...
The table below covers the metadata parameters that a Client publishes in its oauth_client metadata, in addition to those in Section 3. The parameters are defined in Section 2 of [RFC7591], and profiled by Section 2.2.2 of [Ena.OAuth2]. This version of the document covers Clients that use the client_credentials grant, which is the grant type that [BAS.Rules] permits. Parameters that apply only to other grant types, such as redirect_uris, require_signed_request_object and require_pushed_authorization_requests, are therefore not used. The token_endpoint_auth_signing_alg parameter defined by [OpenID.Registration] is not used either, since a Client in BAS does not declare the algorithm it signs with, see Section 4.2.
Parameter | Description | Requirement | Defined in |
|---|---|---|---|
token_endpoint_auth_method | The method by which the Client authenticates at the token endpoint of an Authorization Server. The value MUST be private_key_jwt, see Section 4.2. | REQUIRED. Constrained by the Trust Anchor metadata policy. | Section 2 of [RFC7591] and Section 2.2.2.2 of [Ena.OAuth2] |
jwks | The Client's JSON Web Key Set, included by value. The Client MUST publish its keys using either jwks or jwks_uri, but not both, see Section 2.2.2.4 of [Ena.OAuth2]. The keys MUST meet the requirements of [BAS.Security]. | REQUIRED, unless jwks_uri is used. | Section 2 of [RFC7591] and Section 5.2.1 of [OpenID.Federation] |
jwks_uri | A URL from which the Client's JSON Web Key Set can be retrieved. The URL MUST use the HTTPS scheme. The keys MUST meet the requirements of [BAS.Security]. | REQUIRED, unless jwks is used. | Section 2 of [RFC7591] and Section 5.2.1 of [OpenID.Federation] |
grant_types | The grant types that the Client uses. The value MUST contain client_credentials. Without this parameter, [RFC7591] and [Ena.OAuth2] assume the authorization_code grant type. | REQUIRED. Constrained by the Trust Anchor metadata policy to the grant types that [BAS.Rules] permits. | Section 2 of [RFC7591] and Section 2.2.2.3 of [Ena.OAuth2] |
redirect_uris | Array of redirection URIs for use in redirect-based flows | REQUIRED if the client is registered for the authorization_code grant type | Section 2 of [RFC7591] and Section 2.2.2.1 of [Ena.OAuth2] |
response_types | The response types that the Client uses. The value MUST be an empty array, since the client_credentials grant uses no response type. Without this parameter, [RFC7591] assumes the code response type. | REQUIRED. Assigned by the Trust Anchor metadata policy. OPTIONAL for the Client to supply. | Section 2 of [RFC7591] |
client_name | A human-readable name of the Client, provided in Swedish and English, see Section 2. If display_name is not supplied, its value is taken from client_name, see Section 3. | OPTIONAL | Section 2 of [RFC7591] and Section 2.2.2.6 of [Ena.OAuth2] |
scope | The scope values that the Client can use when requesting access tokens. The values are agreed between the parties to an exchange, see Section 1.3. | OPTIONAL | Section 2 of [RFC7591] and Section 2.2.2.5 of [Ena.OAuth2] |
dpop_bound_access_tokens | Whether the Client always uses DPoP [RFC9449] when requesting access tokens. A Client that does so MUST set this parameter to true. | OPTIONAL | Section 5.2 of [RFC9449] and Section 2.2.2.7 of [Ena.OAuth2] |
tls_client_certificate_bound_access_tokens | Whether the Client requests access tokens bound to its TLS client certificate [RFC8705]. A Client that does so MUST set this parameter to true. | OPTIONAL | Section 3.4 of [RFC8705] and Section 2.2.2.7 of [Ena.OAuth2] |
Table 2: Client metadata parameters.
...
An Authorization Server also publishes its metadata at the location stated in Section 3.1.2 of [Ena.OAuth2]. For every parameter that appears in both, the metadata published there MUST be consistent with the Authorization Server's Resolved Metadata. Where the Trust Anchor metadata policy removes values that the Authorization Server supports outside BAS, such as other grant types or client authentication methods, the value in the Resolved Metadata is a subset of the published value, and the two are consistent in this sense.
Parameter | Description | Requirement | Defined in | ||
|---|---|---|---|---|---|
issuer | The issuer identifier of the Authorization Server. The value MUST be equal to the Authorization Server's Entity Identifier, see Section 5.1.3 of [OpenID.Federation.Connect], and MUST meet the requirements of Section 3.1.1.1 of [Ena.OAuth2]. | REQUIRED | Section 2 of [RFC8414] and Section 3.1.1.1 of [Ena.OAuth2] | ||
token_endpoint | The URL of the token endpoint. | REQUIRED | Section 2 of [RFC8414] and Section 3.1.1.2 of [Ena.OAuth2] | ||
jwks_uri | A URL from which the Authorization Server's JSON Web Key Set can be retrieved. The URL MUST use the HTTPS scheme. The keys MUST meet the requirements of [BAS.Security]. | REQUIRED | Section 2 of [RFC8414] and Section 3.1.1.3 of [Ena.OAuth2] | ||
grant_types_supported | The grant types that the Authorization Server supports. The value MUST contain client_credentials. Without this parameter, [Ena.OAuth2] assumes the authorization_code grant type. | REQUIRED. Constrained by the Trust Anchor metadata policy to the grant types that [BAS.Rules] permits. | Section 2 of [RFC8414] and Section 3.1.1.5 of [Ena.OAuth2] | ||
response_types_supported | The response types that the Authorization Server supports. The value is not constrained within BAS, since the client_credentials grant uses no response type. | REQUIRED | Section 2 of [RFC8414] | ||
token_endpoint_auth_methods_supported | The client authentication methods that the token endpoint supports. The value MUST be private_key_jwt only, see Section 2 of [BAS.Security]. | REQUIRED. Constrained by the Trust Anchor metadata policy. | Section 2 of [RFC8414] and Section 3.1.1.6 of [Ena.OAuth2] | ||
token_endpoint_auth_signing_alg_values_supported | The signature algorithms that the token endpoint supports for private_key_jwt. See Section 3.1 of [BAS.Security]. | REQUIRED. Constrained by the Trust Anchor metadata policy. | Section 2 of [RFC8414] and Section 3.1.1.7 of [Ena.OAuth2] | ||
scopes_supported | The scope values that the Authorization Server supports. The values are agreed between the parties to an exchange, see Section 1.3. | REQUIRED | Section 2 of [RFC8414] and Section 3.1.1.4 of [Ena.OAuth2] | ||
revocation_endpoint | The URL of the revocation endpoint. | OPTIONAL | Section 2 of [RFC8414] | ||
revocation_endpoint_auth_methods_supported | The client authentication methods that the revocation endpoint supports. The value MUST be private_key_jwt only, see Section 2 of [BAS.Security]. | REQUIRED if revocation_endpoint is present. Constrained by the Trust Anchor metadata policy. | Section 2 of [RFC8414] and Section 3.1.1.6 of [Ena.OAuth2] | ||
introspection_endpoint | The URL of the introspection endpoint. | OPTIONAL | Section 2 of [RFC8414] | ||
revocation_endpoint_auth_signing_alg_values_supported | Signing algorithms supported by this endpoint for the signature on the JWT, when used with private_key_jwt client authentication. | REQUIRED if revocation_endpoint is present. Constrained by the Trust Anchor metadata policy. | Section 2 of [RFC8414] and Section 3.1.1.7 of [Ena.OAuth2] | ||
introspection_endpoint | The URL of the introspection endpoint. | OPTIONAL | Section 2 of [RFC8414] | ||
introspection_endpoint_auth_methods_supported | The client authentication methods that the introspection endpoint supports. The | introspection_endpoint_auth_methods_supported | The client authentication methods that the introspection endpoint supports. The value MUST be private_key_jwt only, see Section 2 of [BAS.Security]. | REQUIRED if introspection_endpoint is present. Constrained by the Trust Anchor metadata policy. | Section 2 of [RFC8414] and Section 3.1.1.6 of [Ena.OAuth2] | dpop
introspection_endpoint_auth_signing_alg_values_supported | Signing algorithms supported by this endpoint for the signature on the JWT, when used with private_key_jwt client authentication. | REQUIRED if introspection_endpoint is present. Constrained by the Trust Anchor metadata policy. | Section 2 of [RFC8414] and Section 3.1.1.7 of [Ena.OAuth2] | ||
dpop_signing_alg_values_supported | The signature algorithms that the Authorization Server supports for DPoP proofs. An Authorization Server that supports DPoP MUST publish this parameter. | REQUIRED if DPoP is supported. | Section 5.1 of [RFC9449] and Section 3.1.1.10 of [Ena.OAuth2] | ||
tls_client_certificate_bound_access_tokens | Whether the Authorization Server supports access tokens bound to TLS client certificates. | OPTIONAL | Section 3.3 of [RFC8705] and Section 3.1.1.10 of [Ena.OAuth2] | ||
mtls_endpoint_aliases | Alternative endpoints for use with mutual TLS. | OPTIONAL | Section 5 of [RFC8705] and Section 3.1.1.10 of [Ena.OAuth2] | ||
protected_resources | The resource identifiers of the Protected Resources that the Authorization Server issues access tokens for. | RECOMMENDED | Section 4 of [RFC9728] and Section 3.1.1.10 of [Ena.OAuth2] | ||
require_signed_request_object | Indicates whether authorization request needs to be protected as Request Object and provided through either request or request_uri parameter | OPTIONAL | Section 10.5 of [RFC9101] and Section 7.2 of [Ena.OAuth2] | ||
require_pushed_authorization_requests | Boolean parameter indicating whether the authorization server accepts authorization request data only via PAR. If omitted, the default value is false. | OPTIONAL | Section 5 of [RFC9126] | ||
pushed_authorization_request_endpoint | The URL of the pushed authorization request endpoint at which a client can post an authorization request to exchange for a request_uri value usable at the authorization server | OPTIONAL | Section 5 of [RFC9126] and Section 3.1.1.2 of |
Table 3: Authorization Server metadata parameters.
...