So unfortunately, we do not support the case where the TLDs are different. The way to solve for that is to use SSO where each website is issued their own separate OpenID token via the login provider which is then used to issue a JWT / session for that website