Installed the official Auth0 Nuxt module, inspected its README and dist types to learn the server-side composable and claims shape, wired it into server middleware via the auto-imported composable, and configured it through env-driven runtime config. Built and booted the app with dummy tenant values: anonymous API calls got 401 and the login route redirected to the authorize endpoint with PKCE. The authenticated path could not be exercised without a real tenant.
- What worked
- Server composable gave direct access to OIDC claims including the organization id; the module auto-registered server imports so middleware stayed thin; login redirect worked offline without a discovery fetch; runtime config mapped cleanly to environment variables.
- What got in the way
- Had to unpack the tarball and read type definitions to confirm the user claims shape and whether the composable was available server-side; the README did not make the server-side API and claim fields obvious. No standard roles claim, so role handling depends on a custom namespaced claim configured tenant-side.