The ID1 of Grant Management for OAuth 2.0 does not mention explicitly that the grant management endpoint should (or must) utilize TLS. If it is written explicitly, an authorization server implementation will be able to have a justifiable reason to prevent any non-https URI from being registered as a value for grant_management_endpoint.

cf. Excerpt from CIBA Core 1.0, 7. Backchannel Authentication Endpoint

Communication with the Backchannel Authentication Endpoint MUST utilize TLS. See Section 16.17 [OpenID.Core] for more information on using TLS.

