When the auth is domain scoped, then there should be an option to extract the token's domain scope. See https://docs.openstack.org/api-ref/identity/v3/?expanded=password-authentication-with-scoped-authorization-detail#domain-scoped-example for example