
SahasS.60259 (Customer) asked a question.
We use Okta as user store. Other information necessary for authorization (ie. who can do what) exist outside of Okta but information can be access via RESTful APIs. We would like to follow OIDC claims model where scopes are embedded part of the token. Based on my reading, Okta has plenty of guidance to achieve this if all the data is within Okta. Is it possible to create okta tokens with scopes from external system?

Hi Sahas,
Thank you for posting your inquiry to Okta Support Community Portal. Are you using Okta's Authorization Server or a Custom Authorization Server ?
https://developer.okta.com/docs/api/resources/oidc#scopes
https://developer.okta.com/authentication-guide/implementing-authentication/set-up-authz-server
Since this matter needs further investigation, I suggest opening a Support case with our developers team at developers@okta.com and we would be happy to assist.
Best Regards,
Daniel