Developing APIs with OAuth

Inbound Apps are OAuth clients. They request access tokens from Descope and call your APIs. They are not where you define your API's permission model.

PieceResponsibility
API ResourcePermission catalog: audience (aud), OAuth scopes, optional RBAC role mapping
Inbound AppOAuth client (consent, grant types, session settings)
PoliciesWhich clients can receive which scopes on which Resources
Your API / gatewayValidate the access token and enforce aud, scope, and other claims

What to do

  1. Define permissions on a Resource — Create an API Resource with the scopes your endpoints require. See Scopes and roles.
  2. Register clients — Create Inbound Apps (or Agentic Clients) that request tokens for that Resource. Control grants with Policies.
  3. Validate every request — In your gateway or backend, verify the JWT and require the scopes (and aud) for each operation. See Session validation, including Enforce scopes and Resource claims.

Descope issues the token; your service enforces it.

Was this helpful?

On this page