← Back to plugin index

OAuth 2.0 Token Revocation Endpoint

Description

RFC 7009 Token Revocation endpoint allows clients to revoke Access and Refresh Tokens.

The endpoint is available under /<loginapp-uri>/rest/oauth2/authorization-servers/<as-identifier>/revoke

Type name
OAuth2TokenRevocation
Class
com.airlock.iam.oauth2.application.configuration.revocation.OAuth2TokenRevocationConfig
May be used by
License-Tags
OAuthServer
Properties
Access Token Revocation Strategy (accessTokenInvalidationStrategy)
Description
If the revoked token is an access token, this property defines which tokens to invalidate.
Attributes
Plugin-Link
Optional
Assignable plugins
Refresh Token Revocation Strategy (refreshTokenInvalidationStrategy)
Description
If the revoked token is a refresh token, this property defines which tokens to invalidate.
Attributes
Plugin-Link
Optional
Assignable plugins
Authentication Method (authenticationMethod)
Description

Enforce the client authentication of the token revocation endpoint.

  • BASIC_AUTH: Basic Authentication using the client id and secret, see RFC 6749.
  • POST_PARAM: Authentication is done using the POST parameters client_id and client_secret, see RFC 6749.
    Warning: Including the client credentials in the request-body using the two parameters is not recommended for security reasons.
  • NONE: No authentication required (should only used for public clients without any credentials). However, a client_id parameter must still be provided.
Attributes
Enum
Optional
Default value
BASIC_AUTH
YAML Template (with default values)

type: OAuth2TokenRevocation
id: OAuth2TokenRevocation-xxxxxx
displayName: 
comment: 
properties:
  accessTokenInvalidationStrategy:
  authenticationMethod: BASIC_AUTH
  refreshTokenInvalidationStrategy: