{"id":1591,"date":"2016-08-03T13:55:11","date_gmt":"2016-08-03T20:55:11","guid":{"rendered":"https:\/\/self-issued.info\/?p=1591"},"modified":"2016-08-03T13:55:11","modified_gmt":"2016-08-03T20:55:11","slug":"oauth-metadata-specifications-enhanced","status":"publish","type":"post","link":"https:\/\/self-issued.info\/?p=1591","title":{"rendered":"OAuth Metadata Specifications Enhanced"},"content":{"rendered":"<p><span class=\"plain\"><img decoding=\"async\" align=\"right\" src=\"https:\/\/self-issued.info\/images\/oauth_logo_120x120.png\" alt=\"OAuth logo\"\/><\/span>The existing <a href=\"https:\/\/tools.ietf.org\/html\/draft-ietf-oauth-discovery\">OAuth 2.0 Authorization Server Metadata<\/a> specification has now been joined by a related <a href=\"https:\/\/tools.ietf.org\/html\/draft-jones-oauth-resource-metadata\">OAuth 2.0 Protected Resource Metadata<\/a> specification.  This means that JSON metadata formats are now defined for all the OAuth 2.0 parties: clients, authorization servers, and protected resources.<\/p>\n<p>The most significant addition to the OAuth 2.0 Authorization Server Metadata specification is enabling signed metadata, represented as claims in a JSON Web Token (JWT).  This is analogous to the role that the Software Statement plays in OAuth Dynamic Client Registration.  Signed metadata can also be used for protected resource metadata.<\/p>\n<p>For use cases in which the set of protected resources used with an authorization server are enumerable, the authorization server metadata specification now defines the &#8220;<code>protected_resources<\/code>&#8221; metadata value to list them.  Likewise, the protected resource metadata specification defines an &#8220;<code>authorization_servers<\/code>&#8221; metadata value to list the authorization servers that can be used with a protected resource, for use cases in which those are enumerable.<\/p>\n<p>The specifications are available at:<\/p>\n<ul>\n<li><a href=\"http:\/\/tools.ietf.org\/html\/draft-ietf-oauth-discovery-04\">http:\/\/tools.ietf.org\/html\/draft-ietf-oauth-discovery-04<\/a><\/li>\n<li><a href=\"http:\/\/tools.ietf.org\/html\/draft-jones-oauth-resource-metadata-00\">http:\/\/tools.ietf.org\/html\/draft-jones-oauth-resource-metadata-00<\/a><\/li>\n<\/ul>\n<p>HTML-formatted versions are also available at:<\/p>\n<ul>\n<li><a href=\"https:\/\/self-issued.info\/docs\/draft-ietf-oauth-discovery-04.html\">https:\/\/self-issued.info\/docs\/draft-ietf-oauth-discovery-04.html<\/a><\/li>\n<li><a href=\"https:\/\/self-issued.info\/docs\/draft-jones-oauth-resource-metadata-00.html\">https:\/\/self-issued.info\/docs\/draft-jones-oauth-resource-metadata-00.html<\/a><\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>The existing OAuth 2.0 Authorization Server Metadata specification has now been joined by a related OAuth 2.0 Protected Resource Metadata specification. This means that JSON metadata formats are now defined for all the OAuth 2.0 parties: clients, authorization servers, and protected resources. The most significant addition to the OAuth 2.0 Authorization Server Metadata specification is [&hellip;]<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[8,27,26,25],"tags":[],"class_list":["post-1591","post","type-post","status-publish","format-standard","hentry","category-claims","category-json","category-oauth","category-specifications"],"_links":{"self":[{"href":"https:\/\/self-issued.info\/index.php?rest_route=\/wp\/v2\/posts\/1591","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/self-issued.info\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/self-issued.info\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/self-issued.info\/index.php?rest_route=\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/self-issued.info\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1591"}],"version-history":[{"count":4,"href":"https:\/\/self-issued.info\/index.php?rest_route=\/wp\/v2\/posts\/1591\/revisions"}],"predecessor-version":[{"id":1595,"href":"https:\/\/self-issued.info\/index.php?rest_route=\/wp\/v2\/posts\/1591\/revisions\/1595"}],"wp:attachment":[{"href":"https:\/\/self-issued.info\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1591"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/self-issued.info\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1591"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/self-issued.info\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1591"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}