OAuth 2.0 Token Endpoint
Configuration of the token endpoint for OAuth 2.0 or OpenID Connect.
The endpoint will be available under /<loginapp-uri>/rest/oauth2/authorization-servers/<as-identifier>/token
clientAuthentication) scopesToRemoveOnRefresh) bindAccessTokens) Issued Access Tokens will be bound to the client certificate that was used for client authentication for the Token Endpoint Authentication. This will enable the "cnf" claim to be included in the Token Introspection Endpoint result as well as in the JWT Access Token (if enabled). All consumers must utilise the claim to verify the client certificate being used with the Access Token.
IAM consumes such Access Tokens (Token Revocation Endpoint, Session Management Endpoint, Resource Endpoints, UserInfo Endpoint and One-Shot Authenticators) and will therefore automatically verify the mTLS client certificate, if an Certificate-Bound Access Token is used for authorization.
Note: Currently this setting is restricted to client authentications using mTLS.
type: OAuth2TokenEndpoint
id: OAuth2TokenEndpoint-xxxxxx
displayName:
comment:
properties:
bindAccessTokens: false
clientAuthentication:
scopesToRemoveOnRefresh: