e..g Authorization Code Flow, Implicit Flow, Hybrid Flow We should be explicit as to what we support

    Since we agreed that we need to have both the request and response signed, only the viable flow is the Hybrid Flow.

    shall require the response_type values code id_token or code id_token token;
    shall return ID Token as a detached signature to the authorization response;
    shall include state hash, s_hash, in the ID Token to protect the state value;

