JWT Bearer Grant

The JWT bearer grant (urn:ietf:params:oauth:grant-type:jwt-bearer, RFC 7523) lets an Inbound App present a signed JWT from a trusted external issuer at the token endpoint and receive a Descope-issued access token in return. Descope validates the assertion's signature, issuer, and claims, then maps the subject to a user (when the external token represents a person) and issues tokens for your project.

Use this grant when a partner IdP, enterprise workforce IdP, or cloud platform already authenticated the caller and you want to accept that JWT without a full authorization-code redirect.

How it works

  1. The external system (or cloud platform) issues a signed JWT for the user or workload.
  2. Your backend or the Inbound App client sends POST to /token with grant_type=urn:ietf:params:oauth:grant-type:jwt-bearer, client_id, client authentication, and assertion=<EXTERNAL_JWT>.
  3. Descope validates the JWT against trusted issuers configured on the Inbound App (JWT Bearer settings).
  4. If valid, Descope returns an access token (and optionally refresh and ID tokens). Scopes and Resource targeting still follow Policies and the request's scope / resource parameters.

Configure in the Console

Under Grant Types:

  • Enable JWT Bearer (confidential clients only; off by default).
  • Click Manage to add one or more trusted issuers (Issuer URL, JWKs URL, algorithms, optional UserInfo mapping).

Beta feature flag

Some projects also use the External Token Management section on the Inbound App. Contact Descope Support if you need that UI enabled.

For AWS / GCP workload tokens, see Using Descope with Workloads.

Implement

See Using Inbound Apps → External Token Management for issuer setup and curl examples.

Was this helpful?

On this page