{"id":1825,"date":"2018-04-24T15:48:46","date_gmt":"2018-04-24T22:48:46","guid":{"rendered":"https:\/\/self-issued.info\/?p=1825"},"modified":"2018-04-24T15:48:46","modified_gmt":"2018-04-24T22:48:46","slug":"late-breaking-changes-to-oauth-token-exchange-syntax","status":"publish","type":"post","link":"https:\/\/self-issued.info\/?p=1825","title":{"rendered":"Late-breaking changes to OAuth Token Exchange syntax"},"content":{"rendered":"<p><span class=\"plain\"><img decoding=\"async\" align=\"right\" src=\"https:\/\/self-issued.info\/images\/oauth_logo_120x120.png\" alt=\"OAuth logo\"\/><\/span>The syntax of two JWT claims registered by the OAuth Token Exchange specification has been changed as a result of developer feedback.  Developers pointed out that the OAuth Token Introspection specification [<a href=\"https:\/\/tools.ietf.org\/html\/rfc7662\">RFC 7662<\/a>] uses a &#8220;<code>scope<\/code>&#8221; string to represent scope values, whereas Token Exchange was defining an array-valued &#8220;<code>scp<\/code>&#8221; claim to represent scope values.  The former also uses a &#8220;<code>client_id<\/code>&#8221; element to represent OAuth Client ID values, whereas the latter was using a &#8220;<code>cid<\/code>&#8221; claim for the same purpose.<\/p>\n<p>After consulting with the working group, the OAuth Token Exchange claim names have been changed to &#8220;<code>scope<\/code>&#8221; and &#8220;<code>client_id<\/code>&#8220;.  Thanks to <a href=\"https:\/\/twitter.com\/tlodderstedt\">Torsten Lodderstedt<\/a> for pointing out the inconsistencies and to <a href=\"https:\/\/twitter.com\/__b_c\">Brian Campbell<\/a> for seeking consensus and making the updates.<\/p>\n<p>The specification is available at:<\/p>\n<ul>\n<li><a href=\"https:\/\/tools.ietf.org\/html\/draft-ietf-oauth-token-exchange-13\">https:\/\/tools.ietf.org\/html\/draft-ietf-oauth-token-exchange-13<\/a><\/li>\n<\/ul>\n<p>An HTML-formatted version is also available at:<\/p>\n<ul>\n<li><a href=\"https:\/\/self-issued.info\/docs\/draft-ietf-oauth-token-exchange-13.html\">https:\/\/self-issued.info\/docs\/draft-ietf-oauth-token-exchange-13.html<\/a><\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>The syntax of two JWT claims registered by the OAuth Token Exchange specification has been changed as a result of developer feedback. Developers pointed out that the OAuth Token Introspection specification [RFC 7662] uses a &#8220;scope&#8221; string to represent scope values, whereas Token Exchange was defining an array-valued &#8220;scp&#8221; claim to represent scope values. The [&hellip;]<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[8,32,27,26,25],"tags":[],"class_list":["post-1825","post","type-post","status-publish","format-standard","hentry","category-claims","category-ietf","category-json","category-oauth","category-specifications"],"_links":{"self":[{"href":"https:\/\/self-issued.info\/index.php?rest_route=\/wp\/v2\/posts\/1825","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/self-issued.info\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/self-issued.info\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/self-issued.info\/index.php?rest_route=\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/self-issued.info\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1825"}],"version-history":[{"count":2,"href":"https:\/\/self-issued.info\/index.php?rest_route=\/wp\/v2\/posts\/1825\/revisions"}],"predecessor-version":[{"id":1827,"href":"https:\/\/self-issued.info\/index.php?rest_route=\/wp\/v2\/posts\/1825\/revisions\/1827"}],"wp:attachment":[{"href":"https:\/\/self-issued.info\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1825"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/self-issued.info\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1825"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/self-issued.info\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1825"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}