Skip to content

Audience Restriction for Client Assertions #41

@tlodderstedt

Description

@tlodderstedt

Do we need to be more specific about audience restriction for use the client assertion at the PAR endpoint than RFC7523?

The JWT MUST contain an "aud" (audience) claim containing a
value that identifies the authorization server as an intended
audience. The token endpoint URL of the authorization server
MAY be used as a value for an "aud" element to identify the
authorization server as an intended audience of the JWT.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions