Define custom scopes
This guide explains how to define custom scopes on an application. A custom scope names one permission or capability of your service. Clients request the scopes that they need, and your service checks the scopes of the token.
Learning outcomes
- Add custom scopes to an application.
- Know how Casdoor validates the scopes that a client requests.
- Request several scopes with a pattern.
What you need
- An application with the category
Agent
About custom scopes
Custom scopes are available on applications with the category Agent. Typical uses are:
- An MCP server that defines a permission for each kind of resource
- An API that controls access to single endpoints or features
- A service with a fine-grained authorization model
Custom scopes extend the standard OpenID Connect (OIDC) scopes and don't replace them. The standard scopes stay available on every application. Casdoor lists the custom scopes in the discovery document of the application, at /.well-known/openid-configuration.
Add scopes
-
In the Casdoor admin console, open the edit page of the application.
-
Check that Category is
Agent. -
In Scopes, click Add and fill in the row:
Column