https://descope.com logo
Join Slack
Powered by
# ask-a-descoper
  • a

    Alon Menczer

    04/09/2026, 8:55 AM
    Hey! I am using RBAC, we have some roles that are internal, and some that are external (users can see / control them) the user facing SSO configuration flow shows only the external ones - but i am not sure which configuration made that work Would love to understand that so that we don't make a mistake in the future Thanks
    d
    b
    • 3
    • 14
  • t

    Tohar Kubani

    04/09/2026, 11:25 AM
    Hey! we have a user that keeps getting E062901 all the time, he's only being able to login through 'forgot password' flow and then again, if he'll try to use that password he will get E062901 again. this only happens for this individual user and it happens on every device he tries.
    ✅ 1
    a
    • 2
    • 12
  • s

    Shay Gusin

    04/09/2026, 11:57 AM
    hi, how can I add idpgroups to the jwt token?
    ✅ 1
    d
    • 2
    • 3
  • o

    Oran Aviv

    04/10/2026, 11:43 AM
    Guys, i'm using nOTP with whatsapp, iphone users tell me it's not working, the url it opens uses the https://api.whatsapp.com/resolve/?deeplink.... link which doesnt works on iphones. it should use https://wa.me/.... any help?
    d
    m
    b
    • 4
    • 6
  • o

    Oran Aviv

    04/10/2026, 11:51 AM
    Also, i was trying to use magic link authenticator with the WhatsApp authenticator but it doesn't work. testing the connector shows successes but no messages has been sent. i verified the phone and WhatsApp number at the business center and WhatsApp manager is working. It seems magic link with WhatsApp is broken.
    ✅ 1
    d
    b
    • 3
    • 5
  • k

    Kirk Morales

    04/10/2026, 11:23 PM
    We use the Firebase authentication integration and look for the
    externalToken
    on the session when a user is sent back to us. If we don't get a token, is there a way to tell if it's because something went wrong with the integration or if it's just because the user doesn't exist? If the only time we wouldn't get it is if the user doesn't exist, that makes it easier, but we want to make sure we properly catch any errors in the integration as well. Thanks!
    ✅ 1
    d
    • 2
    • 1
  • s

    Shahar Danus

    04/12/2026, 8:19 AM
    Hey folks, how are you? By your recommendation we've added a process of exporting all our projects (with settings, tenants, flows, etc) Our gaps are things like SSO settings, etc which requires Access key with Full access - and we don't want an access key which is over privileged. What are our options?
    m
    b
    • 3
    • 7
  • b

    Bruce Cloud

    04/12/2026, 11:53 PM
    We are attempting to integrate a legacy client-server application with data from an analytics provider who requires a user-specific OIDC token in order to provide authorization and auditing in their database. The client-server application is performing a secure, but proprietary, login. The user is successfully identified by this process, but no token is produced. Are there any ways that Descope can help us bridge this gap? Thanks
    m
    t
    • 3
    • 10
  • a

    Anand Sheth

    04/13/2026, 6:24 AM
    Hello - I am hitting a problem. I've added a Generic HTTP connector (POST) step to my sign-up-or-in flow. The step is configured with async=true, a custom header, and a JSON payload using flow context variables (user.userId, user.tenantIds, sourceIP). The step is wired between the "Is new user?" condition (existing user path) and the "End" (logged-in) step. The flow completes successfully and the user gets a session, but the HTTP connector never fires — our server receives no request. When I tried placing the step on the magic link polling path, I got nonce validation errors: [E108201] Error validating flow nonce: Request sequence validation failed Questions: 1. Where in the flow can an HTTP connector step be placed without breaking nonce validation? 2. Is there a flow execution log that shows whether the connector step was attempted and what error occurred? 3. Does async=true on a connector step actually execute the request, or does it skip it? Also, I reverted back to your version of the sign up and sign in flow..and the nonce errors keep going every few seconds. how do I stop this?
    ✅ 1
    m
    d
    a
    • 4
    • 9
  • u

    Uday Singh

    04/13/2026, 8:07 AM
    I'm using email/phone field but for phone is unable to take input, it going to reset again and again cc: @Atharva Joshi
    Screen Recording 2026-04-13 at 1.35.38 PM.mov
    d
    a
    a
    • 4
    • 10
  • s

    Sharan

    04/13/2026, 10:04 AM
    Hi team, I’m currently using the “sign-up-or-in-passwords” flow in Descope. Right now, I can only test it using the Run button in the dashboard. Is there a way to generate a direct URL so I can access and test this flow from a different browser?
    ✅ 1
    d
    • 2
    • 1
  • d

    David Hanway

    04/13/2026, 11:39 AM
    Hi All, I want to fire off a Hubspot notification when a user is created/deleted and need access to the user's email, name and family name. Looks like Management Flows are the way to go to achieve this. My preference is to leverage the Event Triggers in descope rather than trigger a management flow myself from our backend. My question: In the "Start" step of a management flow, i've selected "Enable Event Triggers" and it should trigger on the Event Type "User Created". What does the "Start" step pass on as an output to following steps? I can't seem to find it documented anywhere. Thanks
    ✅ 1
    m
    t
    • 3
    • 4
  • i

    Itai Ben Natan

    04/13/2026, 12:15 PM
    Hey, I have a customer with SSO configured through our Descope integration, using Azure AD (Entra ID) as their IdP with SCIM provisioning enabled. When Azure attempts to validate SCIM authorization, it's hitting:
    Copy code
    GET <https://api.descope.com/scim/v2/Users?filter=userName+eq+>"<REDACTED_USER_ID>"
    And receiving the following error response:
    Copy code
    json
    {
      "errorCode": "E111005",
      "errorDescription": "Management key does not match project",
      "errorMessage": "Invalid permission in request, access key must be associated with the correct permission for this action"
    }
    HTTP Status: 401 Unauthorized Our questions: 1. What is the correct SCIM base URL format we should be providing to customers for Azure AD provisioning — should it include the Descope Project ID as a path suffix? 2. What exact permissions does the management key need to have for SCIM provisioning to work? 3. Is SCIM provisioning enabled per-tenant or at the project level, and what does that configuration look like on your end? 4. Is there a way on the Descope console to verify whether a given SCIM token is valid and associated with the correct project, without having to regenerate it? Thanks
    ✅ 1
    d
    d
    • 3
    • 5
  • m

    Mateusz Mecina

    04/13/2026, 12:58 PM
    Hello, We are integrating Descope as the identity layer for our platform. In addition to our primary environment, we run a
    sandbox
    environment: a separate application and database that mirrors production for safe testing. What we want to achieve 1. Strong isolation: A JWT issued for the sandbox environment must not be accepted by our production API (and ideally vice versa if we ever need symmetric rules). Users should not be able to call production backends using a sandbox-oriented token. 2. Smooth UX: After the user signs in to the main environment, we want them to switch to the sandbox context without a full interactive login (e.g. silent OIDC / refresh-style flow), while still ending up with credentials that are clearly scoped to sandbox. Current approach We are experimenting with two OAuth applications in Descope (separate client IDs/secrets): one for production and one for sandbox, with a silent authorization request for the sandbox client. We would like to confirm the recommended Descope pattern for this: 1. Is it valid and supported to keep one Descope project (and one tenant) and achieve isolation via multiple OAuth clients and/or custom claims / audiences? 2. Alternatively, should sandbox be modeled as a separate project or tenant, or another mechanism, to guarantee token separation? 3. What is the best way to ensure tokens are cryptographically or semantically bound to “production” vs “sandbox” so our resource servers can reject cross-environment tokens reliably? Thank you. cc: @Steffen Hanikel
    a
    s
    • 3
    • 8
  • o

    Oren Pinkas

    04/13/2026, 2:40 PM
    Hi team, how can i invite my colleagues to the project so they can also take action in the Descope console?
    ✅ 1
    d
    a
    • 3
    • 2
  • o

    Omer Bialer

    04/13/2026, 9:11 PM
    Hi - I got a question :) I’m currently fetching your JWKS endpoint every 5 minutes in order to cache the keys for token verification and I want to build a condition to verify the JWKS response was valid before caching it. Any tips on how to do that? anything else i should do beside verifying the 200 status? Thanks!
    ✅ 1
    d
    • 2
    • 1
  • m

    Meir Armon

    04/14/2026, 9:10 AM
    Hey, We had the ability to merge users that were first created by magic link and then logged in via SSO, as well as first SSO and then magic link. If I recall, it was an issue of a feature flag. This appears to be broken now for us, is there any way to look into it?
    ✅ 1
    m
    r
    • 3
    • 12
  • e

    elad mamdon

    04/14/2026, 10:47 AM
    Hey there, I am tring to add authenticator to the login process but from some reason the authenticator doesnt succeed to sca the QR, what can cause this problem?
    ✅ 1
    d
    m
    • 3
    • 2
  • s

    Sapir

    04/14/2026, 11:21 AM
    Hey, I’m unable to edit the "Tenant admin" role in my project. When I try, I only see the “Duplicate” option, even though the docs says editing should be possible. Could you please help?
    ✅ 1
    d
    a
    • 3
    • 2
  • a

    Amir Wollman

    04/14/2026, 2:21 PM
    I have an issue with sign in flows. I tried adding CIDR Whitelist and Blacklist, then added nested flows verifying these tenant scoped attributes exist on a tenant, and if so - verify ip is (or not) in the respective list before approving. When I test the flow from flows UI in Descope - it works as expected. When I run it from the app - it does not work. I followed this guide: https://docs.descope.com/flows/conditions/ipaddress But a. its confusing in relation to ipAddress VS sourceIP usage, b. neither works... I verified my UI uses the correct flow by changing a screen in the flow and saw it propagated to the UI in auth flow. Any ideas?
    m
    d
    • 3
    • 14
  • a

    Anand Sheth

    04/14/2026, 3:50 PM
    Create a new one cause the old thread it appears this question is not being answered. I've added a Generic HTTP connector (POST) step to my sign-up-or-in flow. The step is configured with async=true, a custom header, and a JSON payload using flow context variables (user.userId, user.tenantIds, sourceIP). The step is wired between the "Is new user?" condition (existing user path) and the "End" (logged-in) step. The flow completes successfully and the user gets a session, but the HTTP connector never fires — our server receives no request. When I tried placing the step on the magic link polling path, I got nonce validation errors: [E108201] Error validating flow nonce: Request sequence validation failed Questions: 1. Where in the flow can an HTTP connector step be placed without breaking nonce validation? 2. Is there a flow execution log that shows whether the connector step was attempted and what error occurred? 3. Does async=true on a connector step actually execute the request, or does it skip it?
    c
    r
    • 3
    • 2
  • s

    Shira Lev

    04/15/2026, 7:04 AM
    Hi, We're looking to tighten access controls on our Descope console and had a couple of questions: 1. SSO for console login — Is it possible to configure SSO (Google Workspace) for Descope console users (Descopers), and can roles be scoped per-project through SSO group mapping? 2. Programmatic role management — Is there an API to assign/revoke Descoper roles (specifically Project Developer) programmatically? We're looking to implement JIT access where a developer gets temporary Developer permissions on a specific project for a defined time window. 3. SSO blast radius — If we enable SSO for console access, does it have any effect on tenants or the general authentication flows configured within our projects, or is it strictly isolated to console login? 4. JIT option in SSO setup — While exploring the SSO configuration at the company level, I noticed a JIT configuration option but couldn't find any documentation on it. Could you explain what it does and whether it's relevant for managing Descoper access? Thanks!
    d
    • 2
    • 6
  • o

    Oren Pinkas

    04/15/2026, 1:17 PM
    Hi Descope team! I’m integrating with AWS ALB via OIDC. Since the ALB handles the flow, it forwards the Access Token in the headers but not the ID Token. I need to trigger a logout, but your standard logout endpoint seems to require the
    id_token_hint
    . Is there a way to perform a logout using only the Access Token, or perhaps an alternative endpoint that doesn't require the ID token hint? Thanks!
    ✅ 1
    d
    a
    • 3
    • 5
  • s

    Shy

    04/15/2026, 2:34 PM
    Hey, can I get support from someone in a private DM?
    ✅ 1
    d
    n
    • 3
    • 2
  • n

    Noel

    04/16/2026, 12:23 PM
    Hi. AI isn't enough to answer my question as it doesn't seem to take into account (1) that this sub-flow works as expected on any other browser (2) that the passkey is defined right before we try to use it and (3) the screenshot. Would you have a better idea of what could cause this? https://authtown.slack.com/archives/C07P7AN1EQH/p1776272802745549
    ✅ 1
    d
    r
    • 3
    • 3
  • g

    Gal Rosenberg

    04/16/2026, 2:38 PM
    Hey there I coudlnt get a relevant answer using the AI. An existing client connected okta sso and now my audit webhook connector no audit logs of their tenant appear in the coralogix that is connected to the webhook connector. Other tenants still appear as expected, and I see LoginSucceed Events in the descope audit log. And I did get the audit logs events from them before they setup the sso Is there any reason the sso would stop it from working?
    ✅ 1
    d
    a
    • 3
    • 8
  • s

    Shahar Danus

    04/16/2026, 2:59 PM
    Hi guys, we've implemented the welcome back flow (on sign in), but after the page is open for some time, users clicking sign in in welcome back screen and either redirected to magic link flow and getting errors, or either getting this errors:
    Copy code
    Failed to exchange OAuth code
    What are our options to fix this ? Thanks
    ✅ 1
    a
    • 2
    • 1
  • k

    Kevin Ross

    04/16/2026, 3:02 PM
    Hidden screen components were working - yesterday - now they aren’t. I’m simply statically hiding buttons. I tried a few other values including providing them as a
    form
    value but no change. Is this a known bug today?
    d
    a
    • 3
    • 3
  • a

    Anson Geisel

    04/16/2026, 6:27 PM
    on the profile widget, if a user updates phone number to same number the flow fires off the verify with otp, I want to stop this and only proceed if the number really changes
    ✅ 1
    c
    b
    • 3
    • 13
  • c

    Chris Carper

    04/16/2026, 8:14 PM
    How can I integrate Descope into my react app?
    ✅ 1
    d
    • 2
    • 10