...
Parameter | Description | Requirement | Defined in |
|---|---|---|---|
issuer | The issuer identifier of the Authorization Server. The value MUST be equal to the Authorization Server's Entity Identifier, see Section 5.1.3 of [OpenID.Federation.Connect], and MUST meet the requirements of Section 3.1.1.1 of [Ena.OAuth2]. | REQUIRED | Section 2 of [RFC8414] and Section 3.1.1.1 of [Ena.OAuth2] |
token_endpoint | The URL of the token endpoint. | REQUIRED | Section 2 of [RFC8414] and Section 3.1.1.2 of [Ena.OAuth2] |
jwks_uri | A URL from which the Authorization Server's JSON Web Key Set can be retrieved. The URL MUST use the HTTPS scheme. The keys MUST meet the requirements of [BAS.Security]. | REQUIRED | Section 2 of [RFC8414] and Section 3.1.1.3 of [Ena.OAuth2] |
grant_types_supported | The grant types that the Authorization Server supports. The value MUST contain client_credentials. Without this parameter, [Ena.OAuth2] assumes the authorization_code grant type. | REQUIRED. Constrained by the Trust Anchor metadata policy to the grant types that [BAS.Rules] permits. | Section 2 of [RFC8414] and Section 3.1.1.5 of [Ena.OAuth2] |
response_types_supported | The response types that the Authorization Server supports. The value is not constrained within BAS, since the client_credentials grant uses no response type. | REQUIRED | Section 2 of [RFC8414] |
token_endpoint_auth_methods_supported | The client authentication methods that the token endpoint supports. The value MUST be private_key_jwt only, see Section 2 of [BAS.Security]. | REQUIRED. Constrained by the Trust Anchor metadata policy. | Section 2 of [RFC8414] and Section 3.1.1.6 of [Ena.OAuth2] |
token_endpoint_auth_signing_alg_values_supported | The signature algorithms that the token endpoint supports for private_key_jwt. See Section 3.1 of [BAS.Security]. | REQUIRED. Constrained by the Trust Anchor metadata policy. | Section 2 of [RFC8414] and Section 3.1.1.7 of [Ena.OAuth2] |
scopes_supported | The scope values that the Authorization Server supports. The values are agreed between the parties to an exchange, see Section 1.3. | REQUIRED | Section 2 of [RFC8414] and Section 3.1.1.4 of [Ena.OAuth2] |
revocation_endpoint | The URL of the revocation endpoint. | OPTIONAL | Section 2 of [RFC8414] |
revocation_endpoint_auth_methods_supported | The client authentication methods that the revocation endpoint supports. The value MUST be private_key_jwt only, see Section 2 of [BAS.Security]. | REQUIRED if revocation_endpoint is present. Constrained by the Trust Anchor metadata policy. | Section 2 of [RFC8414] and Section 3.1.1.6 of [Ena.OAuth2] |
revocation_endpoint_auth_signing_alg_values_supported | Signing algorithms supported by this endpoint for the signature on the JWT, when used with private_key_jwt client authentication. | REQUIRED if revocation_endpoint is present. Constrained by the Trust Anchor metadata policy. | Section 2 of [RFC8414] and Section 3.1.1.7 of [Ena.OAuth2] |
introspection_endpoint | The URL of the introspection endpoint. | OPTIONAL | Section 2 of [RFC8414] |
introspection_endpoint_auth_methods_supported | The client authentication methods that the introspection endpoint supports. The value MUST be private_key_jwt only, see Section 2 of [BAS.Security]. | REQUIRED if introspection_endpoint is present. Constrained by the Trust Anchor metadata policy. | Section 2 of [RFC8414] and Section 3.1.1.6 of [Ena.OAuth2] |
introspection_endpoint_auth_methodssigning_alg_values_supported | Signing algorithms supported by this endpoint for the signature on the JWT, when used with private_key_jwt client authentication. | REQUIRED if introspection_endpoint is present. Constrained by the Trust Anchor metadata policy. | Section 2 of [RFC8414] and Section 3.1.1.7 of [Ena.OAuth2] |
dpop_signing_alg_values_supported | The signature algorithms that the Authorization Server supports for DPoP proofs. An Authorization Server that supports DPoP MUST publish this parameter. | REQUIRED if DPoP is supported. | Section 5.1 of [RFC9449] and Section 3.1.1.10 of [Ena.OAuth2] |
tls_client_certificate_bound_access_tokens | Whether the Authorization Server supports access tokens bound to TLS client certificates. | OPTIONAL | Section 3.3 of [RFC8705] and Section 3.1.1.10 of [Ena.OAuth2] |
mtls_endpoint_aliases | Alternative endpoints for use with mutual TLS. | OPTIONAL | Section 5 of [RFC8705] and Section 3.1.1.10 of [Ena.OAuth2] |
protected_resources | The resource identifiers of the Protected Resources that the Authorization Server issues access tokens for. | RECOMMENDED | Section 4 of [RFC9728] and Section 3.1.1.10 of [Ena.OAuth2] |
require_signed_request_object | Indicates whether authorization request needs to be protected as Request Object and provided through either request or request_uri parameter | OPTIONAL | Section 10.5 of [RFC9101] and Section 7.2 of [Ena.OAuth2] |
require_pushed_authorization_requests | Boolean parameter indicating whether the authorization server accepts authorization request data only via PAR. If omitted, the default value is false. | OPTIONAL | Section 5 of [RFC9126] |
pushed_authorization_request_endpoint | The URL of the pushed authorization request endpoint at which a client can post an authorization request to exchange for a request_uri value usable at the authorization server | OPTIONAL | Section 5 of [RFC9126] and Section 3.1.1.2 of |
Table 3: Authorization Server metadata parameters.
...