...
The table below covers the metadata parameters that Clients, Authorization Servers and Protected Resources publish with the same meaning in their oauth_client, oauth_authorization_server and oauth_resource metadata, respectively. These parameters describe the Entity and the organization behind it, and are defined in Section 5.2.2 of [OpenID.Federation]. Some of these values are verified when an Entity is registered, see Section 2.
| Parameter | Description | Requirement | Defined in |
|---|---|---|---|
| organization_name | The name of the organization that owns the Entity. The value given without a language tag MUST be the legal name of the organization. Human-readable names for Swedish (#sv) and English (#en) MAY also be given. | REQUIRED. Assigned by the Federation Registration Entity. OPTIONAL for the Entity to supply. | Section 5.2.2 of [OpenID.Federation] |
| organization_identifier | A unique identifier for the organization that owns the Entity. The value MUST contain the ten-digit Swedish organization number within an ISO/IEC 6523 [ISO.6523] GLUE-URI [I-D.ietf-spice-glue-id], see Section 3.1. | REQUIRED. Assigned by the Federation Registration Entity. OPTIONAL for the Entity to supply. | Section 2 of [OIDC.Sweden.OrgId] |
| contacts | Contact addresses for the people or groups responsible for operating the Entity. The value MUST hold at least one email address. | REQUIRED | Section 5.2.2 of [OpenID.Federation] and Section 2 of [RFC7591] (for Clients) |
| organization_uri | A URL to a web page for the organization that owns the Entity. | OPTIONAL | Section 5.2.2 of [OpenID.Federation] |
| logo_uri | A URL referencing a logotype for the Entity. The URL MUST use the HTTPS scheme. | OPTIONAL | Section 5.2.2 of [OpenID.Federation] and Section 2 of [RFC7591] (for Clients) |
| description | A brief human-readable description of the Entity. | OPTIONAL | Section 5.2.2 of [OpenID.Federation] |
| keywords | Search keywords, tags, or categories that apply to the Entity. | OPTIONAL | Section 5.2.2 of [OpenID.Federation] |
| policy_uri | A URL to the documentation of conditions and policies that are relevant to the Entity. | OPTIONAL | Section 5.2.2 of [OpenID.Federation] and Section 2 of [RFC7591] (for Clients) |
| information_uri | A URL to further documentation about the Entity. | OPTIONAL | Section 5.2.2 of [OpenID.Federation] |
Table 1: Organization and informational metadata parameters.
...
The table below covers the metadata parameters that a Client publishes in its oauth_client metadata, in addition to those in Section 3. The parameters are defined in Section 2 of [RFC7591], and profiled by Section 2.2.2 of [Ena.OAuth2]. This version of the document covers Clients that use the client_credentials grant, which is the grant type that [BAS.Rules] permits. Parameters that apply only to other grant types, such as redirect_uris, require_signed_request_object and require_pushed_authorization_requests, are therefore not used.
| Parameter | Description | Requirement | Defined in |
|---|---|---|---|
| token_endpoint_auth_method | The method by which the Client authenticates at the token endpoint of an Authorization Server. The value MUST be private_key_jwt, see Section 4.2. | REQUIRED. Constrained by the Trust Anchor metadata policy. | Section 2 of [RFC7591] and Section 2.2.2.2 of [Ena.OAuth2] |
| jwks | The Client's JSON Web Key Set, included by value. The Client MUST publish its keys using either jwks or jwks_uri, but not both, see Section 2.2.2.4 of [Ena.OAuth2]. | REQUIRED, unless jwks_uri is used. | Section 2 of [RFC7591] and Section 5.2.1 of [OpenID.Federation] |
| jwks_uri | A URL from which the Client's JSON Web Key Set can be retrieved. The URL MUST use the HTTPS scheme. | REQUIRED, unless jwks is used. | Section 2 of [RFC7591] and Section 5.2.1 of [OpenID.Federation] |
| grant_types | The grant types that the Client uses. The value MUST contain client_credentials. Without this parameter, [RFC7591] and [Ena.OAuth2] assume the authorization_code grant type. | REQUIRED. Constrained by the Trust Anchor metadata policy to the grant types that [BAS.Rules] permits. | Section 2 of [RFC7591] and Section 2.2.2.3 of [Ena.OAuth2] |
| response_types | The response types that the Client uses. The value MUST be an empty array, since the client_credentials grant uses no response type. Without this parameter, [RFC7591] assumes the code response type. | REQUIRED. Assigned by the Trust Anchor metadata policy. OPTIONAL for the Client to supply. | Section 2 of [RFC7591] |
| client_name | A human-readable name of the Client, provided in Swedish and English, see Section 2. If display_name is not supplied, its value is taken from client_name, see Section 3. | OPTIONAL | Section 2 of [RFC7591] and Section 2.2.2.6 of [Ena.OAuth2] |
| scope | The scope values that the Client can use when requesting access tokens. The values are agreed between the parties to an exchange, see Section 1.3. | OPTIONAL | Section 2 of [RFC7591] and Section 2.2.2.5 of [Ena.OAuth2] |
| dpop_bound_access_tokens | Whether the Client always uses DPoP [RFC9449] when requesting access tokens. A Client that does so MUST set this parameter to true. | OPTIONAL | Section 5.2 of [RFC9449] and Section 2.2.2.7 of [Ena.OAuth2] |
| tls_client_certificate_bound_access_tokens | Whether the Client requests access tokens bound to its TLS client certificate [RFC8705]. A Client that does so MUST set this parameter to true. | OPTIONAL | Section 3.4 of [RFC8705] and Section 2.2.2.7 of [Ena.OAuth2] |
Table 2: Client metadata parameters.
...
An Authorization Server also publishes its metadata at the location stated in Section 3.1.2 of [Ena.OAuth2]. For every parameter that appears in both, the metadata published there MUST be consistent with the Authorization Server's Resolved Metadata.
| Parameter | Description | Requirement | Defined in |
|---|---|---|---|
| issuer | The issuer identifier of the Authorization Server. The value MUST be equal to the Authorization Server's Entity Identifier, and MUST meet the requirements of Section 3.1.1.1 of [Ena.OAuth2]. | REQUIRED | Section 2 of [RFC8414] and Section 3.1.1.1 of [Ena.OAuth2] |
| token_endpoint | The URL of the token endpoint. | REQUIRED | Section 2 of [RFC8414] and Section 3.1.1.2 of [Ena.OAuth2] |
| jwks_uri | A URL from which the Authorization Server's JSON Web Key Set can be retrieved. The URL MUST use the HTTPS scheme, and each key MUST include the use parameter. | REQUIRED | Section 2 of [RFC8414] and Section 3.1.1.3 of [Ena.OAuth2] |
| grant_types_supported | The grant types that the Authorization Server supports. The value MUST contain client_credentials. Without this parameter, [Ena.OAuth2] assumes the authorization_code grant type. | REQUIRED. Constrained by the Trust Anchor metadata policy to the grant types that [BAS.Rules] permits. | Section 2 of [RFC8414] and Section 3.1.1.5 of [Ena.OAuth2] |
| response_types_supported | The response types that the Authorization Server supports. | REQUIRED | Section 2 of [RFC8414] |
| token_endpoint_auth_methods_supported | The client authentication methods that the token endpoint supports. The value MUST contain private_key_jwt. |
| REQUIREDF | Section 2 of [RFC8414] and Section 3.1.1.6 of [Ena.OAuth2] | ||
| token_endpoint_auth_signing_alg_values_supported | The signature algorithms that the token endpoint supports for private_key_jwt. The value MUST conform to Section 8.2 of [Ena.OAuth2]. | REQUIRED | Section 2 of [RFC8414] and Section 3.1.1.7 of [Ena.OAuth2] |
| scopes_supported | The scope values that the Authorization Server supports. The values are agreed between the parties to an exchange, see Section 1.3. | REQUIRED | Section 2 of [RFC8414] and Section 3.1.1.4 of [Ena.OAuth2] |
| revocation_endpoint | The URL of the revocation endpoint. | OPTIONAL | Section 2 of [RFC8414] |
| revocation_endpoint_auth_methods_supported | The client authentication methods that the revocation endpoint supports, under the same requirements as token_endpoint_auth_methods_supported. | REQUIRED if revocation_endpoint is present. | Section 2 of [RFC8414] and Section 3.1.1.6 of [Ena.OAuth2] |
| introspection_endpoint | The URL of the introspection endpoint. | OPTIONAL | Section 2 of [RFC8414] |
| introspection_endpoint_auth_methods_supported | The client authentication methods that the introspection endpoint supports, under the same requirements as token_endpoint_auth_methods_supported. | REQUIRED if introspection_endpoint is present. | Section 2 of [RFC8414] and Section 3.1.1.6 of [Ena.OAuth2] |
| dpop_signing_alg_values_supported | The signature algorithms that the Authorization Server supports for DPoP proofs. An Authorization Server that supports DPoP MUST publish this parameter. | REQUIRED if DPoP is supported. | Section 5.1 of [RFC9449] and Section 3.1.1.10 of [Ena.OAuth2] |
| tls_client_certificate_bound_access_tokens | Whether the Authorization Server supports access tokens bound to TLS client certificates. | OPTIONAL | Section 3.3 of [RFC8705] and Section 3.1.1.10 of [Ena.OAuth2] |
| mtls_endpoint_aliases | Alternative endpoints for use with mutual TLS. | OPTIONAL | Section 5 of [RFC8705] and Section 3.1.1.10 of [Ena.OAuth2] |
| protected_resources | The resource identifiers of the Protected Resources that the Authorization Server issues access tokens for. | RECOMMENDED | Section 4 of [RFC9728] and Section 3.1.1.10 of [Ena.OAuth2] |
Table 3: Authorization Server metadata parameters.
...
The table below covers the metadata parameters that a Protected Resource publishes in its oauth_resource metadata, in addition to those in Section 3. The parameters are defined in Section 2 of [RFC9728], and profiled by Section 4.3 of [Ena.OAuth2].
| Parameter | Description | Requirement | Defined in |
|---|---|---|---|
| resource | The resource identifier of the Protected Resource, see Section 6.1. | REQUIRED | Section 2 of [RFC9728] and Section 4.3 of [Ena.OAuth2] |
| authorization_servers | The issuer identifiers of the Authorization Servers that issue access tokens for the Protected Resource. The value MUST contain the Entity Identifier of at least one Authorization Server in BAS. |
| OPTIONAL | Section 2 of [RFC9728] | ||
| jwks_uri | A URL from which the Protected Resource's JSON Web Key Set can be retrieved. The URL MUST use the HTTPS scheme. | OPTIONAL | Section 2 of [RFC9728] and Section 5.2.1 of [OpenID.Federation] |
| resource_name | A human-readable name of the Protected Resource, provided in Swedish and English, see Section 2. If display_name is not supplied, its value is taken from resource_name, see Section 3. | OPTIONAL | Section 2 of [RFC9728] |
| scopes_supported | The scope values that the Protected Resource uses. The values are agreed between the parties to an exchange, see Section 1.3. | RECOMMENDED | Section 2 of [RFC9728] |
| bearer_methods_supported | The methods by which the Protected Resource accepts access tokens. If present, the value MUST include header and body, see Section 4 of [Ena.OAuth2]. | OPTIONAL | Section 2 of [RFC9728] |
| dpop_bound_access_tokens_required | Whether the Protected Resource requires DPoP-bound access tokens. A Protected Resource that does so MUST set this parameter to true. | OPTIONAL | Section 2 of [RFC9728] |
| dpop_signing_alg_values_supported | The signature algorithms that the Protected Resource supports for DPoP proofs. A Protected Resource that supports DPoP MUST publish this parameter. |
| OPTIONAL | Section 2 of [RFC9728] | ||
| tls_client_certificate_bound_access_tokens | Whether the Protected Resource supports access tokens bound to TLS client certificates. A Protected Resource that requires such tokens MUST set this parameter to true. | OPTIONAL | Section 2 of [RFC9728] |
Table 4: Protected Resource metadata parameters.
...