-connection-profile-lookup"></div>

Matches `data` instances of `auth0_connection_profile`.

**Classification:** [`auth0.concept.self-service-configuration`](#auth0-concept-self-service-configuration).

</details>

<details>
<summary><code>auth0.rule.connection-profile</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/auth0/connections/self-service-sso.rf.hcl#L9-L15">Source</a></summary>

<div id="rule-connection-profile"></div>

Matches `resource` instances of `auth0_connection_profile`.

**Classification:** [`auth0.concept.self-service-configuration`](#auth0-concept-self-service-configuration).

</details>

<details>
<summary><code>auth0.rule.connection-scim-configuration-lookup</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/auth0/connections/configuration.rf.hcl#L159-L178">Source</a></summary>

<div id="rule-connection-scim-configuration-lookup"></div>

Matches `data` instances of `auth0_connection_scim_configuration`.

**Classification:** [`auth0.concept.connection-configuration`](#auth0-concept-connection-configuration).

**Contributions**

- targets [`auth0.concept.identity-connection`](#auth0-concept-identity-connection) through `source.connection_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.connection_id`**

- `on_null`: `"indeterminate"`
- `on_empty`: `"indeterminate"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>auth0.rule.connection-scim-configuration</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/auth0/connections/configuration.rf.hcl#L139-L157">Source</a></summary>

<div id="rule-connection-scim-configuration"></div>

Matches `resource` instances of `auth0_connection_scim_configuration`.

**Classification:** [`auth0.concept.connection-configuration`](#auth0-concept-connection-configuration).

**Contributions**

- targets [`auth0.concept.identity-connection`](#auth0-concept-identity-connection) through `source.connection_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.connection_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>auth0.rule.connection-lookup</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/auth0/connections/identity-connections.rf.hcl#L22-L38">Source</a></summary>

<div id="rule-connection-lookup"></div>

Matches `data` instances of `auth0_connection`.

**Classification:** [`auth0.concept.identity-connection`](#auth0-concept-identity-connection).

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id"]`

</details>

</details>

<details>
<summary><code>auth0.rule.connection</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/auth0/connections/identity-connections.rf.hcl#L5-L20">Source</a></summary>

<div id="rule-connection"></div>

Matches `resource` instances of `auth0_connection`.

**Classification:** [`auth0.concept.identity-connection`](#auth0-concept-identity-connection).

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id"]`

</details>

</details>

<details>
<summary><code>auth0.rule.custom-domain-default</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/auth0/domains/custom-domains.rf.hcl#L26-L47">Source</a></summary>

<div id="rule-custom-domain-default"></div>

Matches `resource` instances of `auth0_custom_domain_default`.

**Classification:** [`auth0.concept.domain-configuration`](#auth0-concept-domain-configuration).

**Contributions**

- targets [`auth0.concept.identity-domain`](#auth0-concept-identity-domain) through `source.domain`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.domain`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.domain`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>auth0.rule.custom-domain-verification</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/auth0/domains/custom-domains.rf.hcl#L67-L88">Source</a></summary>

<div id="rule-custom-domain-verification"></div>

Matches `resource` instances of `auth0_custom_domain_verification`.

**Classification:** [`auth0.concept.domain-configuration`](#auth0-concept-domain-configuration).

**Contributions**

- targets [`auth0.concept.identity-domain`](#auth0-concept-identity-domain) through `source.custom_domain_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.custom_domain_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `external`: `"allow"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>auth0.rule.custom-domain-lookup</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/auth0/domains/custom-domains.rf.hcl#L49-L65">Source</a></summary>

<div id="rule-custom-domain-lookup"></div>

Matches `data` instances of `auth0_custom_domain`.

**Classification:** [`auth0.concept.identity-domain`](#auth0-concept-identity-domain).

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id", "domain"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "domain"]`

</details>

</details>

<details>
<summary><code>auth0.rule.custom-domain</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/auth0/domains/custom-domains.rf.hcl#L9-L24">Source</a></summary>

<div id="rule-custom-domain"></div>

Matches `resource` instances of `auth0_custom_domain`.

**Classification:** [`auth0.concept.identity-domain`](#auth0-concept-identity-domain).

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id", "domain"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "domain"]`

</details>

</details>

<details>
<summary><code>auth0.rule.email-provider</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/auth0/communications/notification-providers.rf.hcl#L5-L11">Source</a></summary>

<div id="rule-email-provider"></div>

Matches `resource` instances of `auth0_email_provider`.

**Classification:** [`auth0.concept.notification-provider`](#auth0-concept-notification-provider).

</details>

<details>
<summary><code>auth0.rule.encryption-key-manager</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/auth0/security/authentication-boundaries.rf.hcl#L26-L32">Source</a></summary>

<div id="rule-encryption-key-manager"></div>

Matches `resource` instances of `auth0_encryption_key_manager`.

**Classification:** [`auth0.concept.authentication-configuration`](#auth0-concept-authentication-configuration).

</details>

<details>
<summary><code>auth0.rule.event-stream-lookup</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/auth0/eventing-observability/event-streams.rf.hcl#L25-L44">Source</a></summary>

<div id="rule-event-stream-lookup"></div>

Matches `data` instances of `auth0_event_stream`.

**Classification:** [`auth0.concept.identity-event-stream`](#auth0-concept-identity-event-stream).

**Relations**

- [`auth0.relation.delivers-to-action`](#auth0-relation-delivers-to-action): targets [`auth0.concept.identity-extension`](#auth0-concept-identity-extension) through `source.action_configuration[0].action_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Relation through `source.action_configuration[0].action_id`**

- `on_null`: `"indeterminate"`
- `on_empty`: `"indeterminate"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>auth0.rule.event-stream</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/auth0/eventing-observability/event-streams.rf.hcl#L5-L23">Source</a></summary>

<div id="rule-event-stream"></div>

Matches `resource` instances of `auth0_event_stream`.

**Classification:** [`auth0.concept.identity-event-stream`](#auth0-concept-identity-event-stream).

**Relations**

- [`auth0.relation.delivers-to-action`](#auth0-relation-delivers-to-action): targets [`auth0.concept.identity-extension`](#auth0-concept-identity-extension) through `source.action_configuration[0].action_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Relation through `source.action_configuration[0].action_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>auth0.rule.flow-vault-connection-lookup</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/auth0/workflows/integrations.rf.hcl#L13-L20">Source</a></summary>

<div id="rule-flow-vault-connection-lookup"></div>

Matches `data` instances of `auth0_flow_vault_connection`.

**Classification:** [`auth0.concept.flow-vault-connection`](#auth0-concept-flow-vault-connection).

</details>

<details>
<summary><code>auth0.rule.flow-vault-connection</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/auth0/workflows/integrations.rf.hcl#L5-L11">Source</a></summary>

<div id="rule-flow-vault-connection"></div>

Matches `resource` instances of `auth0_flow_vault_connection`.

**Classification:** [`auth0.concept.flow-vault-connection`](#auth0-concept-flow-vault-connection).

</details>

<details>
<summary><code>auth0.rule.flow-lookup</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/auth0/workflows/forms-flows.rf.hcl#L13-L20">Source</a></summary>

<div id="rule-flow-lookup"></div>

Matches `data` instances of `auth0_flow`.

**Classification:** [`auth0.concept.identity-workflow`](#auth0-concept-identity-workflow).

</details>

<details>
<summary><code>auth0.rule.flow</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/auth0/workflows/forms-flows.rf.hcl#L5-L11">Source</a></summary>

<div id="rule-flow"></div>

Matches `resource` instances of `auth0_flow`.

**Classification:** [`auth0.concept.identity-workflow`](#auth0-concept-identity-workflow).

</details>

<details>
<summary><code>auth0.rule.form-lookup</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/auth0/workflows/forms-flows.rf.hcl#L30-L37">Source</a></summary>

<div id="rule-form-lookup"></div>

Matches `data` instances of `auth0_form`.

**Classification:** [`auth0.concept.identity-workflow`](#auth0-concept-identity-workflow).

</details>

<details>
<summary><code>auth0.rule.form</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/auth0/workflows/forms-flows.rf.hcl#L22-L28">Source</a></summary>

<div id="rule-form"></div>

Matches `resource` instances of `auth0_form`.

**Classification:** [`auth0.concept.identity-workflow`](#auth0-concept-identity-workflow).

</details>

<details>
<summary><code>auth0.rule.guardian</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/auth0/security/authentication-boundaries.rf.hcl#L34-L40">Source</a></summary>

<div id="rule-guardian"></div>

Matches `resource` instances of `auth0_guardian`.

**Classification:** [`auth0.concept.authentication-configuration`](#auth0-concept-authentication-configuration).

</details>

<details>
<summary><code>auth0.rule.hook</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/auth0/extensibility/actions-hooks.rf.hcl#L40-L55">Source</a></summary>

<div id="rule-hook"></div>

Matches `resource` instances of `auth0_hook`.

**Classification:** [`auth0.concept.identity-extension`](#auth0-concept-identity-extension).

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id"]`

</details>

</details>

<details>
<summary><code>auth0.rule.network-acl-lookup</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/auth0/security/authentication-boundaries.rf.hcl#L50-L57">Source</a></summary>

<div id="rule-network-acl-lookup"></div>

Matches `data` instances of `auth0_network_acl`.

**Classification:** [`auth0.concept.authentication-boundary`](#auth0-concept-authentication-boundary).

</details>

<details>
<summary><code>auth0.rule.network-acl</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/auth0/security/authentication-boundaries.rf.hcl#L42-L48">Source</a></summary>

<div id="rule-network-acl"></div>

Matches `resource` instances of `auth0_network_acl`.

**Classification:** [`auth0.concept.authentication-boundary`](#auth0-concept-authentication-boundary).

</details>

<details>
<summary><code>auth0.rule.organization-client-grant</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/auth0/tenancy/organization-configuration.rf.hcl#L33-L51">Source</a></summary>

<div id="rule-organization-client-grant"></div>

Matches `resource` instances of `auth0_organization_client_grant`.

**Classification:** [`auth0.concept.connection-configuration`](#auth0-concept-connection-configuration).

**Contributions**

- targets [`auth0.concept.customer-organization`](#auth0-concept-customer-organization) through `source.organization_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.organization_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>auth0.rule.organization-client-lookup</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/auth0/tenancy/organization-configuration.rf.hcl#L53-L84">Source</a></summary>

<div id="rule-organization-client-lookup"></div>

Matches `data` instances of `auth0_organization_client`.

**Classification:** [`auth0.concept.connection-configuration`](#auth0-concept-connection-configuration).

**Contributions**

- targets [`auth0.concept.customer-organization`](#auth0-concept-customer-organization) through `source.organization_id`.
- targets [`auth0.concept.identity-application`](#auth0-concept-identity-application) through `source.client_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.organization_id`**

- `on_null`: `"indeterminate"`
- `on_empty`: `"indeterminate"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

**Contribution through `source.client_id`**

- `on_null`: `"indeterminate"`
- `on_empty`: `"indeterminate"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>auth0.rule.organization-client</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/auth0/tenancy/organization-configuration.rf.hcl#L1-L31">Source</a></summary>

<div id="rule-organization-client"></div>

Matches `resource` instances of `auth0_organization_client`.

**Classification:** [`auth0.concept.connection-configuration`](#auth0-concept-connection-configuration).

**Contributions**

- targets [`auth0.concept.customer-organization`](#auth0-concept-customer-organization) through `source.organization_id`.
- targets [`auth0.concept.identity-application`](#auth0-concept-identity-application) through `source.client_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.organization_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

**Contribution through `source.client_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>auth0.rule.organization-clients</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/auth0/tenancy/organization-configuration.rf.hcl#L86-L104">Source</a></summary>

<div id="rule-organization-clients"></div>

Matches `resource` instances of `auth0_organization_clients`.

**Classification:** [`auth0.concept.connection-configuration`](#auth0-concept-connection-configuration).

**Contributions**

- targets [`auth0.concept.customer-organization`](#auth0-concept-customer-organization) through `source.organization_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.organization_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>auth0.rule.organization-connection</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/auth0/tenancy/organization-configuration.rf.hcl#L106-L136">Source</a></summary>

<div id="rule-organization-connection"></div>

Matches `resource` instances of `auth0_organization_connection`.

**Classification:** [`auth0.concept.connection-configuration`](#auth0-concept-connection-configuration).

**Contributions**

- targets [`auth0.concept.customer-organization`](#auth0-concept-customer-organization) through `source.organization_id`.
- targets [`auth0.concept.identity-connection`](#auth0-concept-identity-connection) through `source.connection_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.organization_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

**Contribution through `source.connection_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>auth0.rule.organization-connections</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/auth0/tenancy/organization-configuration.rf.hcl#L138-L156">Source</a></summary>

<div id="rule-organization-connections"></div>

Matches `resource` instances of `auth0_organization_connections`.

**Classification:** [`auth0.concept.connection-configuration`](#auth0-concept-connection-configuration).

**Contributions**

- targets [`auth0.concept.customer-organization`](#auth0-concept-customer-organization) through `source.organization_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.organization_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>auth0.rule.organization-discovery-domain</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/auth0/tenancy/organization-configuration.rf.hcl#L158-L176">Source</a></summary>

<div id="rule-organization-discovery-domain"></div>

Matches `resource` instances of `auth0_organization_discovery_domain`.

**Classification:** [`auth0.concept.connection-configuration`](#auth0-concept-connection-configuration).

**Contributions**

- targets [`auth0.concept.customer-organization`](#auth0-concept-customer-organization) through `source.organization_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.organization_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>auth0.rule.organization-discovery-domains</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/auth0/tenancy/organization-configuration.rf.hcl#L178-L196">Source</a></summary>

<div id="rule-organization-discovery-domains"></div>

Matches `resource` instances of `auth0_organization_discovery_domains`.

**Classification:** [`auth0.concept.connection-configuration`](#auth0-concept-connection-configuration).

**Contributions**

- targets [`auth0.concept.customer-organization`](#auth0-concept-customer-organization) through `source.organization_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.organization_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>auth0.rule.organization-lookup</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/auth0/tenancy/tenants-organizations.rf.hcl#L26-L42">Source</a></summary>

<div id="rule-organization-lookup"></div>

Matches `data` instances of `auth0_organization`.

**Classification:** [`auth0.concept.customer-organization`](#auth0-concept-customer-organization).

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id"]`

</details>

</details>

<details>
<summary><code>auth0.rule.organization</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/auth0/tenancy/tenants-organizations.rf.hcl#L9-L24">Source</a></summary>

<div id="rule-organization"></div>

Matches `resource` instances of `auth0_organization`.

**Classification:** [`auth0.concept.customer-organization`](#auth0-concept-customer-organization).

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id"]`

</details>

</details>

<details>
<summary><code>auth0.rule.phone-provider-lookup</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/auth0/communications/notification-providers.rf.hcl#L21-L28">Source</a></summary>

<div id="rule-phone-provider-lookup"></div>

Matches `data` instances of `auth0_phone_provider`.

**Classification:** [`auth0.concept.notification-provider`](#auth0-concept-notification-provider).

</details>

<details>
<summary><code>auth0.rule.phone-provider</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/auth0/communications/notification-providers.rf.hcl#L13-L19">Source</a></summary>

<div id="rule-phone-provider"></div>

Matches `resource` instances of `auth0_phone_provider`.

**Classification:** [`auth0.concept.notification-provider`](#auth0-concept-notification-provider).

</details>

<details>
<summary><code>auth0.rule.rate-limit-policy-lookup</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/auth0/security/authentication-boundaries.rf.hcl#L67-L74">Source</a></summary>

<div id="rule-rate-limit-policy-lookup"></div>

Matches `data` instances of `auth0_rate_limit_policy`.

**Classification:** [`auth0.concept.authentication-configuration`](#auth0-concept-authentication-configuration).

</details>

<details>
<summary><code>auth0.rule.rate-limit-policy</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/auth0/security/authentication-boundaries.rf.hcl#L59-L65">Source</a></summary>

<div id="rule-rate-limit-policy"></div>

Matches `resource` instances of `auth0_rate_limit_policy`.

**Classification:** [`auth0.concept.authentication-configuration`](#auth0-concept-authentication-configuration).

</details>

<details>
<summary><code>auth0.rule.resource-server-scope</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/auth0/applications/configuration.rf.hcl#L45-L63">Source</a></summary>

<div id="rule-resource-server-scope"></div>

Matches `resource` instances of `auth0_resource_server_scope`.

**Classification:** [`auth0.concept.application-configuration`](#auth0-concept-application-configuration).

**Contributions**

- targets [`auth0.concept.api-resource-server`](#auth0-concept-api-resource-server) through `source.resource_server_identifier`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.resource_server_identifier`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.identifier`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>auth0.rule.resource-server-scopes</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/auth0/applications/configuration.rf.hcl#L65-L83">Source</a></summary>

<div id="rule-resource-server-scopes"></div>

Matches `resource` instances of `auth0_resource_server_scopes`.

**Classification:** [`auth0.concept.application-configuration`](#auth0-concept-application-configuration).

**Contributions**

- targets [`auth0.concept.api-resource-server`](#auth0-concept-api-resource-server) through `source.resource_server_identifier`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.resource_server_identifier`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.identifier`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>auth0.rule.resource-server-lookup</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/auth0/applications/clients-apis.rf.hcl#L134-L150">Source</a></summary>

<div id="rule-resource-server-lookup"></div>

Matches `data` instances of `auth0_resource_server`.

**Classification:** [`auth0.concept.api-resource-server`](#auth0-concept-api-resource-server).

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["identifier"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "identifier"]`

</details>

</details>

<details>
<summary><code>auth0.rule.resource-server</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/auth0/applications/clients-apis.rf.hcl#L117-L132">Source</a></summary>

<div id="rule-resource-server"></div>

Matches `resource` instances of `auth0_resource_server`.

**Classification:** [`auth0.concept.api-resource-server`](#auth0-concept-api-resource-server).

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["identifier"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id", "identifier"]`

</details>

</details>

<details>
<summary><code>auth0.rule.risk-assessments-new-device</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/auth0/security/authentication-boundaries.rf.hcl#L84-L90">Source</a></summary>

<div id="rule-risk-assessments-new-device"></div>

Matches `resource` instances of `auth0_risk_assessments_new_device`.

**Classification:** [`auth0.concept.authentication-configuration`](#auth0-concept-authentication-configuration).

</details>

<details>
<summary><code>auth0.rule.risk-assessments</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/auth0/security/authentication-boundaries.rf.hcl#L76-L82">Source</a></summary>

<div id="rule-risk-assessments"></div>

Matches `resource` instances of `auth0_risk_assessments`.

**Classification:** [`auth0.concept.authentication-configuration`](#auth0-concept-authentication-configuration).

</details>

<details>
<summary><code>auth0.rule.rule</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/auth0/extensibility/actions-hooks.rf.hcl#L57-L72">Source</a></summary>

<div id="rule-rule"></div>

Matches `resource` instances of `auth0_rule`.

**Classification:** [`auth0.concept.identity-extension`](#auth0-concept-identity-extension).

<details>
<summary>Conditions, identity and resolution</summary>

**Identity**

- `attributes`: `["id"]`
- `scope`: `"provider"`

**Endpoint**

- `attributes`: `["id"]`

</details>

</details>

<details>
<summary><code>auth0.rule.self-service-profile-lookup</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/auth0/connections/self-service-sso.rf.hcl#L34-L41">Source</a></summary>

<div id="rule-self-service-profile-lookup"></div>

Matches `data` instances of `auth0_self_service_profile`.

**Classification:** [`auth0.concept.self-service-sso-profile`](#auth0-concept-self-service-sso-profile).

</details>

<details>
<summary><code>auth0.rule.self-service-profile</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/auth0/connections/self-service-sso.rf.hcl#L26-L32">Source</a></summary>

<div id="rule-self-service-profile"></div>

Matches `resource` instances of `auth0_self_service_profile`.

**Classification:** [`auth0.concept.self-service-sso-profile`](#auth0-concept-self-service-sso-profile).

</details>

<details>
<summary><code>auth0.rule.supplemental-signals</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/auth0/security/authentication-boundaries.rf.hcl#L92-L98">Source</a></summary>

<div id="rule-supplemental-signals"></div>

Matches `resource` instances of `auth0_supplemental_signals`.

**Classification:** [`auth0.concept.authentication-configuration`](#auth0-concept-authentication-configuration).

</details>

<details>
<summary><code>auth0.rule.tenant-lookup</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/auth0/tenancy/tenants-organizations.rf.hcl#L52-L59">Source</a></summary>

<div id="rule-tenant-lookup"></div>

Matches `data` instances of `auth0_tenant`.

**Classification:** [`auth0.concept.identity-tenant`](#auth0-concept-identity-tenant).

</details>

<details>
<summary><code>auth0.rule.tenant</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/auth0/tenancy/tenants-organizations.rf.hcl#L44-L50">Source</a></summary>

<div id="rule-tenant"></div>

Matches `resource` instances of `auth0_tenant`.

**Classification:** [`auth0.concept.identity-tenant`](#auth0-concept-identity-tenant).

</details>

<details>
<summary><code>auth0.rule.token-exchange-profile-lookup</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/auth0/extensibility/token-exchange.rf.hcl#L25-L44">Source</a></summary>

<div id="rule-token-exchange-profile-lookup"></div>

Matches `data` instances of `auth0_token_exchange_profile`.

**Classification:** [`auth0.concept.token-exchange-profile`](#auth0-concept-token-exchange-profile).

**Relations**

- [`auth0.relation.executes-action`](#auth0-relation-executes-action): targets [`auth0.concept.identity-extension`](#auth0-concept-identity-extension) through `source.action_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Relation through `source.action_id`**

- `on_null`: `"indeterminate"`
- `on_empty`: `"indeterminate"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>auth0.rule.token-exchange-profile</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/auth0/extensibility/token-exchange.rf.hcl#L5-L23">Source</a></summary>

<div id="rule-token-exchange-profile"></div>

Matches `resource` instances of `auth0_token_exchange_profile`.

**Classification:** [`auth0.concept.token-exchange-profile`](#auth0-concept-token-exchange-profile).

**Relations**

- [`auth0.relation.executes-action`](#auth0-relation-executes-action): targets [`auth0.concept.identity-extension`](#auth0-concept-identity-extension) through `source.action_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Relation through `source.action_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>auth0.rule.trigger-action</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/auth0/extensibility/configuration.rf.hcl#L22-L40">Source</a></summary>

<div id="rule-trigger-action"></div>

Matches `resource` instances of `auth0_trigger_action`.

**Classification:** [`auth0.concept.extension-configuration`](#auth0-concept-extension-configuration).

**Contributions**

- targets [`auth0.concept.identity-extension`](#auth0-concept-identity-extension) through `source.action_id`.

<details>
<summary>Conditions, identity and resolution</summary>

**Contribution through `source.action_id`**

- `on_null`: `"absent"`
- `on_empty`: `"absent"`
- `match.by`: `target.id`
- `match.strategy`: `"exact"`

</details>

</details>

<details>
<summary><code>auth0.rule.trigger-actions</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/auth0/extensibility/configuration.rf.hcl#L42-L48">Source</a></summary>

<div id="rule-trigger-actions"></div>

Matches `resource` instances of `auth0_trigger_actions`.

**Classification:** [`auth0.concept.extension-configuration`](#auth0-concept-extension-configuration).

</details>

<details>
<summary><code>auth0.rule.user-attribute-profile-lookup</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/auth0/connections/self-service-sso.rf.hcl#L51-L58">Source</a></summary>

<div id="rule-user-attribute-profile-lookup"></div>

Matches `data` instances of `auth0_user_attribute_profile`.

**Classification:** [`auth0.concept.self-service-configuration`](#auth0-concept-self-service-configuration).

</details>

<details>
<summary><code>auth0.rule.user-attribute-profile</code> <a href="https://github.com/rootform-dev/rootform/blob/dev/dialects/auth0/connections/self-service-sso.rf.hcl#L43-L49">Source</a></summary>

<div id="rule-user-attribute-profile"></div>

Matches `resource` instances of `auth0_user_attribute_profile`.

**Classification:** [`auth0.concept.self-service-configuration`](#auth0-concept-self-service-configuration).

</details>
