i have identity server that provide access token to the login user and api(multiple) that have bearer token authentication but in case of authorization I need to know how to authorize user by using user permissions and not only client scopes. the issue here is to load those permisions from authorization server independent from identity server because user might have to many permissions that can not be added into access token through IProfileService. I tried to add those permission into access token but it caused the token to be too large and request header has limitation of 8kb and 16kb in IIS server. I was thinking of using IDistributedCache for sharing user permissions but I dont think it is a better solution.