Openiddict - Validating scope, protect api

Viewed 646
1 Answers

The validation in an API service, is done in the authorization handler/middleware in the ASP.NET Core request pipeline and it is independent of the identity provider you use. It's configured using the AddAuthorization method as shown in the page you linked to.

Sure, you have to configure the client and identity provider to provide the appropriate scopes, claims, that's a different question.

Related