Use the OAuthV2 policy with the VerifyAccessToken operation and specify the required scope using the element.
For example, suppose your API requires:
payment.read
Configure:
<OAuthV2 name="VerifyPaymentScope">
<Operation>VerifyAccessToken</Operation>
<Scope>payment.read</Scope>
<GenerateResponse enabled="true"/>
</OAuthV2>
What happens?
Suppose the access token contains:
scope = payment.read payment.write
Request:
GET /payments
Authorization: Bearer <access_token>
Apigee checks:
Is token valid? → Yes
Does token have
payment.read? → Yes
↓
Continue
If the token only contains:
scope = payment.write
then the scope requirement fails and Apigee returns a 403 with the InsufficientScope fault.
Important: Where would you put the policy?
If all APIs require OAuth validation, put VerifyAccessToken in the ProxyEndpoint PreFlow.
If different resources require different scopes, create conditional flows and put the appropriate policy in each flow. Google’s documentation specifically describes this pattern.
For example:
<Flow name="GetPayment">
<Condition>
(proxy.pathsuffix MatchesPath "/payments")
and (request.verb = "GET")
</Condition>
<Request>
<Step>
<Name>VerifyPaymentReadScope</Name>
</Step>
</Request>
</Flow>
And:
<OAuthV2 name="VerifyPaymentReadScope">
<Operation>VerifyAccessToken</Operation>
<Scope>payment.read</Scope>
</OAuthV2>
So you can have:
GET /payments
↓
payment.read
POST /payments
↓
payment.write
POST /payments/refund
↓
payment.refund
⚠️ Very important interview detail
If you specify multiple scopes:
<Scope>payment.read payment.write</Scope>
Apigee’s VerifyAccessToken policy treats them as OR, not AND.
So:
Token has payment.read
↓
PASS ✓
Token has payment.write
↓
PASS ✓
If you need both scopes, use separate VerifyAccessToken policies, each requiring one scope.
⭐ Perfect interview answer
I would validate the OAuth scope using the OAuthV2 policy with the VerifyAccessToken operation. I would specify the required scope in the element. For example, if an endpoint requires payment.read, I configure payment.read. Apigee first validates the access token and then checks whether the token contains the required scope. If the scope is present, the request continues; otherwise, Apigee rejects the request with an insufficient-scope error, typically HTTP 403. If different resources require different scopes, I would use conditional flows and attach different VerifyAccessToken policies to those flows.
Top comments (0)