I should clarify that the first request to Auth0 is to get a token with the right audience and scopes to call an API.