support db policy like `@claims.scope contains @item.AllowedScopes` because in most access tokens `scp` (scope) claim has >1 value.