Hi @sargatanas
You are trying to set up Machine-to-Machine (M2M) authentication to manage users and roles in Auth0 through your API. You created a "User Administration" app connected to the Auth0 Management API with the correct permissions (all user, role_members, and user_tickets scopes). However, when you request an M2M access token using client credentials, you receive a 500 error with "no_tenant" — "This application is not associated with a tenant." Additionally, the Quickstart and Management API Test features are also failing with generic errors. You also mention having a custom domain and are unsure whether to use a CNAME or the default Auth0 domain for the token endpoint.
[Root Cause]
The "no_tenant" 500 error combined with failures in the Quickstart and Management API Test features suggests one of these causes:
- Audience parameter mismatch with custom domain — If you have a custom domain, you must still use your default tenant domain in the
audience parameter for Management API requests, not the custom domain
- Token endpoint and audience domain mismatch — If you request a token via custom domain but specify a custom domain audience, the token will be rejected when calling the Management API
- Tenant data corruption — Your tenant's internal data structure may be corrupted, causing the application to lose its tenant association
- Tenant provisioning failure — Your tenant may not have been fully provisioned during account creation
- Backend infrastructure issue — Auth0's backend services may have an issue with your specific tenant
[Solution]
Step 1: Understand the custom domain rule for Management API
According to Auth0 documentation, when using the Management API with a custom domain:
- Use your default tenant domain in the
audience parameter — This is the ONLY place to use your default tenant domain (e.g., https://dev-12zmndtub68y4114.us.auth0.com/api/v2/)
- You can request the token via custom domain — The token endpoint can use your custom domain (e.g.,
https://auth.yourdomain.com/oauth/token)
- Call the Management API with your default tenant domain — All API requests must use the same domain as the audience (the default domain)
- All requests must use the same domain — Tokens obtained via a custom domain must be used on Auth0 APIs using the same custom domain; tokens obtained via default domain must be used on default domain APIs
Step 2: Verify your custom domain configuration
Navigate to Auth0 Dashboard → Branding → Custom Domains.
Check whether:
- You have a custom domain configured (e.g.,
auth.yourdomain.com)
- The custom domain status shows as "Verified" or "Active"
- You have a CNAME record pointing to Auth0's endpoint
Step 3: Construct your M2M token request correctly
If you have a custom domain configured, use this format:
POST https://auth.yourdomain.com/oauth/token
Content-Type: application/json
{
"client_id":"<VALID_CLIENT_ID>",
"client_secret":"<VALID_CLIENT_SECRET>",
"audience":"https://dev-12zmndtub68y4114.us.auth0.com/api/v2/",
"grant_type":"client_credentials"
}
Key points:
- Token endpoint: Use your custom domain (
https://auth.yourdomain.com/oauth/token)
- Audience parameter: Use your default tenant domain (
https://dev-12zmndtub68y4114.us.auth0.com/api/v2/)
If you do NOT have a custom domain, use this format:
POST https://dev-12zmndtub68y4114.us.auth0.com/oauth/token
Content-Type: application/json
{
"client_id":"<VALID_CLIENT_ID>",
"client_secret":"<VALID_CLIENT_SECRET>",
"audience":"https://dev-12zmndtub68y4114.us.auth0.com/api/v2/",
"grant_type":"client_credentials"
}
Key points:
- Token endpoint: Use your default tenant domain
- Audience parameter: Use your default tenant domain
Step 4: Call the Management API with the correct domain
After obtaining the token, call the Management API using your custom domain:
GET https://auth.yourdomain.com/api/v2/users
Authorization: Bearer <ACCESS_TOKEN>
Step 5: Verify M2M application authorization
Navigate to Auth0 Dashboard → Applications → APIs → Auth0 Management API.
Click the "Machine to Machine Applications" tab.
Verify that:
- Your "User Administration" application is listed and authorized
- The application has a checkmark or "Authorized" status
- The authorized scopes include all the permissions you need (users, role_members, user_tickets)
If the application is not listed or not authorized, click "Authorize" and select your "User Administration" application, then grant all required scopes.
Step 6: Verify the application has the correct permissions
Navigate to Auth0 Dashboard → Applications → Applications → Your "User Administration" App.
Click the "APIs" tab.
Verify that:
- The "Auth0 Management API" is listed
- The API has a checkmark or "Authorized" status
- All required scopes are granted (read:users, create:users, update:users, delete:users, read:roles, manage:role_members, create:user_tickets)
If scopes are missing, click the API and add the missing scopes.
Step 7: Test the M2M token request with correct audience
Test your token request using the correct audience (default tenant domain):
curl --location 'https://dev-12zmndtub68y4114.us.auth0.com/oauth/token' \
--header 'Content-Type: application/json' \
--data '{
"client_id":"<VALID_CLIENT_ID>",
"client_secret":"<VALID_CLIENT_SECRET>",
"audience":"https://dev-12zmndtub68y4114.us.auth0.com/api/v2/",
"grant_type":"client_credentials"
}'
If the request succeeds, you will receive a 200 response with an access_token.
Then test calling the Management API with the token:
curl --location 'https://dev-12zmndtub68y4114.us.auth0.com/api/v2/users' \
--header 'Authorization: Bearer <ACCESS_TOKEN>'
Some of the information above is stated in our documentation on configuring features to use custom domains.
Kind Regards,
Nik