Skip to content

Specify how OAuth server determines appropriate audience for Access Token #13

Description

@jbasney

The OAuth Authorization Request includes the desired scope(s) but not the desired audience. We need a token that can be used with other relying parties, so the audience isn't just the requester's client_id. We need to understand the right flow for this.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions