← Back to plugin index

OAuth 2.0 Token Endpoint

Description

Configuration of the token endpoint for OAuth 2.0 or OpenID Connect.

The endpoint will be available under /<loginapp-uri>/rest/oauth2/authorization-servers/<as-identifier>/token

Type name
OAuth2TokenEndpoint
Class
com.airlock.iam.oauth2.application.configuration.as.OAuth2TokenEndpointConfig
May be used by
License-Tags
OAuthServer
Properties
Client Authentication (clientAuthentication)
Description
Specifies if and how requests to the token endpoint and to the 'Pushed Authorization Requests' (PAR) endpoint are authenticated.
Attributes
Plugin-Link
Optional
Assignable plugins
Scopes To Remove On Refresh (scopesToRemoveOnRefresh)
Description
List of matchers that defines the set of scopes not to be refreshed in a refresh token grant. If a scope matches against any entry in the list, it will be removed from the session and not be part of newly acquired tokens.
Attributes
Plugin-List
Optional
Assignable plugins
Issue Certificate-Bound Access Tokens (bindAccessTokens)
Description
If enabled, Certificate-Bound Access Tokens (see RFC8705) are issued.

Issued Access Tokens will be bound to the client certificate that was used for client authentication for the Token Endpoint Authentication. This will enable the "cnf" claim to be included in the Token Introspection Endpoint result as well as in the JWT Access Token (if enabled). All consumers must utilise the claim to verify the client certificate being used with the Access Token.

IAM consumes such Access Tokens (Token Revocation Endpoint, Session Management Endpoint, Resource Endpoints, UserInfo Endpoint and One-Shot Authenticators) and will therefore automatically verify the mTLS client certificate, if an Certificate-Bound Access Token is used for authorization.

Note: Currently this setting is restricted to client authentications using mTLS.

Attributes
Boolean
Optional
Default value
false
YAML Template (with default values)

type: OAuth2TokenEndpoint
id: OAuth2TokenEndpoint-xxxxxx
displayName: 
comment: 
properties:
  bindAccessTokens: false
  clientAuthentication:
  scopesToRemoveOnRefresh: