Ref: https://community.auth0.com/t/configuring-scopes-for-already-authorised-client-easy-when-you-know-how/22043 I found the docs the user was looking for in the architecture scenarios (link below), but would useful if this info was available in generic form directly under, say, https://auth0.com/docs/microsites/protect-api/protect-api. https://auth0.com/docs/architecture-scenarios/server-api/part-2#configure-application-s-access-to-the-api