Hi everyone.
We are currently reviewing content on the community and since this topic did not have a solution added to it, I will provide more information on the matter for anybody else running into the same issue.
You are trying to customize the mfa-otp-challenge and mfa-sms-challenge screens in Auth0 New Universal Login using ACUL (Advanced Customizations for Universal Login) to add a link for third-party SDK validation. You are encountering two issues: (1) mfa-otp-challenge does not appear in ACUL, and (2) the error "Universal Login Context is not available on the global window object" when running auth0 acul dev -c.
ACUL has limited support for MFA screen customization. The mfa-otp-challenge screen is not available for customization in ACUL, and the "Universal Login Context is not available" error indicates that your Authentication Profile is not configured correctly for ACUL development.
[Root Cause]
mfa-otp-challenge is not supported in ACUL — ACUL only supports mfa-sms-challenge and mfa-email-challenge for MFA customization. OTP (One-Time Password) challenge screens cannot be customized through ACUL at this time.
- "Universal Login Context is not available" error — This error occurs when you attempt to use ACUL without first setting your Authentication Profile to "Identifier First" in the Auth0 Dashboard. ACUL requires this setting to function properly.
- ACUL development mode limitations — The
-c flag (connected mode) requires the Authentication Profile to be set correctly. Without it, the Universal Login context is not available to the local development environment.
[Solution]
Step 1: Set Authentication Profile to Identifier First
- Navigate to Auth0 Dashboard → Settings → Authentication Profile
- Select "Identifier First"
- Save the changes
This is a prerequisite for ACUL to work correctly.
Step 2: Verify Available MFA Screens
Run the following command to see which screens are available for customization:
auth0 acul screen list
You will see that only these MFA screens are available:
mfa-sms-challenge
mfa-email-challenge
mfa-otp-challenge is not available in ACUL.
Step 3: Customize the Available MFA Screens
If you need to customize MFA screens, you can only customize SMS and Email challenges:
auth0 acul screen add mfa-sms-challenge
auth0 acul screen add mfa-email-challenge
Then run the development server:
auth0 acul dev
(Note: Do not use the -c flag initially; test without connected mode first.)
Step 4: For OTP Customization, Use Advanced Customizations for Universal Login
Since mfa-otp-challenge is not supported in ACUL, you have two options:
Option 1: Use Advanced Customizations for Universal Login (Recommended)
Advanced Customizations allows you to build a fully custom login UI with complete control over all screens, including OTP challenges. However, this requires:
- Building your own React-based UI
- Handling all authentication logic manually
- Managing API calls to Auth0 endpoints
See the Auth0 Advanced Customizations documentation for details.
Option 2: Contact Auth0 Support
If you need OTP screen customization within the standard Universal Login experience, open a support ticket to:
- Request
mfa-otp-challenge support in ACUL
- Discuss alternative approaches for your third-party SDK integration
- Explore whether your use case can be achieved through Post-Login Actions or Rules
Workaround: Add Third-Party SDK Link via Post-Login Actions
If you cannot customize the MFA screens directly, consider using Post-Login Actions to inject a link or redirect users to your third-party SDK validation page:
- Navigate to Auth0 Dashboard → Actions → Library
- Create a new Action that runs on the
mfa-challenge event
- Add logic to redirect or display a link to your third-party SDK
- Deploy the Action
This approach allows you to integrate third-party validation without modifying the MFA screens themselves.
Troubleshooting the "Universal Login Context is not available" Error:
If you continue to see this error after setting the Authentication Profile:
- Clear your local ACUL cache:
rm -rf .auth0
- Re-initialize ACUL:
auth0 acul init
- Verify your tenant configuration:
auth0 tenants list
- Run development mode without connected mode:
auth0 acul dev
- If the error persists, contact Auth0 Support with:
- Your tenant name
- Your Auth0 CLI version (
auth0 --version)
- The exact command and error output
Important Limitations:
- ACUL does not support
mfa-otp-challenge customization — This is a known limitation
- Only
mfa-sms-challenge and mfa-email-challenge can be customized in ACUL
- MFA customization is limited to text and styling — You cannot add custom links or redirect logic directly in ACUL
- Third-party SDK integration on MFA screens requires Advanced Customizations or Post-Login Actions
We recommend opening a support ticket with Auth0 if you need OTP screen customization, as this is currently a limitation of ACUL.
Kind Regards,
Nik