| I think I'd be okay with the IANA registry being updated to also reference PAR, alongside 6749, it's just 6749 doesn't reflect the registries's contents. My use for invalid_client is "what happens if a CIMD is invalid or contains something like token_endpoint_auth_method of private_key_jwt but does not have a jwks or jwks_uri property (which would make that authentication method fail)" Given CIMDs are fetched after authentication, this is on the authorize or token endpoint, not PAR which is before authentication (though iirc we have that just as a security consideration) I'm looking for an appropriate error response for various CIMD scenarios, and I think invalid_client or invalid_client_metadata may be most applicable. Emelia On 21. Sep 2026, at 11:48, Warren Parad <[email protected]> wrote:
|
_______________________________________________ OAuth mailing list -- [email protected] To unsubscribe send an email to [email protected]
