Hi @zschaffter,
You can add additional scopes via the /authorize
endpoint using the connection_scope
parameter. Please review this document which will demonstrate further: Add Scopes/Permissions to Call Identity Provider APIs
Let me know if that helps!
Thanks,
Mary Beth