Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Parameter

Description

Requirement

Defined in

resource

The resource identifier of the Protected Resource, see Section 6.1.

REQUIRED

Section 2 of [RFC9728] and Section 4.3 of [Ena.OAuth2]

authorization_servers

The issuer identifiers of the Authorization Servers that issue access tokens for the Protected Resource. The value MUST contain the Entity Identifier of at least one Authorization Server in BAS.

OPTIONAL

Section 2 of [RFC9728]

jwks_uri

A URL from which the Protected Resource's JSON Web Key Set can be retrieved. The URL MUST use the HTTPS scheme. The keys MUST meet the requirements of [BAS.Security].

OPTIONAL

Section 2 of [RFC9728] and Section 5.2.1 of [OpenID.Federation]

resource_name

A human-readable name of the Protected Resource, provided in Swedish and English, see Section 2. If display_name is not supplied, its value is taken from resource_name, see Section 3.

OPTIONALRECOMMENDED

Section 2 of [RFC9728]

scopes_supported

The scope values that the Protected Resource uses. The values are agreed between the parties to an exchange, see Section 1.3.

RECOMMENDED

Section 2 of [RFC9728]

bearer_methods_supported

The methods by which the Protected Resource accepts access tokens. If present, the value MUST include header and body, see Section 4 of [Ena.OAuth2].

OPTIONAL

Section 2 of [RFC9728]

dpop_bound_access_tokens_required

Whether the Protected Resource requires DPoP-bound access tokens. A Protected Resource that does so MUST set this parameter to true.

OPTIONAL

Section 2 of [RFC9728]

dpop_signing_alg_values_supported

The signature algorithms that the Protected Resource supports for DPoP proofs. A Protected Resource that supports DPoP MUST publish this parameter.

OPTIONAL

Section 2 of [RFC9728]

tls_client_certificate_bound_access_tokens

Whether the Protected Resource supports access tokens bound to TLS client certificates. A Protected Resource that requires such tokens MUST set this parameter to true.

OPTIONAL

Section 2 of [RFC9728]

...