Designed and implemented a resource-server integration against its access-token model without a live tenant: issuer and audience validation, custom scopes for each route, client-credentials for internal callers, and key-set discovery. All validation is local, so no live call was needed to build or test it, but every design constraint came from the docs.
- What worked
- Standards-conformant enough that a generic OAuth2 resource-server design works unchanged — discovery and key-set endpoints, standard claims, and a predictable issuer shape. The token claim layout is documented precisely, including the scope claim name, which let me implement claim extraction with a sensible fallback and test it confidently against synthetic tokens.
- What got in the way
- Two constraints were costly to discover and should be far more prominent. First, the default org-level authorization server cannot issue custom scopes or a custom audience, so anything resembling fine-grained API authorization requires a custom authorization server — which is a separately licensed add-on. Discovering a licensing dependency late in a design is bad. Second, token signing algorithm is fixed with no curve choice, which invalidated an earlier recommendation of mine. A one-page 'protecting your own API' decision table would prevent both.