> ## Documentation Index
> Fetch the complete documentation index at: https://docs-staging-feat-docs-5612-expanded-grant-support-ea.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

> HTTPS ベースのコールバックを使用して、アプリケーションのなりすましに対するセキュリティを強化し、リスクを軽減する方法を学びます。

# 検証不能なコールバック URI のエンドユーザー確認への移行

Auth0 は、[認可コードフロー](/docs/ja-jp/get-started/authentication-and-authorization-flow/authorization-code-flow-with-pkce) を使用するすべてのネイティブアプリケーションに対して、[Android App Links](https://developer.android.com/training/app-links) と [Apple Universal Links](https://developer.apple.com/documentation/xcode/allowing-apps-and-websites-to-link-to-your-content) を使用した HTTPS ベースのコールバックへの移行を推奨しています。これにより、セキュリティが強化され、アプリケーションのなりすましやフィッシング攻撃のリスクを軽減できます。

これによって攻撃をどのように防げるかを理解するには、[Measures Against Application Impersonation](/docs/ja-jp/secure/security-guidance/measures-against-app-impersonation#prompt-customization) を確認してください。

2025 年 10 月 15 日より前に作成されたテナントでは、2026 年 4 月 28 日までは従来の動作がデフォルトのまま維持されます。10 月の期限日以降に新しく作成されたテナントでは、各環境のデプロイ スケジュールによる一部の例外を除き、新しいログイン確認プロンプトがデフォルトで表示される場合があります。

明示的にオプトアウトしたテナントでは、このプロンプトは無期限に表示されません。これは、2026 年 4 月 28 日にサービスで確認プロンプトがデフォルトの動作となり、「Unconfirmed Login with Non-Verifiable Callback URI Redirects」の移行トグルが削除された後も変わりません。

<h2 id="how-are-you-affected">
  どのような影響がありますか？
</h2>

すでにカスタム URI スキームまたはループバック URI コールバックを指定している、あるいは今後指定する予定のあるクライアントアプリケーションでは、エンドユーザーが新しいログイン確認プロンプトで操作を行い、ログインを明示的に確認する必要が生じる場合があります。エンドユーザーは、この変更によってユーザーエクスペリエンスが低下したと感じる可能性があります。

さらに、アプリケーションが検証不能なコールバック URI を使用し、新しいログイン確認プロンプトを使用するよう設定されている場合、`prompt=none` を含む認証リクエストは拒否されます。

<h2 id="migration-tasks">
  移行タスク
</h2>

**Auth0 は、認可コードフローを使用するすべてのネイティブアプリケーションについて、可能な限り Android App Links と Apple Universal Links を使用した HTTPS ベースのコールバックへの移行を強く推奨しています**。

さらに、2026 年 4 月 28 日以降にデフォルトの動作が変更されるテナントでは、システムのデフォルト変更に先立ち、カスタム URI スキームまたはループバック URI コールバックを使用する認証リクエストに必要な動作を明示的に選択する必要があります。

<h3 id="review-whether-your-applications-are-using-non-verifiable-callback-uris">
  アプリケーションで 検証不能なコールバック URI が使用されているか確認する
</h3>

Unconfirmed Login with 検証不能なコールバック URI Redirects の migration toggle が利用可能で、有効になっているテナントでは、カスタム URI スキームまたはループバック URI を指定する認証リクエストは、アプリケーションまたはテナント レベルで次のオプションを明示的に設定していない限り、**非推奨化通知を示すテナントログを生成します**。

`skip_non_verifiable_callback_uri_confirmation_prompt`

これらのテナントログには、リクエストを実行したアプリケーションのクライアント ID が含まれます。これらのテナントログは、次のクエリを使用して Auth0 Dashboard で監視できます。

```bash theme={null}
type:depnotetype:depnote AND description:Unconfirmed\ Login\ with\ Non-Verifiable\ Callback\ URI\ Redirects*
```

<h3 id="opt-in-to-new-login-confirmation-prompt">
  新しいログイン確認プロンプトを事前に有効化する
</h3>

新しいログイン確認プロンプトを事前に有効化し、カスタム URI スキームまたはループバック URI を使用する認証フローのセキュリティを強化するには、Auth0 Dashboard で次の手順を実行します。

1. [**Auth0 Dashboard > Tenant Settings > Advanced**](https://manage.auth0.com/#/tenant/advanced) に移動します。
2. **Migrations** セクションで、**Unconfirmed Login with Non-Verifiable Callback URI Redirects** トグルをオフにします。

<Frame>
  <img src="https://mintcdn.com/docs-staging-feat-docs-5612-expanded-grant-support-ea/z4swooqkImAVV4VL/docs/images/cdy7uua7fh8z/unconfirmed-login-uri.png?fit=max&auto=format&n=z4swooqkImAVV4VL&q=85&s=b9f75c76c5387b09940d9058f7d2de9c" alt="Auth0 Dashboard > Tenant Settings > Advanced > トグルをオフ" data-og-width="502" width="502" data-og-height="128" height="128" data-path="docs/images/cdy7uua7fh8z/unconfirmed-login-uri.png" data-optimize="true" data-opv="3" srcset="https://mintcdn.com/docs-staging-feat-docs-5612-expanded-grant-support-ea/z4swooqkImAVV4VL/docs/images/cdy7uua7fh8z/unconfirmed-login-uri.png?w=280&fit=max&auto=format&n=z4swooqkImAVV4VL&q=85&s=00cb85c89a40e93382cab09ff900df34 280w, https://mintcdn.com/docs-staging-feat-docs-5612-expanded-grant-support-ea/z4swooqkImAVV4VL/docs/images/cdy7uua7fh8z/unconfirmed-login-uri.png?w=560&fit=max&auto=format&n=z4swooqkImAVV4VL&q=85&s=328c81a89eb1ff3d7fbb4a43ba130a8f 560w, https://mintcdn.com/docs-staging-feat-docs-5612-expanded-grant-support-ea/z4swooqkImAVV4VL/docs/images/cdy7uua7fh8z/unconfirmed-login-uri.png?w=840&fit=max&auto=format&n=z4swooqkImAVV4VL&q=85&s=b137b4686b1a958e22673b0ed5b88b75 840w, https://mintcdn.com/docs-staging-feat-docs-5612-expanded-grant-support-ea/z4swooqkImAVV4VL/docs/images/cdy7uua7fh8z/unconfirmed-login-uri.png?w=1100&fit=max&auto=format&n=z4swooqkImAVV4VL&q=85&s=d8f032622418e0d2b64481f9c0ff073a 1100w, https://mintcdn.com/docs-staging-feat-docs-5612-expanded-grant-support-ea/z4swooqkImAVV4VL/docs/images/cdy7uua7fh8z/unconfirmed-login-uri.png?w=1650&fit=max&auto=format&n=z4swooqkImAVV4VL&q=85&s=6a6172958f6dd18bc8911d457ecfd54c 1650w, https://mintcdn.com/docs-staging-feat-docs-5612-expanded-grant-support-ea/z4swooqkImAVV4VL/docs/images/cdy7uua7fh8z/unconfirmed-login-uri.png?w=2500&fit=max&auto=format&n=z4swooqkImAVV4VL&q=85&s=89eff4345b4fbd5d60136d9551757941 2500w" />
</Frame>

<h3 id="opt-out-of-new-login-confirmation-prompt">
  新しいログイン確認プロンプトを使用しない
</h3>

セキュリティ上の考慮事項を評価したうえで、新しいログイン確認プロンプトを使用しないと判断した場合は、特定のアプリケーションまたはテナント全体で、この新しい動作を無効にするよう設定できます。設定は Auth0 Dashboard から行えます。

アプリケーション レベルの設定は、テナント レベルの設定より優先されます。意図しない動作変更を避けるため、テナント レベルの設定を変更する前に、アプリケーション固有の設定を行ってください。たとえば、特定のアプリケーションでは **検証不能なコールバック URI End-User Confirmation** をスキップし、他のアプリケーションではデフォルトで表示する、といった設定やその逆の設定が可能です。

特定のアプリケーションで無効にするには:

1. [Auth0 Dashboard > Applications > Settings > Advanced Settings > OAuth](https://manage.auth0.com/applications/settings) に移動します。
2. **検証不能なコールバック URI End-User Confirmation** トグルを見つけて無効にし、**Save** を選択します。この設定を永続的に管理できるようにするには、**Override the tenant setting** オプションの選択が必要になる場合があります。

<Frame>
  <img src="https://mintcdn.com/docs-staging-feat-docs-5612-expanded-grant-support-ea/z4swooqkImAVV4VL/docs/images/cdy7uua7fh8z/custom-uri-override.png?fit=max&auto=format&n=z4swooqkImAVV4VL&q=85&s=821c10c11b7f9871562f35f0eed76ef8" alt="Auth0 Dashboard > Applications > Settings > Advanced" data-og-width="602" width="602" data-og-height="227" height="227" data-path="docs/images/cdy7uua7fh8z/custom-uri-override.png" data-optimize="true" data-opv="3" srcset="https://mintcdn.com/docs-staging-feat-docs-5612-expanded-grant-support-ea/z4swooqkImAVV4VL/docs/images/cdy7uua7fh8z/custom-uri-override.png?w=280&fit=max&auto=format&n=z4swooqkImAVV4VL&q=85&s=df703fd75c0adff485b1426fe84b016b 280w, https://mintcdn.com/docs-staging-feat-docs-5612-expanded-grant-support-ea/z4swooqkImAVV4VL/docs/images/cdy7uua7fh8z/custom-uri-override.png?w=560&fit=max&auto=format&n=z4swooqkImAVV4VL&q=85&s=7e88fc5969b4cd92b9b9a2609b235e57 560w, https://mintcdn.com/docs-staging-feat-docs-5612-expanded-grant-support-ea/z4swooqkImAVV4VL/docs/images/cdy7uua7fh8z/custom-uri-override.png?w=840&fit=max&auto=format&n=z4swooqkImAVV4VL&q=85&s=b9fa50277807b41857f78986d7318ae0 840w, https://mintcdn.com/docs-staging-feat-docs-5612-expanded-grant-support-ea/z4swooqkImAVV4VL/docs/images/cdy7uua7fh8z/custom-uri-override.png?w=1100&fit=max&auto=format&n=z4swooqkImAVV4VL&q=85&s=ff76b936f66996adf233a5e64c12337b 1100w, https://mintcdn.com/docs-staging-feat-docs-5612-expanded-grant-support-ea/z4swooqkImAVV4VL/docs/images/cdy7uua7fh8z/custom-uri-override.png?w=1650&fit=max&auto=format&n=z4swooqkImAVV4VL&q=85&s=08b17060af53226613ca3af951c7c0c2 1650w, https://mintcdn.com/docs-staging-feat-docs-5612-expanded-grant-support-ea/z4swooqkImAVV4VL/docs/images/cdy7uua7fh8z/custom-uri-override.png?w=2500&fit=max&auto=format&n=z4swooqkImAVV4VL&q=85&s=ad9d52cbc35465da1afb4a7dea6ba319 2500w" />
</Frame>

テナント全体で無効にするには:

1. [Auth0 Dashboard > Tenant Settings > Advanced](https://manage.auth0.com/tenant/advanced) に移動します。
2. **Login and Logout** セクション内の **検証不能なコールバック URI End-User Confirmation** トグルを見つけて無効にし、**Save** を選択します。この設定を永続的に管理できるようにするには、**Turn on** の選択が必要になる場合があります。

<Frame>
  <img src="https://mintcdn.com/docs-staging-feat-docs-5612-expanded-grant-support-ea/z4swooqkImAVV4VL/docs/images/cdy7uua7fh8z/migrate-uri-setting.png?fit=max&auto=format&n=z4swooqkImAVV4VL&q=85&s=5febbb9fb87751dfd69684b2f8f6fe98" alt="Auth0 Dashboard > Tenant Settings > Advanced" data-og-width="552" width="552" data-og-height="173" height="173" data-path="docs/images/cdy7uua7fh8z/migrate-uri-setting.png" data-optimize="true" data-opv="3" srcset="https://mintcdn.com/docs-staging-feat-docs-5612-expanded-grant-support-ea/z4swooqkImAVV4VL/docs/images/cdy7uua7fh8z/migrate-uri-setting.png?w=280&fit=max&auto=format&n=z4swooqkImAVV4VL&q=85&s=ad432b93a6efb8556a5b878a1a785912 280w, https://mintcdn.com/docs-staging-feat-docs-5612-expanded-grant-support-ea/z4swooqkImAVV4VL/docs/images/cdy7uua7fh8z/migrate-uri-setting.png?w=560&fit=max&auto=format&n=z4swooqkImAVV4VL&q=85&s=69637da2cca003bf8ca05bb61e78f833 560w, https://mintcdn.com/docs-staging-feat-docs-5612-expanded-grant-support-ea/z4swooqkImAVV4VL/docs/images/cdy7uua7fh8z/migrate-uri-setting.png?w=840&fit=max&auto=format&n=z4swooqkImAVV4VL&q=85&s=7c1bd27d2b2984430c1e09debdff190d 840w, https://mintcdn.com/docs-staging-feat-docs-5612-expanded-grant-support-ea/z4swooqkImAVV4VL/docs/images/cdy7uua7fh8z/migrate-uri-setting.png?w=1100&fit=max&auto=format&n=z4swooqkImAVV4VL&q=85&s=33584fa27a6a532f39ab55fb2abe7b89 1100w, https://mintcdn.com/docs-staging-feat-docs-5612-expanded-grant-support-ea/z4swooqkImAVV4VL/docs/images/cdy7uua7fh8z/migrate-uri-setting.png?w=1650&fit=max&auto=format&n=z4swooqkImAVV4VL&q=85&s=6c25c97583f9c8e76a8907451c6dad76 1650w, https://mintcdn.com/docs-staging-feat-docs-5612-expanded-grant-support-ea/z4swooqkImAVV4VL/docs/images/cdy7uua7fh8z/migrate-uri-setting.png?w=2500&fit=max&auto=format&n=z4swooqkImAVV4VL&q=85&s=07687f008bd2c17d1fe54ccd31168252 2500w" />
</Frame>

必要なテナントの動作は、Auth0 Management API を使用して設定することもできます。具体的には、次の 2 つのレベルで設定できます。

* **テナント レベルの設定**: [テナント設定を更新](https://auth0.com/docs/api/management/v2#!/Tenants/patch_settings) エンドポイントで `skip_non_verifiable_callback_uri_confirmation_prompt` プロパティを設定することで、確認プロンプトの動作を管理できます。
* **アプリケーション レベルの設定**: 特定のアプリケーションについてテナント レベルの設定を上書きするには、[Update Client](https://auth0.com/docs/api/management/v2#!/Clients/patch_clients_by_id) エンドポイントで同じ `skip_non_verifiable_callback_uri_confirmation_prompt` プロパティを設定します。

アプリケーションの設定に関する追加情報とガイダンスについては、[Measures Against Application Impersonation](/docs/ja-jp/secure/security-guidance/measures-against-app-impersonation) を参照してください。
