A login box is where a company asks a stranger to become known. It can also be where the company loses that person: a broken password flow, an inaccessible prompt, a security step that confuses rather than protects. Auth0 turned this often invisible engineering job into a product for developers. Eugenio Pace and Matías Woloski founded the company in 2013. Woloski’s own account says they saw identity becoming central as software moved to the cloud and smartphones made services more continuous. Their answer was to make authentication something development teams could integrate and adapt.

The founders’ working geography was part of the design. Auth0’s account places Woloski in Buenos Aires and Pace in the Redmond area, roughly 7,000 miles apart at the start. The company was remote before remote work became a fashionable post-pandemic management story. That distance did not automatically make its product inclusive, but it complicates the notion that serious infrastructure must be invented in one U.S. office. An Argentine engineering network contributed to a platform used far beyond Argentina.

Okta completed its acquisition of Auth0 in 2021. The transaction drew attention because identity had become valuable infrastructure, not an auxiliary feature. What the deal did not answer is the user’s basic question: who controls the terms on which I can enter a service? A vendor can help an application secure an account, but the application still chooses what data to require, which recovery routes to offer, and how to treat someone who loses a phone or cannot pass a particular challenge.

Auth0’s technical emphasis on extensibility is revealing. A company account describes how customers could add custom logic to an authentication flow, adapting it without waiting for changes to the core product. Flexibility helps a developer solve a real problem; it also means a bad policy can be implemented efficiently. A login can include a person or exclude them at scale. The product’s success makes those decisions more consequential, not less.

It is easy to celebrate founders only when a large acquisition confirms their worth. Pace and Woloski’s more interesting contribution is the earlier judgment that identity work deserved careful tools and documentation for the people building applications. Their Argentine connection belongs in the history of that judgment. The next question belongs to all of us who use the resulting systems: when a login asks us to prove who we are, is there a fair way to recover when its proof fails?