...
The table below covers the metadata parameters that a Client publishes in its oauth_client metadata, in addition to those in Section 3. The parameters are defined in Section 2 of [RFC7591], and profiled by Section 2.2.2 of [Ena.OAuth2]. This version of the document covers Clients that use the client_credentials grant, which is the grant type that [BAS.Rules] permits. Parameters that apply only to other grant types, such as redirect_uris, require_signed_request_object and require_pushed_authorization_requests, are therefore not used. The token_endpoint_auth_signing_alg parameter defined by [OpenID.Registration] is not used either, since a Client in BAS does not declare the algorithm it signs with, see Section 4.2.
Parameter | Description | Requirement | Defined in |
|---|---|---|---|
token_endpoint_auth_method | The method by which the Client authenticates at the token endpoint of an Authorization Server. The value MUST be private_key_jwt, see Section 4.2. | REQUIRED. Constrained by the Trust Anchor metadata policy. | Section 2 of [RFC7591] and Section 2.2.2.2 of [Ena.OAuth2] |
jwks | The Client's JSON Web Key Set, included by value. The Client MUST publish its keys using either jwks or jwks_uri, but not both, see Section 2.2.2.4 of [Ena.OAuth2]. The keys MUST meet the requirements of [BAS.Security]. | REQUIRED, unless jwks_uri is used. | Section 2 of [RFC7591] and Section 5.2.1 of [OpenID.Federation] |
jwks_uri | A URL from which the Client's JSON Web Key Set can be retrieved. The URL MUST use the HTTPS scheme. The keys MUST meet the requirements of [BAS.Security]. | REQUIRED, unless jwks is used. | Section 2 of [RFC7591] and Section 5.2.1 of [OpenID.Federation] |
grant_types | The grant types that the Client uses. The value MUST contain client_credentials. Without this parameter, [RFC7591] and [Ena.OAuth2] assume the authorization_code grant type. | REQUIRED. Constrained by the Trust Anchor metadata policy to the grant types that [BAS.Rules] permits. | Section 2 of [RFC7591] and Section 2.2.2.3 of [Ena.OAuth2] |
redirect_uris | Array of redirection URIs for use in redirect-based flows | REQUIRED if the client is registered for the authorization_code grant type | Section 2 of [RFC7591] and Section 2.2.2.1 of [Ena.OAuth2] |
response_types | The response types that the Client uses. The value MUST be an empty array, since the client_credentials grant uses no response type. Without this parameter, [RFC7591] assumes the code response type. | REQUIRED. Assigned by the Trust Anchor metadata policy. OPTIONAL for the Client to supply. | Section 2 of [RFC7591] |
client_name | A human-readable name of the Client, provided in Swedish and English, see Section 2. If display_name is not supplied, its value is taken from client_name, see Section 3. | OPTIONAL | Section 2 of [RFC7591] and Section 2.2.2.6 of [Ena.OAuth2] |
scope | The scope values that the Client can use when requesting access tokens. The values are agreed between the parties to an exchange, see Section 1.3. | OPTIONAL | Section 2 of [RFC7591] and Section 2.2.2.5 of [Ena.OAuth2] |
dpop_bound_access_tokens | Whether the Client always uses DPoP [RFC9449] when requesting access tokens. A Client that does so MUST set this parameter to true. | OPTIONAL | Section 5.2 of [RFC9449] and Section 2.2.2.7 of [Ena.OAuth2] |
tls_client_certificate_bound_access_tokens | Whether the Client requests access tokens bound to its TLS client certificate [RFC8705]. A Client that does so MUST set this parameter to true. | OPTIONAL | Section 3.4 of [RFC8705] and Section 2.2.2.7 of [Ena.OAuth2] |
Table 2: Client metadata parameters.
...