Decides which audiences an access token is addressed to and which scopes it
carries for them (sections 2.2.3 and 3, as one decision).
Refuses scopes naming two APIs, a scope naming an API the request did not
address, and an ordinary scope on a token with several audiences; strips
OpenID Connect scopes from a token for an API.
Parameters
input: any
the classified request: ownResource, explicit audiences
and one row per scope
Decides which audiences an access token is addressed to and which scopes it carries for them (sections 2.2.3 and 3, as one decision).
Refuses scopes naming two APIs, a scope naming an API the request did not address, and an ordinary scope on a token with several audiences; strips OpenID Connect scopes from a token for an API.