AuthSec
SPIFFE/SPIRE certificate-based workload identity — Auth0 has none
XAA (ID-JAG) ships as stable and generally available; Auth0's Cross App Access is still closed Beta requiring Support enrollment
MCP resource indicators (RFC 8707) are native; Auth0 requires manually enabling a compatibility profile and lacks an RFC 7592 client-configuration-management endpoint
Device Authorization Grant, CIBA, and PAR are all included by default; Auth0 gates CIBA behind a +50% 'AI Agents' surcharge and PAR behind an Enterprise-only 'Highly Regulated Identity' add-on