Acme@auth0/nextjs-auth0 4.26.0

Two brands, two custom domains

Acme Shop is a public store and anyone may sign up for it. Acme Bank is a separate brand with its own customers, its own custom domain and its own account directory. The bank directory holds no shopper accounts, and the bank customer's password is generated at start-up and never printed.

  1. Sign in to Acme Shop as shopper@acme-shop.test with Shop-Signup-2026.
  2. Open Acme Bank. The SDK refuses your shop session.
  3. Log out, then sign in to Acme Shop again through this link, with the same credentials. The link carries ?challengeMode=popup and nothing else is different.
  4. Open Acme Bank again. You are inside it.

No session

No session cookie is present.

Which custom domain each brand uses

Acme Shopf12-login-shop.huntland.abiusx.com
Acme Bankf12-login-bank.huntland.abiusx.com

Each brand also answers as JSON at /shop/whoami and /bank/whoami. Acme Bank has its own sign-in page at /auth/login?brand=bank, which refuses the shopper account.