Hooks and id_token

Where do these permissions come from? Are you using Auth0’s RBAC core feature?
Another question: why do you need the permissions in the ID token and not the access token?

This might be a helpful post:

1 Like