Acme@auth0/nextjs-auth0 4.26.0

Two brands, two custom domains

Acme Shop is a public store and anyone may sign up for it. Acme Bank is a separate brand with its own customers, its own custom domain and its own account directory. The bank directory holds no shopper accounts, and the bank customer's password is generated at start-up and never printed.

  1. Sign in to Acme Shop, which is the link /auth/login, as shopper@acme-shop.test with Shop-Signup-2026.
  2. Open Acme Bank. The SDK refuses your shop session.
  3. Log out. Now take the sign-in link from step 1 and append ?challengeMode=popup to it yourself:
    /auth/login?challengeMode=popup
    Open that and sign in with the same credentials.
  4. Open Acme Bank again. You are inside it.

No session

No session cookie is present.

Which custom domain each brand uses

Acme Shopf12-login-shop.huntland.abiusx.com
Acme Bankf12-login-bank.huntland.abiusx.com

Each brand also answers as JSON at /shop/whoami and /bank/whoami. Acme Bank has its own sign-in page at /auth/login?brand=bank, which refuses the shopper account.