[Federation] request_object is usable at the PAR endpoint

Issue #1509 resolved
Takahiko Kawasaki created an issue

Section 10.1.1.2 of OpenID Connect Federation 1.0 says “the applicable methods are three”. However, because the PAR endpoint can accept a request object (FAPI actually requires it), the number of applicable methods at the PAR endpoint is four.

That is,

  1. private_key_jwt
  2. tls_client_auth
  3. self_signed_tls_client_auth
  4. request_object

Comments (5)

  1. Log in to comment