Authorization Series — Pt 2: Securing HTTP APIs with RBAC rules

In this article, you will learn how you can leverage Auth0’s RBAC (Role-Based Access Control) feature to handle end-user authorization in your APIs.

Nice article, thanks! One question though: the application you use to demo the access control talks to multiple APIs (expense, invoice and vacation). As far as I understand it, this is not something the current SPA SDK (auth0-spa-js) supports, it only accepts a single string for the audience parameter. Would you mind sharing how you accomplished this functionality? And is auth0-spa-js going to get support for dealing with multiple APIs?