We currently say: > This means the authorization server MUST compare the two URIs using simple string comparison as defined in [[RFC3986](https://www.rfc-editor.org/info/rfc3986)], Section 6.2.1. But 3986 does not actually contain a good description of the matching. We need to improve that.