Purpose, protect api method, check token has scope.
Identityserver4, you can validate scope, as shown here https://docs.identityserver.io/en/3.1.0/topics/apis.html
How do you validate scope in openiddict?
Purpose, protect api method, check token has scope.
Identityserver4, you can validate scope, as shown here https://docs.identityserver.io/en/3.1.0/topics/apis.html
How do you validate scope in openiddict?
The validation in an API service, is done in the authorization handler/middleware in the ASP.NET Core request pipeline and it is independent of the identity provider you use. It's configured using the AddAuthorization method as shown in the page you linked to.
Sure, you have to configure the client and identity provider to provide the appropriate scopes, claims, that's a different question.