...
Metadata | Description | Requirement | Defined in | Comment | ||
|---|---|---|---|---|---|---|
issuer | MUST be a globally unique URL. | REQUIRED | [RFC8414], REQUIRED | |||
grant_types_supported | Supported Grant Types | OPTIONAL If the parameter is omitted, the default value SHALL be [ "authorization_code" ]. | [RFC8414], OPTIONAL, ["authorization_code", "implicit"] is default if not present | Note: [Ena.OAuth]: If the parameter is omitted, the default value SHALL be "authorization_code" Could it be a risk to change the default of the standard? | ||
token_endpoint | Endpoint for requesting access tokens | REQUIRED | [RFC8414], REQUIRED | |||
token_endpoint_auth_methods_supported | Client authentication methods supported by the token endpoint. | REQUIRED and MUST include private_key_jwt. | [RFC8414] OPTIONAL, client_secret_basic is default if not present | In line with the security requirements | ||
token_endpoint_auth_signing_alg_values_supported | JWS signing algorithms for client authentication supported by the token endpoint. | REQUIRED | [RFC8414] REQUIRED when private_key_jwt is used. | |||
scopes_supported | scopes supported by the authorization server | REQUIRED | [RFC8414] , RECOMMENDED [Ena.OAuth] | What is the rationale for this sharper requirement in Ena.OAuth? | ||
dpop_signing_alg_values_supported | JWS algorithms supported for DPoP proof JWTs. | RECOMMENDED | [Ena.OAuth] | |||
authorization_response_iss_parameter_supported | indicates whether the authorization server supports including the issuer parameter in authorization responses to protect against Authorization Server Mix-Up Attacks | SHOULD OPTIONAL? | [RFC9207] [Ena.OAuth] | issuer is already required, so this could be OPTIONAL because this is only an indication? | ||
jwks | The Entity's JSON Web Key Set, representing the Entity's protocol keys, included by value in the metadata. | REQUIRED if jwks_uri is not provided | [OpenID.Fed] | [Ena.OAuth], and [RFC8414] Not supported? | ||
jwks_uri | URL referencing a JWK Set document containing the Entity's protocol keys for that Entity Type | REQUIRED if jwks is not provided | [OpenID.Fed] [RFC8414] [Ena.OAuth] | [Ena.OAuth] has this as the only option - why? | ||
signed_jwks_uri | URL referencing a signed JWT having the Entity's JWK Set document, representing the Entity's protocol keys for that Entity Type as its payload | OPTIONAL | [OpenID.Fed] | [Ena.OAuth], and [RFC8414] Not supported? | ||
Below is ONLY applicable IF the corresponding features are supported. | ||||||
authorization_endpoint | URL of the authorization server's authorization endpoint | REQUIRED IF authorization code grant type is supported. | [RFC8414] REQUIRED | Out of cope for SIB BAS Step 1, but should be included. | ||
code_challenge_methods_supported | PKCE [RFC7636] code challenge methods supported | REQUIRED IF authorization code grant type is supported. | [RFC8414] OPTIONAL [Ena.OAuth] | |||
ui_locales_supported | Languages and scripts supported for the user interface | SHOULD | [RFC8414] OPTIONAL [Ena.OAuth] SHOULD. | Should only be relevant if the authorization endpoint is supported. | ||
pushed_authorization_request_endpoint | URL of the authorization server's endpoint for pushed authorization requests | REQUIRED IF pushed authorization requests are supported. | Section 5 of [RFC9126] (extension) [Ena.OAuth] | |||
protected_resources | resource identifiers for OAuth protected resources as defined Section 4 of [RFC9728] | OPTIONAL | [Ena.OAuth] | An extension to RFC8414. | ||
registration_endpoint | URL of the authorization server's OAuth 2.0 Dynamic Client Registration endpoint | OPTIONAL | [RFC8414] OPTIONAL | |||
revocation_endpoint | URL of the authorization server's revocation endpoint | OPTIONAL | [RFC8414] OPTIONAL | |||
revocation_endpoint_auth_methods_supported | client authentication methods supported by this revocation endpoint | OPTIONAL | [RFC8414] OPTIONAL | |||
revocation_endpoint_auth_signing_alg_values_supported | signing algorithms supported by this endpoint for the signature on the JWT, when used with private_key_jwt | OPTIONAL | [RFC8414] OPTIONAL | |||
introspection_endpoint | URL of the authorization server's introspection endpoint | OPTIONAL | [RFC8414] OPTIONAL | |||
introspection_endpoint_auth_methods_supported | signing algorithms client authentication methods supported by this endpoint for the signature on the JWT, when used with private_key_jwt | OPTIONAL | [RFC8414] OPTIONALmtls | |||
introspection_endpoint_auth_signing_alg_values_supported | signing algorithms supported by this endpoint for the signature on the JWT, when used with private_key_jwt | OPTIONAL | [RFC8414] OPTIONAL | |||
mtls_endpoint_aliases | OPTIONAL | [ | _aliasesOPTIONAL | [Ena.OAuth] | ||
tls_client_certificate_bound_access_tokens | indicates authorization server support for mutual TLS client certificate-bound access tokens | OPTIONAL | Section 3.3 of [RFC8705] | [RFC8705] Mutual-TLS client certificate-Bound Access Tokens does not combine well with private_key_jwt. | ||
require_signed_request_object | indicates where whether authorization request needs to be protected as Request Object and provided through either request or request_uri parameter | OPTIONAL | Section 10.5 of [RFC9101] | |||
...
require_pushed_authorization_requests | Boolean parameter indicating whether the authorization server accepts authorization request data only via PAR. If omitted, the default value is false. | OPTIONAL | Section 5 of [RFC9126]. Section ??? of | |
pushed_authorization_request_endpoint | The URL of the pushed authorization request endpoint at which a client can post an authorization request to exchange for a request_uri value usable at the authorization server | OPTIONAL | Section 5 of [RFC9126]. Section 3.1.1.2 of [Ena.OAuth] |
OpenID Relying Party (RP) metadata requirements
OpenID Relying Party (RP) metadata requirements
...
Metadata
Description
Requirement
Defined in
Comment
redirect_uris
Array of redirection URI values used by the Relying Party.
REQUIRED
[RFC7591] REQUIRED
[OIDC.Sweden] REQUIRED
response_types
The response types that the Relying Party uses. Must be set to code.
REQUIRED
[RFC7591] OPTIONAL
[OIDC.Sweden] REQUIRED
grant_types
The OAuth2 grant types the Relying Party uses.
REQUIRED
MUST be set to authorization_code.
Metadata | Description | Requirement | Defined in | Comment |
|---|---|---|---|---|
redirect_uris | Array of redirection URI values used by the Relying Party. | REQUIRED | [RFC7591] REQUIRED |
|
token_endpoint_auth_method
Authentication method for accessing the Token endpoint.
response_types | The response types that the Relying Party uses. Must be set to code. | REQUIRED |
MUST be set to private_key_jwt
[RFC7591] OPTIONAL |
default is client_secret_basic
[OIDC.Sweden] REQUIRED |
jwks
The Entity's JSON Web Key Set, representing the Entity's protocol keys, included by value in the metadata.
REQUIRED IF jwks_uri is not provided
[OpenID.Fed]
[RFC7591] OPTIONAL
[RFC7591] The jwks_uri and jwks parameters MUST NOT be used together.
jwks_uri
URL referencing a JWK Set document containing the Entity's protocol keys for that Entity Type
REQUIRED IF jwks is not provided
grant_types | The OAuth2 grant types the Relying Party uses. | REQUIRED | [RFC7591] OPTIONAL [OIDC.Sweden] REQUIRED | |
token_endpoint_auth_method | Authentication method for accessing the Token endpoint. | REQUIRED |
[RFC7591] OPTIONAL |
[RFC7591] The jwks_uri and jwks parameters MUST NOT be used together.
default is client_secret_basic [OIDC.Sweden] REQUIRED | |
jwks | The Entity's JSON Web Key Set |
signed_jwks_uri
, representing the Entity's protocol keys |
, included by value in the metadata. | REQUIRED IF jwks_uri is not provided | [OpenID.Fed] |
default_acr_values
Default requested Authentication Context Class Reference values.
OPTIONAL
[RFC7591] OPTIONAL
[OIDC.Sweden] OPTIONAL
subject_type
Subject type requested for responses to this Client.
OPTIONAL
[RFC7591] OPTIONAL
[OIDC.Sweden] OPTIONAL
...
[RFC7591] OPTIONAL | [RFC7591] The jwks_uri and jwks parameters MUST NOT be used together. | |||
jwks_uri | URL referencing a JWK Set document containing the Entity's protocol keys for that Entity Type | REQUIRED IF jwks is not provided | [OpenID.Fed] [RFC7591] OPTIONAL | [RFC7591] The jwks_uri and jwks parameters MUST NOT be used together. |
signed_jwks_uri | URL referencing a signed JWT having the Entity's JWK Set document, representing the Entity's protocol keys for that Entity Type as its payload | OPTIONAL | [OpenID.Fed] | |
default_acr_values | Default requested Authentication Context Class Reference values. | OPTIONAL | [RFC7591] OPTIONAL [OIDC.Sweden] OPTIONAL | |
subject_type | Subject type requested for responses to this Client. | OPTIONAL | [RFC7591] OPTIONAL [OIDC.Sweden] OPTIONAL | |
client_registration_types | the client registration types the RP supports. Values defined by this specification are | RECOMMENDED? | [OpenID.Fed.OIDC] |
OpenID Provider metadata requirements
Metadata | Description | Requirement | Defined in | Comment |
|---|---|---|---|---|
issuer | The Issuer Identifier of the OpenID Provider. The value MUST match the Entity Identifier of the OpenID Provider, that is, the | REQUIRED | [OIDC.Discovery] [OpenID.Fed.OIDC] | |
authorization_endpoint | The URL of the OpenID Provider's authorization endpoint. | REQUIRED | [OIDC.Discovery] REQUIRED | |
token_endpoint |
| REQUIRED | [OIDC.Discovery] | |
userinfo_endpoint | URL of the OP's OAuth 2.0 Token Endpoint | RECOMMENDED | [OIDC.Discovery] RECOMMENDED | |
registration_endpoint | URL of the OP's Dynamic Client Registration Endpoint | RECOMMENDED | [OIDC.Discovery] RECOMMENDED | |
scopes_supported | The scope values the OpenID Provider supports. | RECOMMENDED | [OIDC.Discovery] RECOMMENDED | |
response_types_supported | list of the OAuth 2.0 response_type values that this OP supports | REQUIRED | [OIDC.Discovery] REQUIRED | |
grant_types_supported |
|
| ||
acr_values_supported | list of the Authentication Context Class References that this OP supports. |
| ||
|
|
| ||
client_registration_types_supported | the client registration types the OP supports. Values defined by this specification are | RECOMMENDED? | [OpenID.Fed.OIDC] | |
federation_registration_endpoint | URL of the OP's federation-specific Dynamic Client Registration Endpoint | OPTIONAL | [OpenID.Fed.OIDC] OPTIONAL | |
| ||||
jwks_uri | [OIDC.Discovery] REQUIRED | |||
| ||||
| ||||
|
OpenID Provider metadata requirements
Metadata
Description
Requirement
Defined in
Comment
indicates whether the request extension parameter https://id.oidc.se/param/authnProvider is supported | OPTIONAL | [Ena.OAuth] | ||
TBD | ||||
Appendix
Organization identifier formats
...
[OpenID.Fed.Reg.Policy] https://www.oidc.se/openid-federation-registration-policy/main.html
[OpenID.Fed.OIDC] https://openid.net/specs/openid-federation-connect-1_1.html
[RFC7591] https://openid.net/specs/openid-connect-registration-1_0.html
[OIDC.Sweden] https://www.oidc.se/specifications/
[OIDC.Discovery] https://openid.net/specs/openid-connect-discovery-1_0.html
Notes
[OpenID.Fed.Swe.Profile] contains recommendations regarding “Adapting OAuth 2.0 and OpenID Connect for OpenID Federation“, chapter 7, which may affect metadata requirements:
“For federation deployments based on this profile, it is RECOMMENDED that support for the parameters defined in [OpenID.RP.Choices] be mandatory for federation participants.“
“It is RECOMMENDED that the Federation Operator define requirements for which client authentication methods OAuth 2.0 Authorization Servers and OpenID Connect OpenID Providers should support, in order to avoid such interoperability problems.“
“Requirements for OpenID Connect Subject Types
Section 2 of [OpenID.Registration] defines the subject_type metadata parameter, which is used by an OpenID Connect Relying Party to declare whether it requires subject identifiers in tokens to be public or pairwise. Correspondingly, an OpenID Provider's Discovery metadata contains the subject_types_supported parameter [OpenID.Discovery], listing the subject types the OpenID Provider supports. If OpenID Providers within the federation do not support both types, interoperability issues may arise. It is RECOMMENDED that the Federation Operator, via referenced profiles or federation rules, require OpenID Providers to support both the public and pairwise subject types.”