Descope signs users in through a federated OpenID Connect application. Authdog uses the project's OIDC endpoints. The client ID is the Descope project ID.

## Copy the redirect URI

In the [Authdog console](https://console.authdog.com), select the project and environment, open **Authentication > Providers**, find **Descope**, and click **Enable**. Copy the redirect URI shown in the form:

```url
https://identity.authdog.com/api/v1/callback/<connectionId>
```

## Create the application

1. In the Descope console, open the project and create an OIDC application that accepts a client secret (`client_secret_post`).
2. Set the redirect URI to the value copied from Authdog.
3. Grant the scopes `openid`, `profile`, and `email`.
4. Copy the **Project ID** (this is the client ID) and the **client secret**.
5. Note the API host for the project. The default is `https://api.descope.com`. A regional project uses a host such as `https://api.euc1.descope.com`. That host is the Domain URI.

## Configure Authdog

| Field | Value |
| --- | --- |
| **Client ID** | The Descope project ID |
| **Client Secret** | The client secret from the OIDC application |
| **Domain URI** | The API host, e.g. `https://api.descope.com` |

Save, then toggle the connection **active**.

## What Descope returns

Authdog requests the `openid profile email` scopes and reads the profile from `<API host>/oauth2/v1/userinfo`.

The userinfo endpoint returns `sub`, name, and email claims for the authenticated user.

Paste the API host only. Do not include `/oauth2/v1/authorize`.

## Test it

1. Open your environment's hosted sign-in page, or link to `https://identity.authdog.com/api/v1/signin/<connectionId>`.
2. Select the Descope button and complete the flow.
3. Confirm the user appears under **Users** in the console with a Descope identity linked.

## Troubleshooting

| Symptom | Cause |
| --- | --- |
| `invalid_client` | The client ID is not the project ID, or the secret belongs to another application |
| Redirect or callback URL error | The URI registered with Descope does not match Authdog's exactly |
| 404 on authorize | The Domain URI includes a path, or the region host is wrong |
| Works in one environment only | Each environment has its own `connectionId`, and so its own redirect URI to register |

## Related

| Read | To learn how to |
| --- | --- |
| [Connectors](/docs/connectors) | Set up any other social provider |
