Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.
Comment: added: require_signed_request_object, require_pushed_authorization_requests, pushed_authorization_request_endpoint

...

The table below covers the metadata parameters that a Client publishes in its oauth_client metadata, in addition to those in Section 3. The parameters are defined in Section 2 of [RFC7591], and profiled by Section 2.2.2 of [Ena.OAuth2]. This version of the document covers Clients that use the client_credentials grant, which is the grant type that [BAS.Rules] permits. Parameters that apply only to other grant types, such as redirect_uris, require_signed_request_object and require_pushed_authorization_requests, are therefore not used. The token_endpoint_auth_signing_alg parameter defined by [OpenID.Registration] is not used either, since a Client in BAS does not declare the algorithm it signs with, see Section 4.2.

Parameter

Description

Requirement

Defined in

token_endpoint_auth_method

The method by which the Client authenticates at the token endpoint of an Authorization Server. The value MUST be private_key_jwt, see Section 4.2.

REQUIRED. Constrained by the Trust Anchor metadata policy.

Section 2 of [RFC7591] and Section 2.2.2.2 of [Ena.OAuth2]

jwks

The Client's JSON Web Key Set, included by value. The Client MUST publish its keys using either jwks or jwks_uri, but not both, see Section 2.2.2.4 of [Ena.OAuth2]. The keys MUST meet the requirements of [BAS.Security].

REQUIRED, unless jwks_uri is used.

Section 2 of [RFC7591] and Section 5.2.1 of [OpenID.Federation]

jwks_uri

A URL from which the Client's JSON Web Key Set can be retrieved. The URL MUST use the HTTPS scheme. The keys MUST meet the requirements of [BAS.Security].

REQUIRED, unless jwks is used.

Section 2 of [RFC7591] and Section 5.2.1 of [OpenID.Federation]

grant_types

The grant types that the Client uses. The value MUST contain client_credentials. Without this parameter, [RFC7591] and [Ena.OAuth2] assume the authorization_code grant type.

REQUIRED. Constrained by the Trust Anchor metadata policy to the grant types that [BAS.Rules] permits.

Section 2 of [RFC7591] and Section 2.2.2.3 of [Ena.OAuth2]

redirect_uris

Array of redirection URIs for use in redirect-based flows

REQUIRED if the client is registered for the authorization_code grant type

Section 2 of [RFC7591] and Section 2.2.2.1 of [Ena.OAuth2]

response_types

The response types that the Client uses. The value MUST be an empty array, since the client_credentials grant uses no response type. Without this parameter, [RFC7591] assumes the code response type.

REQUIRED. Assigned by the Trust Anchor metadata policy. OPTIONAL for the Client to supply.

Section 2 of [RFC7591]

client_name

A human-readable name of the Client, provided in Swedish and English, see Section 2. If display_name is not supplied, its value is taken from client_name, see Section 3.

OPTIONAL

Section 2 of [RFC7591] and Section 2.2.2.6 of [Ena.OAuth2]

scope

The scope values that the Client can use when requesting access tokens. The values are agreed between the parties to an exchange, see Section 1.3.

OPTIONAL

Section 2 of [RFC7591] and Section 2.2.2.5 of [Ena.OAuth2]

dpop_bound_access_tokens

Whether the Client always uses DPoP [RFC9449] when requesting access tokens. A Client that does so MUST set this parameter to true.

OPTIONAL

Section 5.2 of [RFC9449] and Section 2.2.2.7 of [Ena.OAuth2]

tls_client_certificate_bound_access_tokens

Whether the Client requests access tokens bound to its TLS client certificate [RFC8705]. A Client that does so MUST set this parameter to true.

OPTIONAL

Section 3.4 of [RFC8705] and Section 2.2.2.7 of [Ena.OAuth2]

Table 2: Client metadata parameters.

...

An Authorization Server also publishes its metadata at the location stated in Section 3.1.2 of [Ena.OAuth2]. For every parameter that appears in both, the metadata published there MUST be consistent with the Authorization Server's Resolved Metadata. Where the Trust Anchor metadata policy removes values that the Authorization Server supports outside BAS, such as other grant types or client authentication methods, the value in the Resolved Metadata is a subset of the published value, and the two are consistent in this sense.

The client authentication methods that the introspection endpoint supports. The dpop

Parameter

Description

Requirement

Defined in

issuer

The issuer identifier of the Authorization Server. The value MUST be equal to the Authorization Server's Entity Identifier, see Section 5.1.3 of [OpenID.Federation.Connect], and MUST meet the requirements of Section 3.1.1.1 of [Ena.OAuth2].

REQUIRED

Section 2 of [RFC8414] and Section 3.1.1.1 of [Ena.OAuth2]

token_endpoint

The URL of the token endpoint.

REQUIRED

Section 2 of [RFC8414] and Section 3.1.1.2 of [Ena.OAuth2]

jwks_uri

A URL from which the Authorization Server's JSON Web Key Set can be retrieved. The URL MUST use the HTTPS scheme. The keys MUST meet the requirements of [BAS.Security].

REQUIRED

Section 2 of [RFC8414] and Section 3.1.1.3 of [Ena.OAuth2]

grant_types_supported

The grant types that the Authorization Server supports. The value MUST contain client_credentials. Without this parameter, [Ena.OAuth2] assumes the authorization_code grant type.

REQUIRED. Constrained by the Trust Anchor metadata policy to the grant types that [BAS.Rules] permits.

Section 2 of [RFC8414] and Section 3.1.1.5 of [Ena.OAuth2]

response_types_supported

The response types that the Authorization Server supports. The value is not constrained within BAS, since the client_credentials grant uses no response type.

REQUIRED

Section 2 of [RFC8414]

token_endpoint_auth_methods_supported

The client authentication methods that the token endpoint supports. The value MUST be private_key_jwt only, see Section 2 of [BAS.Security].

REQUIRED. Constrained by the Trust Anchor metadata policy.

Section 2 of [RFC8414] and Section 3.1.1.6 of [Ena.OAuth2]

token_endpoint_auth_signing_alg_values_supported

The signature algorithms that the token endpoint supports for private_key_jwt. See Section 3.1 of [BAS.Security].

REQUIRED. Constrained by the Trust Anchor metadata policy.

Section 2 of [RFC8414] and Section 3.1.1.7 of [Ena.OAuth2]

scopes_supported

The scope values that the Authorization Server supports. The values are agreed between the parties to an exchange, see Section 1.3.

REQUIRED

Section 2 of [RFC8414] and Section 3.1.1.4 of [Ena.OAuth2]

revocation_endpoint

The URL of the revocation endpoint.

OPTIONAL

Section 2 of [RFC8414]

revocation_endpoint_auth_methods_supported

The client authentication methods that the revocation endpoint supports. The value MUST be private_key_jwt only, see Section 2 of [BAS.Security].

REQUIRED if revocation_endpoint is present. Constrained by the Trust Anchor metadata policy.

Section 2 of [RFC8414] and Section 3.1.1.6 of [Ena.OAuth2]

introspection_endpoint

The URL of the introspection endpoint.

OPTIONAL

Section 2 of [RFC8414]

revocation_endpoint_auth_signing_alg_values_supported


Signing algorithms supported by this endpoint for the signature on the JWT, when used with private_key_jwt client authentication.

REQUIRED if revocation_endpoint is present. Constrained by the Trust Anchor metadata policy.

Section 2 of [RFC8414] and Section 3.1.1.7 of [Ena.OAuth2]

introspection_endpoint

The URL of the introspection endpoint.

OPTIONAL

Section 2 of [RFC8414]

introspection_endpoint_auth_methods_supported

The client authentication methods that the introspection endpoint supports. The

introspection_endpoint_auth_methods_supported

value MUST be private_key_jwt only, see Section 2 of [BAS.Security].

REQUIRED if introspection_endpoint is present. Constrained by the Trust Anchor metadata policy.

Section 2 of [RFC8414] and Section 3.1.1.6 of [Ena.OAuth2]

introspection_endpoint_auth_signing_alg_values_supported

Signing algorithms supported by this endpoint for the signature on the JWT, when used with private_key_jwt client authentication.

REQUIRED if introspection_endpoint is present. Constrained by the Trust Anchor metadata policy.

Section 2 of [RFC8414] and Section 3.1.1.7 of [Ena.OAuth2]

dpop_signing_alg_values_supported

The signature algorithms that the Authorization Server supports for DPoP proofs. An Authorization Server that supports DPoP MUST publish this parameter.

REQUIRED if DPoP is supported.

Section 5.1 of [RFC9449] and Section 3.1.1.10 of [Ena.OAuth2]

tls_client_certificate_bound_access_tokens

Whether the Authorization Server supports access tokens bound to TLS client certificates.

OPTIONAL

Section 3.3 of [RFC8705] and Section 3.1.1.10 of [Ena.OAuth2]

mtls_endpoint_aliases

Alternative endpoints for use with mutual TLS.

OPTIONAL

Section 5 of [RFC8705] and Section 3.1.1.10 of [Ena.OAuth2]

protected_resources

The resource identifiers of the Protected Resources that the Authorization Server issues access tokens for.

RECOMMENDED

Section 4 of [RFC9728] and Section 3.1.1.10 of [Ena.OAuth2]

require_signed_request_object

Indicates whether authorization request needs to be protected as Request Object and provided through either request or request_uri parameter

OPTIONAL

Section 10.5 of [RFC9101] and Section 7.2 of [Ena.OAuth2]

require_pushed_authorization_requests

Boolean parameter indicating whether the authorization server accepts authorization request data only via PAR. If omitted, the default value is false.

OPTIONAL

Section 5 of [RFC9126] 

pushed_authorization_request_endpoint

The URL of the pushed authorization request endpoint at which a client can post an authorization request to exchange for a request_uri value usable at the authorization server

OPTIONAL

Section 5 of [RFC9126] and Section 3.1.1.2 of 
[Ena.OAuth2]

Table 3: Authorization Server metadata parameters.

...