I’m troubleshooting native Sign in with Apple with Auth0 and have isolated the failure to Auth0’s server-side exchange with Apple.
Auth0 tenant: offroadin-app.us.auth0.com
Auth0 application client ID: OdSbaHnPUdXy8MVPtHEkLE6bsxggfCOf
Apple connection ID: con_Cgxq7xkaBSldNmJZ
Configuration:
- Apple Services ID / Auth0 Apple Social Connection Client ID:
app.offroadin.auth - Native iOS App ID / Bundle ID:
app.offroadin.ios - Team ID:
KHG523256M - Native Social Login → Sign in with Apple is enabled
- Device Settings App ID is
app.offroadin.ios
The native iOS app receives a real Apple authorizationCode and sends it to Auth0 /oauth/token using:
grant_type=urn:ietf:params:oauth:grant-type:token-exchange
subject_token_type=http://auth0.com/oauth/token-type/apple-authz-code
Auth0 returns:
Error from apple connection: (no description) (invalid_client)
I independently tested the exact same native Apple authorization code directly against:
https://appleid.apple.com/auth/token
using:
client_id=app.offroadin.ios
and a valid Apple client-secret JWT with:
sub=app.offroadin.ios
Apple successfully returned an access token, refresh token, and ID token.
I also verified that:
- the Apple
.p8/ Key ID are valid; - Team ID is valid;
- direct client-secret generation works;
- no nonce is being sent in the native Apple request;
- Auth0 Dashboard → Apple → Try Connection succeeds with the Services ID
app.offroadin.auth.
This appears to indicate Auth0 may be using the Apple Social Connection’s Services ID for the back-channel client authentication during apple-authz-code exchange rather than the native App ID from Device Settings.
Can someone from Auth0 confirm what client_id and client-secret JWT sub Auth0 uses for native apple-authz-code exchange?
Latest Auth0 error:
Error from apple connection: (no description) (invalid_client)
I can provide the full Auth0 failed-exchange log ID and request details if helpful.