Fetching token from Management App results in no_tenant 500 error

I am using Auth0 as my SSO provider and am interested in adding/updating/deleting users in Auth0 through my API, as well as managing their roles. I’ve created an app called ‘User Administration’ which is connected to the ‘Auth0 Management API’, the API that existed in the tenant when I set up Auth0. The app has 9 Client Access permissions to the API; all the :users permissions, all the :role_members, and the create:user_tickets permissions. However, when I try to fetch Client Credentials to allow my API to created/update users in the Auth0 API through an M2M token, the response I get back is a 500 error.

Here’s the POST request:

{
    "client_id":"<client ID from Administration App>",
    "client_secret":"<client secret from Administration App>",
    "audience":"https://dev-12zmndtub68y4114.us.auth0.com/api/v2/",
    "grant_type":"client_credentials"
}

Here’s the 500 response:

{
    "error": "no_tenant",
    "error_description": "This application is not associated with a tenant. Please contact support."
}

The URL is not a CNAME or any special configuration, I’m working just off of what’s provisioned in Auth0. Research through AI indicates my tenant may be corrupted. WHen I go to the Quickstart of my App I get an error toast: “Error! Unexpected failure trying to fetch apis, try again later.” and in the Test tab of the Auth0 Management API, I get an error toast: “Error!API Error. Please contact support if the problem persists”.

Could this tenant be investigated for what may be the problem? I’m trying to host a POC and I’d rather not start over with a new tenant or account. I’m on a free plan because I’m looking to test a few items before committing to a subscription.

Thank you very much.

Hi @sargatanas

Welcome to the Auth0 Community!

Before providing more information on the matter, I checked your tenant configuration and noticed that you are using a custom domain.

Could you please provide the entire request that you are using for the M2M application and confirm that you are using the canonical domain or not?

The request should look like this:

curl --request POST \
  --url 'https://{CUSTOM_DOMAIN}/oauth/token' \
  --header 'content-type: application/x-www-form-urlencoded' \
  --data grant_type=client_credentials \
  --data client_id={yourClientId} \
  --data client_secret={yourClientSecret} \
  --data audience=YOUR_API_IDENTIFIER

Kind Regards,
Nik

Thank you Nik.

Here’s the full curl request sans secrets:

curl --location 'https://dev-12zmndtub68y4114.us.auth0.com/oauth/token' \
--header 'Content-Type: application/json' \
--data '{
    "client_id":"<VALID_CLIENT_ID>",
    "client_secret":"<VALID_CLIENT_SECRET>",
    "audience":"https://dev-12zmndtub68y4114.us.auth0.com/api/v2/",
    "grant_type":"client_credentials"
}'

Because I have a custom domain, should I be using a CNAME to my app?

Hi @sargatanas

You are trying to set up Machine-to-Machine (M2M) authentication to manage users and roles in Auth0 through your API. You created a "User Administration" app connected to the Auth0 Management API with the correct permissions (all user, role_members, and user_tickets scopes). However, when you request an M2M access token using client credentials, you receive a 500 error with "no_tenant" — "This application is not associated with a tenant." Additionally, the Quickstart and Management API Test features are also failing with generic errors. You also mention having a custom domain and are unsure whether to use a CNAME or the default Auth0 domain for the token endpoint.

[Root Cause]

The "no_tenant" 500 error combined with failures in the Quickstart and Management API Test features suggests one of these causes:

  1. Audience parameter mismatch with custom domain — If you have a custom domain, you must still use your default tenant domain in the audience parameter for Management API requests, not the custom domain
  2. Token endpoint and audience domain mismatch — If you request a token via custom domain but specify a custom domain audience, the token will be rejected when calling the Management API
  3. Tenant data corruption — Your tenant's internal data structure may be corrupted, causing the application to lose its tenant association
  4. Tenant provisioning failure — Your tenant may not have been fully provisioned during account creation
  5. Backend infrastructure issue — Auth0's backend services may have an issue with your specific tenant

[Solution]

Step 1: Understand the custom domain rule for Management API

According to Auth0 documentation, when using the Management API with a custom domain:

  • Use your default tenant domain in the audience parameter — This is the ONLY place to use your default tenant domain (e.g., https://dev-12zmndtub68y4114.us.auth0.com/api/v2/)
  • You can request the token via custom domain — The token endpoint can use your custom domain (e.g., https://auth.yourdomain.com/oauth/token)
  • Call the Management API with your default tenant domain — All API requests must use the same domain as the audience (the default domain)
  • All requests must use the same domain — Tokens obtained via a custom domain must be used on Auth0 APIs using the same custom domain; tokens obtained via default domain must be used on default domain APIs

Step 2: Verify your custom domain configuration

Navigate to Auth0 Dashboard → Branding → Custom Domains.

Check whether:

  • You have a custom domain configured (e.g., auth.yourdomain.com)
  • The custom domain status shows as "Verified" or "Active"
  • You have a CNAME record pointing to Auth0's endpoint

Step 3: Construct your M2M token request correctly

If you have a custom domain configured, use this format:

POST https://auth.yourdomain.com/oauth/token
Content-Type: application/json

{
    "client_id":"<VALID_CLIENT_ID>",
    "client_secret":"<VALID_CLIENT_SECRET>",
    "audience":"https://dev-12zmndtub68y4114.us.auth0.com/api/v2/",
    "grant_type":"client_credentials"
}

Key points:

  • Token endpoint: Use your custom domain (https://auth.yourdomain.com/oauth/token)
  • Audience parameter: Use your default tenant domain (https://dev-12zmndtub68y4114.us.auth0.com/api/v2/)

If you do NOT have a custom domain, use this format:

POST https://dev-12zmndtub68y4114.us.auth0.com/oauth/token
Content-Type: application/json

{
    "client_id":"<VALID_CLIENT_ID>",
    "client_secret":"<VALID_CLIENT_SECRET>",
    "audience":"https://dev-12zmndtub68y4114.us.auth0.com/api/v2/",
    "grant_type":"client_credentials"
}

Key points:

  • Token endpoint: Use your default tenant domain
  • Audience parameter: Use your default tenant domain

Step 4: Call the Management API with the correct domain

After obtaining the token, call the Management API using your custom domain:

GET https://auth.yourdomain.com/api/v2/users
Authorization: Bearer <ACCESS_TOKEN>

Step 5: Verify M2M application authorization

Navigate to Auth0 Dashboard → Applications → APIs → Auth0 Management API.

Click the "Machine to Machine Applications" tab.

Verify that:

  • Your "User Administration" application is listed and authorized
  • The application has a checkmark or "Authorized" status
  • The authorized scopes include all the permissions you need (users, role_members, user_tickets)

If the application is not listed or not authorized, click "Authorize" and select your "User Administration" application, then grant all required scopes.

Step 6: Verify the application has the correct permissions

Navigate to Auth0 Dashboard → Applications → Applications → Your "User Administration" App.

Click the "APIs" tab.

Verify that:

  • The "Auth0 Management API" is listed
  • The API has a checkmark or "Authorized" status
  • All required scopes are granted (read:users, create:users, update:users, delete:users, read:roles, manage:role_members, create:user_tickets)

If scopes are missing, click the API and add the missing scopes.

Step 7: Test the M2M token request with correct audience

Test your token request using the correct audience (default tenant domain):

curl --location 'https://dev-12zmndtub68y4114.us.auth0.com/oauth/token' \
--header 'Content-Type: application/json' \
--data '{
    "client_id":"<VALID_CLIENT_ID>",
    "client_secret":"<VALID_CLIENT_SECRET>",
    "audience":"https://dev-12zmndtub68y4114.us.auth0.com/api/v2/",
    "grant_type":"client_credentials"
}'

If the request succeeds, you will receive a 200 response with an access_token.

Then test calling the Management API with the token:

curl --location 'https://dev-12zmndtub68y4114.us.auth0.com/api/v2/users' \
--header 'Authorization: Bearer <ACCESS_TOKEN>'

Some of the information above is stated in our documentation on configuring features to use custom domains.

Kind Regards,
Nik