Olympus Docs
ReferenceScopes

role

Custom single-string role claim. `admin`, `user`, etc.

OAuth2 scope: role

Source: Olympus convention

Description

Custom single-string role claim. admin, user, etc.

Requesting this scope

In the authorization URL:

GET /oauth2/auth?
  &scope=role
  ...

Multiple scopes are space-separated.

Granting access

A client only receives this scope if it's on the client's allowed scope list. Configure in Athena → OAuth2 Clients → your client → Allowed Scopes.

Checking in your backend

The access token's scope claim contains the granted scopes:

const granted = info.scope?.split(" ") ?? [];
if (!granted.includes("role")) return 403;

On this page