Hi all,

currently it is required that if a client assertion is used for JWT client authentication, that the issuer and subject are the same. See: class line 105

However, there is no such requirement in the standard

In our use case the issuer would be the OIDC server the created the assertion and the subject would be the client id.

Similar issue to:

Best Regards, Patrick Firnkes

