DEV Community

realNameHidden
realNameHidden

Posted on

How exactly would you validate the OAuth scope in Apigee? Which policy or condition would you use?

Use the OAuthV2 policy with the VerifyAccessToken operation and specify the required scope using the element.

For example, suppose your API requires:

payment.read

Enter fullscreen mode Exit fullscreen mode

Configure:

<OAuthV2 name="VerifyPaymentScope">
    <Operation>VerifyAccessToken</Operation>
    <Scope>payment.read</Scope>
    <GenerateResponse enabled="true"/>
</OAuthV2>

Enter fullscreen mode Exit fullscreen mode

What happens?
Suppose the access token contains:

scope = payment.read payment.write

Enter fullscreen mode Exit fullscreen mode

Request:

GET /payments
Authorization: Bearer <access_token>

Enter fullscreen mode Exit fullscreen mode

Apigee checks:

Is token valid?       → Yes
Does token have
payment.read?         → Yes
                         ↓
                      Continue

Enter fullscreen mode Exit fullscreen mode

If the token only contains:

scope = payment.write

Enter fullscreen mode Exit fullscreen mode

then the scope requirement fails and Apigee returns a 403 with the InsufficientScope fault.

Important: Where would you put the policy?
If all APIs require OAuth validation, put VerifyAccessToken in the ProxyEndpoint PreFlow.

If different resources require different scopes, create conditional flows and put the appropriate policy in each flow. Google’s documentation specifically describes this pattern.

For example:

<Flow name="GetPayment">
    <Condition>
        (proxy.pathsuffix MatchesPath "/payments")
        and (request.verb = "GET")
    </Condition>

    <Request>
        <Step>
            <Name>VerifyPaymentReadScope</Name>
        </Step>
    </Request>
</Flow>

Enter fullscreen mode Exit fullscreen mode

And:

<OAuthV2 name="VerifyPaymentReadScope">
    <Operation>VerifyAccessToken</Operation>
    <Scope>payment.read</Scope>
</OAuthV2>

Enter fullscreen mode Exit fullscreen mode

So you can have:

GET /payments
      ↓
payment.read

POST /payments
      ↓
payment.write

POST /payments/refund
      ↓
payment.refund

Enter fullscreen mode Exit fullscreen mode

⚠️ Very important interview detail
If you specify multiple scopes:

<Scope>payment.read payment.write</Scope>

Enter fullscreen mode Exit fullscreen mode

Apigee’s VerifyAccessToken policy treats them as OR, not AND.

So:

Token has payment.read
        ↓
       PASS ✓

Token has payment.write
        ↓
       PASS ✓

Enter fullscreen mode Exit fullscreen mode

If you need both scopes, use separate VerifyAccessToken policies, each requiring one scope.

⭐ Perfect interview answer

I would validate the OAuth scope using the OAuthV2 policy with the VerifyAccessToken operation. I would specify the required scope in the element. For example, if an endpoint requires payment.read, I configure payment.read. Apigee first validates the access token and then checks whether the token contains the required scope. If the scope is present, the request continues; otherwise, Apigee rejects the request with an insufficient-scope error, typically HTTP 403. If different resources require different scopes, I would use conditional flows and attach different VerifyAccessToken policies to those flows.

Top comments (0)