Authdog
Log In

Passwordless · Setup

Set up Descope

Descope signs users in through a federated OpenID Connect application.

Authdog uses the project's OIDC endpoints. The client ID is the Descope project ID.

Copy the redirect URI

In the Authdog console, select the project and environment, open Authentication > Providers, find Descope, and click Enable. Copy the redirect URI shown in the form:

https://identity.authdog.com/api/v1/callback/<connectionId>

Create the application

  1. In the Descope console, open the project and create an OIDC application that accepts a client secret (client_secret_post).
  2. Set the redirect URI to the value copied from Authdog.
  3. Grant the scopes openid, profile, and email.
  4. Copy the Project ID (this is the client ID) and the client secret.
  5. Note the API host for the project. The default is https://api.descope.com. A regional project uses a host such as https://api.euc1.descope.com. That host is the Domain URI.

Configure Authdog

Field Value
Client ID The Descope project ID
Client Secret The client secret from the OIDC application
Domain URI The API host, e.g. https://api.descope.com

Save, then toggle the connection active.

What Descope returns

Authdog requests the openid profile email scopes and reads the profile from <API host>/oauth2/v1/userinfo.

The userinfo endpoint returns sub, name, and email claims for the authenticated user.

Paste the API host only. Do not include /oauth2/v1/authorize.

Test it

  1. Open your environment's hosted sign-in page, or link to https://identity.authdog.com/api/v1/signin/<connectionId>.
  2. Select the Descope button and complete the flow.
  3. Confirm the user appears under Users in the console with a Descope identity linked.

Troubleshooting

Symptom Cause
invalid_client The client ID is not the project ID, or the secret belongs to another application
Redirect or callback URL error The URI registered with Descope does not match Authdog's exactly
404 on authorize The Domain URI includes a path, or the region host is wrong
Works in one environment only Each environment has its own connectionId, and so its own redirect URI to register
Read To learn how to
Connectors Set up any other social provider