Developing APIs with OAuth
Inbound Apps are OAuth clients. They request access tokens from Descope and call your APIs. They are not where you define your API's permission model.
| Piece | Responsibility |
|---|---|
| API Resource | Permission catalog: audience (aud), OAuth scopes, optional RBAC role mapping |
| Inbound App | OAuth client (consent, grant types, session settings) |
| Policies | Which clients can receive which scopes on which Resources |
| Your API / gateway | Validate the access token and enforce aud, scope, and other claims |
What to do
- Define permissions on a Resource — Create an API Resource with the scopes your endpoints require. See Scopes and roles.
- Register clients — Create Inbound Apps (or Agentic Clients) that request tokens for that Resource. Control grants with Policies.
- Validate every request — In your gateway or backend, verify the JWT and require the scopes (and
aud) for each operation. See Session validation, including Enforce scopes and Resource claims.
Descope issues the token; your service enforces it.
Related
- Resources — Audiences and permission scopes
- Session validation — Backend and gateway JWT validation
- Creating Inbound Apps — Register OAuth clients
- Using Inbound Apps — Token flows at runtime
Was this helpful?