Descope signs users in through a federated OpenID Connect application. Authdog uses the project's OIDC endpoints. The client ID is the Descope project ID.
Copy the redirect URI
In the Authdog console, select the project and environment, open Authentication > Providers, find Descope, and click Enable. Copy the redirect URI shown in the form:
https://identity.authdog.com/api/v1/callback/<connectionId>Create the application
- In the Descope console, open the project and create an OIDC application that accepts a client secret (
client_secret_post). - Set the redirect URI to the value copied from Authdog.
- Grant the scopes
openid,profile, andemail. - Copy the Project ID (this is the client ID) and the client secret.
- Note the API host for the project. The default is
https://api.descope.com. A regional project uses a host such ashttps://api.euc1.descope.com. That host is the Domain URI.
Configure Authdog
| Field | Value |
|---|---|
| Client ID | The Descope project ID |
| Client Secret | The client secret from the OIDC application |
| Domain URI | The API host, e.g. https://api.descope.com |
Save, then toggle the connection active.
What Descope returns
Authdog requests the openid profile email scopes and reads the profile from <API host>/oauth2/v1/userinfo.
The userinfo endpoint returns sub, name, and email claims for the authenticated user.
Paste the API host only. Do not include /oauth2/v1/authorize.
Test it
- Open your environment's hosted sign-in page, or link to
https://identity.authdog.com/api/v1/signin/<connectionId>. - Select the Descope button and complete the flow.
- Confirm the user appears under Users in the console with a Descope identity linked.
Troubleshooting
| Symptom | Cause |
|---|---|
invalid_client |
The client ID is not the project ID, or the secret belongs to another application |
| Redirect or callback URL error | The URI registered with Descope does not match Authdog's exactly |
| 404 on authorize | The Domain URI includes a path, or the region host is wrong |
| Works in one environment only | Each environment has its own connectionId, and so its own redirect URI to register |
Related
| Read | To learn how to |
|---|---|
| Connectors | Set up any other social provider |