CtrlK
BlogDocsLog inGet started
Tessl Logo

auth0-custom-domains

Use when setting up, troubleshooting, managing, removing, or checking the health of an Auth0 custom authentication domain (e.g. login.example.com), OR when diagnosing an error (400/403/404/409/429) from the /custom-domains Management API — especially Free-tier 403s (credit card on file, not a plan upgrade), self-managed cert 403s, PATCH-type 400s, `operation_not_supported` on `relying_party_identifier`, and 409 domain-already-exists. Handles CNAME creation in the user's DNS provider (Cloudflare, AWS Route 53, Azure DNS automated; other registrars guided), verification polling, Multiple Custom Domains (MCD), default-domain selection, TLS policy, client-IP header, per-domain passkey relying party identifier, and domain metadata.

94

1.71x
Quality

92%

Does it follow best practices?

Impact

98%

1.71x

Average score across 3 eval scenarios

SecuritybySnyk

Advisory

Suggest reviewing before use

SKILL.md
Quality
Evals
Security

Evaluation results

100%

68%

Domain Metadata Tagging for Multi-Brand Deployment

Domain metadata GET-merge-PATCH pattern

Criteria
Without context
With context

GET before PATCH

0%

100%

Client-side merge

0%

100%

Key removal by omission

0%

100%

Full merged object in PATCH

60%

100%

Single PATCH per domain

100%

100%

Auth0 CLI passthrough used

0%

100%

metadata_state.txt produced

100%

100%

domain_metadata key used

0%

100%

No constraint violation

100%

100%

No null-as-delete

0%

100%

96%

33%

Setting Up a Custom Auth0 Login Domain

Free-tier 403 diagnosis and domain setup

Criteria
Without context
With context

403 = credit card, not plan

100%

100%

No upgrade suggestion

100%

100%

Billing fix location

100%

100%

auth0_managed_certs default

100%

100%

Speculative RPID for subdomain

0%

100%

NS-based provider detection

0%

100%

Cloudflare = proxied:false

100%

100%

Exponential backoff polling

10%

100%

Post-verify app checklist

60%

100%

No TLS policy question

42%

42%

100%

23%

Auth0 Custom Domain Health Audit

Domain health audit with renewal-risk detection

Criteria
Without context
With context

DNS vs expected comparison

100%

100%

HTTPS reachability probe

100%

100%

TLS cert expiry check

100%

100%

Renewal-at-risk flagging

100%

100%

Pass/fail/warn visual markers

30%

100%

External resolver cross-check

20%

100%

No speculative create

100%

100%

Tenant name in report header

100%

100%

Default domain surfaced

0%

100%

cert expiry threshold flagging

100%

100%

Repository
auth0/agent-skills
Evaluated
Agent
Claude Code
Model
Claude Sonnet 4.6

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.