Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.
Comment: added: require_signed_request_object, require_pushed_authorization_requests, pushed_authorization_request_endpoint

...

Parameter

Description

Requirement

Defined in

issuer

The issuer identifier of the Authorization Server. The value MUST be equal to the Authorization Server's Entity Identifier, see Section 5.1.3 of [OpenID.Federation.Connect], and MUST meet the requirements of Section 3.1.1.1 of [Ena.OAuth2].

REQUIRED

Section 2 of [RFC8414] and Section 3.1.1.1 of [Ena.OAuth2]

token_endpoint

The URL of the token endpoint.

REQUIRED

Section 2 of [RFC8414] and Section 3.1.1.2 of [Ena.OAuth2]

jwks_uri

A URL from which the Authorization Server's JSON Web Key Set can be retrieved. The URL MUST use the HTTPS scheme. The keys MUST meet the requirements of [BAS.Security].

REQUIRED

Section 2 of [RFC8414] and Section 3.1.1.3 of [Ena.OAuth2]

grant_types_supported

The grant types that the Authorization Server supports. The value MUST contain client_credentials. Without this parameter, [Ena.OAuth2] assumes the authorization_code grant type.

REQUIRED. Constrained by the Trust Anchor metadata policy to the grant types that [BAS.Rules] permits.

Section 2 of [RFC8414] and Section 3.1.1.5 of [Ena.OAuth2]

response_types_supported

The response types that the Authorization Server supports. The value is not constrained within BAS, since the client_credentials grant uses no response type.

REQUIRED

Section 2 of [RFC8414]

token_endpoint_auth_methods_supported

The client authentication methods that the token endpoint supports. The value MUST be private_key_jwt only, see Section 2 of [BAS.Security].

REQUIRED. Constrained by the Trust Anchor metadata policy.

Section 2 of [RFC8414] and Section 3.1.1.6 of [Ena.OAuth2]

token_endpoint_auth_signing_alg_values_supported

The signature algorithms that the token endpoint supports for private_key_jwt. See Section 3.1 of [BAS.Security].

REQUIRED. Constrained by the Trust Anchor metadata policy.

Section 2 of [RFC8414] and Section 3.1.1.7 of [Ena.OAuth2]

scopes_supported

The scope values that the Authorization Server supports. The values are agreed between the parties to an exchange, see Section 1.3.

REQUIRED

Section 2 of [RFC8414] and Section 3.1.1.4 of [Ena.OAuth2]

revocation_endpoint

The URL of the revocation endpoint.

OPTIONAL

Section 2 of [RFC8414]

revocation_endpoint_auth_methods_supported

The client authentication methods that the revocation endpoint supports. The value MUST be private_key_jwt only, see Section 2 of [BAS.Security].

REQUIRED if revocation_endpoint is present. Constrained by the Trust Anchor metadata policy.

Section 2 of [RFC8414] and Section 3.1.1.6 of [Ena.OAuth2]

revocation_endpoint_auth_signing_alg_values_supported


Signing algorithms supported by this endpoint for the signature on the JWT, when used with private_key_jwt client authentication.

REQUIRED if revocation_endpoint is present. Constrained by the Trust Anchor metadata policy.

Section 2 of [RFC8414] and Section 3.1.1.7 of [Ena.OAuth2]

introspection_endpoint

The URL of the introspection endpoint.

OPTIONAL

Section 2 of [RFC8414]

introspection_endpoint_auth_methods_supported

The client authentication methods that the introspection endpoint supports. The value MUST be private_key_jwt only, see Section 2 of [BAS.Security].

REQUIRED if introspection_endpoint is present. Constrained by the Trust Anchor metadata policy.

Section 2 of [RFC8414] and Section 3.1.1.6 of [Ena.OAuth2]

introspection_endpoint_auth_signing_alg_values_supported

Signing algorithms supported by this endpoint for the signature on the JWT, when used with private_key_jwt client authentication.

REQUIRED if introspection_endpoint is present. Constrained by the Trust Anchor metadata policy.

Section 2 of [RFC8414] and Section 3.1.1.7 of [Ena.OAuth2]

dpop_signing_alg_values_supported

The signature algorithms that the Authorization Server supports for DPoP proofs. An Authorization Server that supports DPoP MUST publish this parameter.

REQUIRED if DPoP is supported.

Section 5.1 of [RFC9449] and Section 3.1.1.10 of [Ena.OAuth2]

tls_client_certificate_bound_access_tokens

Whether the Authorization Server supports access tokens bound to TLS client certificates.

OPTIONAL

Section 3.3 of [RFC8705] and Section 3.1.1.10 of [Ena.OAuth2]

mtls_endpoint_aliases

Alternative endpoints for use with mutual TLS.

OPTIONAL

Section 5 of [RFC8705] and Section 3.1.1.10 of [Ena.OAuth2]

protected_resources

The resource identifiers of the Protected Resources that the Authorization Server issues access tokens for.

RECOMMENDED

Section 4 of [RFC9728] and Section 3.1.1.10 of [Ena.OAuth2]

require_signed_request_object

Indicates whether authorization request needs to be protected as Request Object and provided through either request or request_uri parameter

OPTIONAL

Section 10.5 of [RFC9101] and Section 7.2 of [Ena.OAuth2]

require_pushed_authorization_requests

Boolean parameter indicating whether the authorization server accepts authorization request data only via PAR. If omitted, the default value is false.

OPTIONAL

Section 5 of [RFC9126] 

pushed_authorization_request_endpoint

The URL of the pushed authorization request endpoint at which a client can post an authorization request to exchange for a request_uri value usable at the authorization server

OPTIONAL

Section 5 of [RFC9126] and Section 3.1.1.2 of 
[Ena.OAuth2]

Table 3: Authorization Server metadata parameters.

...