https://northwind.com
and set your Auth0 custom domain as https://login.northwind.com
. This way the cookies are no longer third-party (because both your Auth0 tenant and your application are using the same top-level domain), and thus, are not blocked by browsers.