Rolling claims builder, which uses short-lived tokens to perform authorization.
Kong uses 3 services to complete Client and User authentication;
- Request Token
- IF Requires User, Authenticate
- Introspect / Call Resource
Clients must request a token before calling a resource
- Verify that Client exists
- Verify Client secret
- Validate requested Scopes against the client's allowed scopes
- When User is required, Validate UserToken
- Assign consented claims provided by requested Scopes
- Encrypt Token