Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Parameter

Description

Requirement

Defined in

issuer

The issuer identifier of the Authorization Server. The value MUST be equal to the Authorization Server's Entity Identifier, see Section 5.1.3 of [OpenID.Federation.Connect], and MUST meet the requirements of Section 3.1.1.1 of [Ena.OAuth2].

REQUIRED

Section 2 of [RFC8414] and Section 3.1.1.1 of [Ena.OAuth2]

token_endpoint

The URL of the token endpoint.

REQUIRED

Section 2 of [RFC8414] and Section 3.1.1.2 of [Ena.OAuth2]

jwks_uri

A URL from which the Authorization Server's JSON Web Key Set can be retrieved. The URL MUST use the HTTPS scheme. The keys MUST meet the requirements of [BAS.Security].

REQUIRED

Section 2 of [RFC8414] and Section 3.1.1.3 of [Ena.OAuth2]

grant_types_supported

The grant types that the Authorization Server supports. The value MUST contain client_credentials. Without this parameter, [Ena.OAuth2] assumes the authorization_code grant type.

REQUIRED. Constrained by the Trust Anchor metadata policy to the grant types that [BAS.Rules] permits.

Section 2 of [RFC8414] and Section 3.1.1.5 of [Ena.OAuth2]

response_types_supported

The response types that the Authorization Server supports. The value is not constrained within BAS, since the client_credentials grant uses no response type.

REQUIRED

Section 2 of [RFC8414]

token_endpoint_auth_methods_supported

The client authentication methods that the token endpoint supports. The value MUST be private_key_jwt only, see Section 2 of [BAS.Security].

REQUIRED. Constrained by the Trust Anchor metadata policy.

Section 2 of [RFC8414] and Section 3.1.1.6 of [Ena.OAuth2]

token_endpoint_auth_signing_alg_values_supported

The signature algorithms that the token endpoint supports for private_key_jwt. See Section 3.1 of [BAS.Security].

REQUIRED. Constrained by the Trust Anchor metadata policy.

Section 2 of [RFC8414] and Section 3.1.1.7 of [Ena.OAuth2]

scopes_supported

The scope values that the Authorization Server supports. The values are agreed between the parties to an exchange, see Section 1.3.

REQUIRED

Section 2 of [RFC8414] and Section 3.1.1.4 of [Ena.OAuth2]

revocation_endpoint

The URL of the revocation endpoint.

OPTIONAL

Section 2 of [RFC8414]

revocation_endpoint_auth_methods_supported

The client authentication methods that the revocation endpoint supports. The value MUST be private_key_jwt only, see Section 2 of [BAS.Security].

REQUIRED if revocation_endpoint is present. Constrained by the Trust Anchor metadata policy.

Section 2 of [RFC8414] and Section 3.1.1.6 of [Ena.OAuth2]

revocation_endpoint_auth_signing_alg_values_supported


Signing algorithms supported by this endpoint for the signature on the JWT, when used with private_key_jwt client authentication.

REQUIRED if revocation_endpoint is present. Constrained by the Trust Anchor metadata policy.

Section 2 of [RFC8414] and Section 3.1.1.7 of [Ena.OAuth2]

introspection_endpoint

The URL of the introspection endpoint.

OPTIONAL

Section 2 of [RFC8414]

introspection_endpoint_auth_methods_supported

The client authentication methods that the introspection endpoint supports. The value MUST be private_key_jwt only, see Section 2 of [BAS.Security].

REQUIRED if introspection_endpoint is present. Constrained by the Trust Anchor metadata policy.

Section 2 of [RFC8414] and Section 3.1.1.6 of [Ena.OAuth2]

introspectionrevocation_endpoint_auth_signing_alg_methodsvalues_supported

Signing algorithms supported by this endpoint for the signature on the JWT, when used with private_key_jwt client authentication.

REQUIRED if introspection_endpoint is present. Constrained by the Trust Anchor metadata policy.

Section 2 of [RFC8414] and Section 3.1.1.7 of [Ena.OAuth2]

dpop_signing_alg_values_supported

The signature algorithms that the Authorization Server supports for DPoP proofs. An Authorization Server that supports DPoP MUST publish this parameter.

REQUIRED if DPoP is supported.

Section 5.1 of [RFC9449] and Section 3.1.1.10 of [Ena.OAuth2]

tls_client_certificate_bound_access_tokens

Whether the Authorization Server supports access tokens bound to TLS client certificates.

OPTIONAL

Section 3.3 of [RFC8705] and Section 3.1.1.10 of [Ena.OAuth2]

mtls_endpoint_aliases

Alternative endpoints for use with mutual TLS.

OPTIONAL

Section 5 of [RFC8705] and Section 3.1.1.10 of [Ena.OAuth2]

protected_resources

The resource identifiers of the Protected Resources that the Authorization Server issues access tokens for.

RECOMMENDED

Section 4 of [RFC9728] and Section 3.1.1.10 of [Ena.OAuth2]

...