Best way to limit access of Portal created applications

I got a rather big API imported that I would like to “slice” somehow. Hence I created a couple of scopes matching my slices. That works quite well.

However, I don’t understand how this is supposed to work when applications are created via the Developer Portal. The whole concept only works when the API provider has control over the OAuth server, doesn’t it? As I see it I have to way to force a consumer to limit their access scope.

Is there no other way to limit access to an API? I was hoping for a scope mapping in API packages or something like this.

How do you usually do this?

Cheers, Christoph

Hi @Christoph_Souris ,
Please refer below article. it talks about how the API access can be restricted using communities.

Vikash Sharma