...
Metadata | Description | Requirement | Defined in | Comment |
|---|---|---|---|---|
issuer | MUST be a globally unique URL. | REQUIRED | [RFC8414], REQUIRED | |
grant_types_supported | Supported Grant Types | OPTIONAL If the parameter is omitted, the default value SHALL be [ "authorization_code" ]. | [RFC8414], OPTIONAL, ["authorization_code", "implicit"] is default if not present | Note: [Ena.OAuth]: If the parameter is omitted, the default value SHALL be "authorization_code" Could it be a risk to change the default of the standard? |
token_endpoint | Endpoint for requesting access tokens | REQUIRED | [RFC8414], REQUIRED | |
token_endpoint_auth_methods_supported | Client authentication methods supported by the token endpoint. | REQUIRED and MUST include private_key_jwt. | [RFC8414] OPTIONAL, client_secret_basic is default if not present | In line with the security requirements |
token_endpoint_auth_signing_alg_values_supported | JWS signing algorithms for client authentication supported by the token endpoint. | REQUIRED | [RFC8414] REQUIRED when private_key_jwt is used. | |
scopes_supported | scopes supported by the authorization server | REQUIRED | [RFC8414] , RECOMMENDED [Ena.OAuth] | What is the rationale for this sharper requirement in Ena.OAuth? |
dpop_signing_alg_values_supported | JWS algorithms supported for DPoP proof JWTs. | RECOMMENDED | [Ena.OAuth] | |
authorization_response_iss_parameter_supported | indicates whether the authorization server supports including the issuer parameter in authorization responses to protect against Authorization Server Mix-Up Attacks | SHOULD OPTIONAL? | [RFC9207] [Ena.OAuth] | issuer is already required, so this could be OPTIONAL because this is only an indication? |
jwks | The Entity's JSON Web Key Set, representing the Entity's protocol keys, included by value in the metadata. | REQUIRED if jwks_uri is not provided | [OpenID.Fed] | [Ena.OAuth], and [RFC8414] Not supported? |
jwks_uri | URL referencing a JWK Set document containing the Entity's protocol keys for that Entity Type | REQUIRED if jwks is not provided | [OpenID.Fed] [RFC8414] [Ena.OAuth] | [Ena.OAuth] has this as the only option - why? |
signed_jwks_uri | URL referencing a signed JWT having the Entity's JWK Set document, representing the Entity's protocol keys for that Entity Type as its payload | OPTIONAL | [OpenID.Fed] | [Ena.OAuth], and [RFC8414] Not supported? |
Below is ONLY applicable IF the corresponding features are supported. | ||||
authorization_endpoint | URL of the authorization server's authorization endpoint | REQUIRED IF authorization code grant type is supported. | [RFC8414] REQUIRED | Out of cope for SIB BAS Step 1, but should be included. |
code_challenge_methods_supported | PKCE [RFC7636] code challenge methods supported | REQUIRED IF authorization code grant type is supported. | [RFC8414] OPTIONAL [Ena.OAuth] | |
ui_locales_supported | Languages and scripts supported for the user interface | SHOULD | [RFC8414] OPTIONAL [Ena.OAuth] SHOULD. | Should only be relevant if the authorization endpoint is supported. |
pushed_authorization_request_endpoint | URL of the authorization server's endpoint for pushed authorization requests | REQUIRED IF pushed authorization requests are supported. | Section 5 of [RFC9126] (extension) [Ena.OAuth] | |
protected_resources | resource identifiers for OAuth protected resources as defined Section 4 of [RFC9728] | OPTIONAL | [Ena.OAuth] | An extension to RFC8414. |
registration_endpoint | URL of the authorization server's OAuth 2.0 Dynamic Client Registration endpoint | OPTIONAL | [RFC8414] OPTIONAL | |
revocation_endpoint | URL of the authorization server's revocation endpoint | OPTIONAL | [RFC8414] OPTIONAL | |
revocation_endpoint_auth_methods_supported | client authentication methods supported by this revocation endpoint | OPTIONAL | [RFC8414] OPTIONAL | |
revocation_endpoint_auth_signing_alg_values_supported | signing algorithms supported by this endpoint for the signature on the JWT, when used with private_key_jwt | OPTIONAL | [RFC8414] OPTIONAL | |
introspection_endpoint | URL of the authorization server's introspection endpoint | OPTIONAL | [RFC8414] OPTIONAL | |
introspection_endpoint_auth_methods_supported | client authentication methods supported by this endpoint for the signature on the JWT, when used with private_key_jwt | OPTIONAL | [RFC8414] OPTIONAL | |
introspection_endpoint_auth_signing_alg_values_supported | signing algorithms supported by this endpoint for the signature on the JWT, when used with private_key_jwt | OPTIONAL | [RFC8414] OPTIONAL | |
mtls_endpoint_aliases | OPTIONAL | [Ena.OAuth] | ||
tls_client_certificate_bound_access_tokens | indicates authorization server support for mutual TLS client certificate-bound access tokens | OPTIONAL | Section 3.3 of [RFC8705] | [RFC8705] Mutual-TLS client certificate-Bound Access Tokens does not combine well with private_key_jwt. |
require_signed_request_object | indicates where whether authorization request needs to be protected as Request Object and provided through either request or request_uri parameter | OPTIONAL | Section 10.5 of [RFC9101] | |
require_pushed_authorization_requests | Boolean parameter indicating whether the authorization server accepts authorization request data only via PAR. If omitted, the default value is false. | OPTIONAL | Section 5 of [RFC9126]. Section ??? of | |
pushed_authorization_request_endpoint | The URL of the pushed authorization request endpoint at which a client can post an authorization request to exchange for a request_uri value usable at the authorization server | OPTIONAL | Section 5 of [RFC9126]. Section 3.1.1.2 of [Ena.OAuth] | |
OpenID Relying Party (RP) metadata requirements
...
Metadata | Description | Requirement | Defined in | Comment |
|---|---|---|---|---|
redirect_uris | Array of redirection URI values used by the Relying Party. | REQUIRED | [RFC7591] REQUIRED | |
response_types | The response types that the Relying Party uses. Must be set to code. | REQUIRED | [RFC7591] OPTIONAL [OIDC.Sweden] REQUIRED | |
grant_types | The OAuth2 grant types the Relying Party uses. | REQUIRED | [RFC7591] OPTIONAL [OIDC.Sweden] REQUIRED | |
token_endpoint_auth_method | Authentication method for accessing the Token endpoint. | REQUIRED | [RFC7591] OPTIONAL [OIDC.Sweden] REQUIRED | |
jwks | The Entity's JSON Web Key Set, representing the Entity's protocol keys, included by value in the metadata. | REQUIRED IF jwks_uri is not provided | [OpenID.Fed] [RFC7591] OPTIONAL | [RFC7591] The jwks_uri and jwks parameters MUST NOT be used together. |
jwks_uri | URL referencing a JWK Set document containing the Entity's protocol keys for that Entity Type | REQUIRED IF jwks is not provided | [OpenID.Fed] [RFC7591] OPTIONAL | [RFC7591] The jwks_uri and jwks parameters MUST NOT be used together. |
signed_jwks_uri | URL referencing a signed JWT having the Entity's JWK Set document, representing the Entity's protocol keys for that Entity Type as its payload | OPTIONAL | [OpenID.Fed] | |
default_acr_values | Default requested Authentication Context Class Reference values. | OPTIONAL | [RFC7591] OPTIONAL [OIDC.Sweden] OPTIONAL | |
subject_type | Subject type requested for responses to this Client. | OPTIONAL | [RFC7591] OPTIONAL [OIDC.Sweden] OPTIONAL | |
client_registration_types | the client registration types the RP supports. Values defined by this specification are | RECOMMENDED? | [OpenID.Fed.OIDC] |
...
Metadata | Description | Requirement | Defined in | Comment |
|---|---|---|---|---|
issuer | The Issuer Identifier of the OpenID Provider. The value MUST match the Entity Identifier of the OpenID Provider, that is, the | REQUIRED | [OIDC.Discovery] [OpenID.Fed.OIDC] | |
authorization_endpoint | The URL of the OpenID Provider's authorization endpoint. | REQUIRED | [OIDC.Discovery] REQUIRED | |
token_endpoint |
| REQUIRED | [OIDC.Discovery] | |
userinfo_endpoint | URL of the OP's OAuth 2.0 Token Endpoint | RECOMMENDED | [OIDC.Discovery] RECOMMENDED | |
registration_endpoint | URL of the OP's Dynamic Client Registration Endpoint | RECOMMENDED | [OIDC.Discovery] RECOMMENDED | |
scopes_supported | The scope values the OpenID Provider supports. | RECOMMENDED | [OIDC.Discovery] RECOMMENDED | |
response_types_supported | list of the OAuth 2.0 response_type values that this OP supports | REQUIRED | [OIDC.Discovery] REQUIRED | |
grant_types_supported |
|
| ||
acr_values_supported | list of the Authentication Context Class References that this OP supports. |
| ||
|
|
| ||
client_registration_types_supported | the client registration types the OP supports. Values defined by this specification are | RECOMMENDED? | [OpenID.Fed.OIDC] | |
federation_registration_endpoint | URL of the OP's federation-specific Dynamic Client Registration Endpoint | OPTIONAL | [OpenID.Fed.OIDC] OPTIONAL | |
| ||||
jwks_uri | [OIDC.Discovery] REQUIRED | |||
| ||||
| ||||
| ||||
indicates whether the request extension parameter https://id.oidc.se/param/authnProvider is supported | OPTIONAL | [Ena.OAuth] | ||
TBD | ||||
...