Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

The table below covers the metadata parameters that Clients, Authorization Servers and Protected Resources publish with the same meaning in their oauth_client, oauth_authorization_server and oauth_resource metadata, respectively. These parameters describe the Entity and the organization behind it, and are defined in Section 5.2.2 of [OpenID.Federation]. Some of these values are verified when an Entity is registered, see Section 2.

ParameterDescriptionRequirementDefined in
organization_nameThe name of the organization that owns the Entity. The value given without a language tag MUST be the legal name of the organization. Human-readable names for Swedish (#sv) and English (#en) MAY also be given.REQUIRED. Assigned by the Federation Registration Entity. OPTIONAL for the Entity to supply.Section 5.2.2 of [OpenID.Federation]
organization_identifierA unique identifier for the organization that owns the Entity. The value MUST contain the ten-digit Swedish organization number within an ISO/IEC 6523 [ISO.6523] GLUE-URI [I-D.ietf-spice-glue-id], see Section 3.1.REQUIRED. Assigned by the Federation Registration Entity. OPTIONAL for the Entity to supply.Section 2 of [OIDC.Sweden.OrgId]
display_nameA human-readable name of the Entity itself, intended for the people who administer and operate Entities in BAS. If a Client does not supply this parameter, the value given for client_name is used. If a Protected Resource does not supply it, the value given for resource_name is used.REQUIRED. Assigned by the Federation Registration Entity. OPTIONAL for the Entity to supply.Section 5.2.2 of [OpenID.Federation]
contactsContact addresses for the people or groups responsible for operating the Entity. The value MUST hold at least one email address.REQUIREDSection 5.2.2 of [OpenID.Federation] and Section 2 of [RFC7591] (for Clients)
organization_uriA URL to a web page for the organization that owns the Entity.OPTIONALSection 5.2.2 of [OpenID.Federation]
logo_uriA URL referencing a logotype for the Entity. The URL MUST use the HTTPS scheme.OPTIONALSection 5.2.2 of [OpenID.Federation] and Section 2 of [RFC7591] (for Clients)
descriptionA brief human-readable description of the Entity.OPTIONALSection 5.2.2 of [OpenID.Federation]
keywordsSearch keywords, tags, or categories that apply to the Entity.OPTIONALSection 5.2.2 of [OpenID.Federation]
policy_uriA URL to the documentation of conditions and policies that are relevant to the Entity.OPTIONALSection 5.2.2 of [OpenID.Federation] and Section 2 of [RFC7591] (for Clients)
information_uriA URL to further documentation about the Entity.OPTIONALSection 5.2.2 of [OpenID.Federation]

Table 1: Organization and informational metadata parameters.

...

The table below covers the metadata parameters that a Client publishes in its oauth_client metadata, in addition to those in Section 3. The parameters are defined in Section 2 of [RFC7591], and profiled by Section 2.2.2 of [Ena.OAuth2]. This version of the document covers Clients that use the client_credentials grant, which is the grant type that [BAS.Rules] permits. Parameters that apply only to other grant types, such as redirect_uris, require_signed_request_object and require_pushed_authorization_requests, are therefore not used.

ParameterDescriptionRequirementDefined in
token_endpoint_auth_methodThe method by which the Client authenticates at the token endpoint of an Authorization Server. The value MUST be private_key_jwt, see Section 4.2.REQUIRED. Constrained by the Trust Anchor metadata policy.Section 2 of [RFC7591] and Section 2.2.2.2 of [Ena.OAuth2]
jwksThe Client's JSON Web Key Set, included by value. The Client MUST publish its keys using either jwks or jwks_uri, but not both, see Section 2.2.2.4 of [Ena.OAuth2].REQUIRED, unless jwks_uri is used.Section 2 of [RFC7591] and Section 5.2.1 of [OpenID.Federation]
jwks_uriA URL from which the Client's JSON Web Key Set can be retrieved. The URL MUST use the HTTPS scheme.REQUIRED, unless jwks is used.Section 2 of [RFC7591] and Section 5.2.1 of [OpenID.Federation]
grant_typesThe grant types that the Client uses. The value MUST contain client_credentials. Without this parameter, [RFC7591] and [Ena.OAuth2] assume the authorization_code grant type.REQUIRED. Constrained by the Trust Anchor metadata policy to the grant types that [BAS.Rules] permits.Section 2 of [RFC7591] and Section 2.2.2.3 of [Ena.OAuth2]
response_typesThe response types that the Client uses. The value MUST be an empty array, since the client_credentials grant uses no response type. Without this parameter, [RFC7591] assumes the code response type.REQUIRED. Assigned by the Trust Anchor metadata policy. OPTIONAL for the Client to supply.Section 2 of [RFC7591]
client_nameA human-readable name of the Client, provided in Swedish and English, see Section 2. If display_name is not supplied, its value is taken from client_name, see Section 3.OPTIONALSection 2 of [RFC7591] and Section 2.2.2.6 of [Ena.OAuth2]
scopeThe scope values that the Client can use when requesting access tokens. The values are agreed between the parties to an exchange, see Section 1.3.OPTIONALSection 2 of [RFC7591] and Section 2.2.2.5 of [Ena.OAuth2]
dpop_bound_access_tokensWhether the Client always uses DPoP [RFC9449] when requesting access tokens. A Client that does so MUST set this parameter to true.OPTIONALSection 5.2 of [RFC9449] and Section 2.2.2.7 of [Ena.OAuth2]
tls_client_certificate_bound_access_tokensWhether the Client requests access tokens bound to its TLS client certificate [RFC8705]. A Client that does so MUST set this parameter to true.OPTIONALSection 3.4 of [RFC8705] and Section 2.2.2.7 of [Ena.OAuth2]

Table 2: Client metadata parameters.

...

An Authorization Server also publishes its metadata at the location stated in Section 3.1.2 of [Ena.OAuth2]. For every parameter that appears in both, the metadata published there MUST be consistent with the Authorization Server's Resolved Metadata.

ParameterDescriptionRequirementDefined in
issuerThe issuer identifier of the Authorization Server. The value MUST be equal to the Authorization Server's Entity Identifier, and MUST meet the requirements of Section 3.1.1.1 of [Ena.OAuth2].REQUIREDSection 2 of [RFC8414] and Section 3.1.1.1 of [Ena.OAuth2]
token_endpointThe URL of the token endpoint.REQUIREDSection 2 of [RFC8414] and Section 3.1.1.2 of [Ena.OAuth2]
jwks_uriA URL from which the Authorization Server's JSON Web Key Set can be retrieved. The URL MUST use the HTTPS scheme, and each key MUST include the use parameter.REQUIREDSection 2 of [RFC8414] and Section 3.1.1.3 of [Ena.OAuth2]
grant_types_supportedThe grant types that the Authorization Server supports. The value MUST contain client_credentials. Without this parameter, [Ena.OAuth2] assumes the authorization_code grant type.REQUIRED. Constrained by the Trust Anchor metadata policy to the grant types that [BAS.Rules] permits.Section 2 of [RFC8414] and Section 3.1.1.5 of [Ena.OAuth2]
response_types_supportedThe response types that the Authorization Server supports.REQUIREDSection 2 of [RFC8414]
token_endpoint_auth_methods_supportedThe client authentication methods that the token endpoint supports. The value MUST contain private_key_jwt.
REQUIRED
REQUIREDFSection 2 of [RFC8414] and Section 3.1.1.6 of [Ena.OAuth2]
token_endpoint_auth_signing_alg_values_supportedThe signature algorithms that the token endpoint supports for private_key_jwt. The value MUST conform to Section 8.2 of [Ena.OAuth2].REQUIREDSection 2 of [RFC8414] and Section 3.1.1.7 of [Ena.OAuth2]
scopes_supportedThe scope values that the Authorization Server supports. The values are agreed between the parties to an exchange, see Section 1.3.REQUIREDSection 2 of [RFC8414] and Section 3.1.1.4 of [Ena.OAuth2]
revocation_endpointThe URL of the revocation endpoint.OPTIONALSection 2 of [RFC8414]
revocation_endpoint_auth_methods_supportedThe client authentication methods that the revocation endpoint supports, under the same requirements as token_endpoint_auth_methods_supported.REQUIRED if revocation_endpoint is present.Section 2 of [RFC8414] and Section 3.1.1.6 of [Ena.OAuth2]
introspection_endpointThe URL of the introspection endpoint.OPTIONALSection 2 of [RFC8414]
introspection_endpoint_auth_methods_supportedThe client authentication methods that the introspection endpoint supports, under the same requirements as token_endpoint_auth_methods_supported.REQUIRED if introspection_endpoint is present.Section 2 of [RFC8414] and Section 3.1.1.6 of [Ena.OAuth2]
dpop_signing_alg_values_supportedThe signature algorithms that the Authorization Server supports for DPoP proofs. An Authorization Server that supports DPoP MUST publish this parameter.REQUIRED if DPoP is supported.Section 5.1 of [RFC9449] and Section 3.1.1.10 of [Ena.OAuth2]
tls_client_certificate_bound_access_tokensWhether the Authorization Server supports access tokens bound to TLS client certificates.OPTIONALSection 3.3 of [RFC8705] and Section 3.1.1.10 of [Ena.OAuth2]
mtls_endpoint_aliasesAlternative endpoints for use with mutual TLS.OPTIONALSection 5 of [RFC8705] and Section 3.1.1.10 of [Ena.OAuth2]
protected_resourcesThe resource identifiers of the Protected Resources that the Authorization Server issues access tokens for.RECOMMENDEDSection 4 of [RFC9728] and Section 3.1.1.10 of [Ena.OAuth2]

Table 3: Authorization Server metadata parameters.

...

The table below covers the metadata parameters that a Protected Resource publishes in its oauth_resource metadata, in addition to those in Section 3. The parameters are defined in Section 2 of [RFC9728], and profiled by Section 4.3 of [Ena.OAuth2].

ParameterDescriptionRequirementDefined in
resourceThe resource identifier of the Protected Resource, see Section 6.1.REQUIREDSection 2 of [RFC9728] and Section 4.3 of [Ena.OAuth2]
authorization_serversThe issuer identifiers of the Authorization Servers that issue access tokens for the Protected Resource. The value MUST contain the Entity Identifier of at least one Authorization Server in BAS.
REQUIRED
OPTIONALSection 2 of [RFC9728]
jwks_uriA URL from which the Protected Resource's JSON Web Key Set can be retrieved. The URL MUST use the HTTPS scheme.OPTIONALSection 2 of [RFC9728] and Section 5.2.1 of [OpenID.Federation]
resource_nameA human-readable name of the Protected Resource, provided in Swedish and English, see Section 2. If display_name is not supplied, its value is taken from resource_name, see Section 3.OPTIONALSection 2 of [RFC9728]
scopes_supportedThe scope values that the Protected Resource uses. The values are agreed between the parties to an exchange, see Section 1.3.RECOMMENDEDSection 2 of [RFC9728]
bearer_methods_supportedThe methods by which the Protected Resource accepts access tokens. If present, the value MUST include header and body, see Section 4 of [Ena.OAuth2].OPTIONALSection 2 of [RFC9728]
dpop_bound_access_tokens_requiredWhether the Protected Resource requires DPoP-bound access tokens. A Protected Resource that does so MUST set this parameter to true.OPTIONALSection 2 of [RFC9728]
dpop_signing_alg_values_supportedThe signature algorithms that the Protected Resource supports for DPoP proofs. A Protected Resource that supports DPoP MUST publish this parameter.
REQUIRED if DPoP is supported.
OPTIONALSection 2 of [RFC9728]
tls_client_certificate_bound_access_tokensWhether the Protected Resource supports access tokens bound to TLS client certificates. A Protected Resource that requires such tokens MUST set this parameter to true.OPTIONALSection 2 of [RFC9728]

Table 4: Protected Resource metadata parameters.

...