Use OAuth resource indicators with identity domains
- Services: IAM
- Release Date: October 07, 2026
Identity domains now support OAuth resource indicators. In a token request, an OAuth client can use the resource parameter to identify the target resource server and the required scope parameter to request permissions. The requested scopes must be allowed for the client and belong to the selected resource server.
When a request specifies resource, scopes can be literals or fully qualified scopes. The access token's aud claim reflects the resource application's configured audience, or the resource value if no audience is configured. For more information, see OAuth Resource Indicators.