Internet Assigned Numbers Authority • Domains • Protocols • Numbers • About OAuth Parameters Created 2012-07-27 Last Updated 2026-08-03 Available Formats [IMG] XML [IMG] HTML [IMG] Plain text Registries Included Below • OAuth Access Token Types • OAuth Authorization Endpoint Response Types • OAuth Extensions Error Registry • OAuth Parameters • OAuth Token Type Hints • OAuth URI • OAuth Dynamic Client Registration Metadata • OAuth Token Endpoint Authentication Methods • PKCE Code Challenge Methods • OAuth Token Introspection Response • OAuth Authorization Server Metadata • OAuth Protected Resource Metadata • OAuth Status Types OAuth Access Token Types Registration Procedure(s) Specification Required Expert(s) Hannes Tschofenig, Mike Jones Reference [RFC6749][RFC8414] Note Registration requests should be sent to [oauth-ext-review@ietf.org], as described in [RFC6749]. If they approve, designated experts should notify IANA within two weeks. For assistance, please contact iana@iana.org. IANA does not monitor the list. Available Formats [IMG] CSV Name Additional Token Endpoint Response Parameters HTTP Authentication Scheme(s) Change Controller Reference Bearer Bearer IETF [RFC6750] N_A IESG [RFC8693, Section 2.2.1] PoP cnf, rs_cnf (see [RFC8747, Section 3.1] and [RFC9201, Section 3.2]). N/A IETF [RFC9200] DPoP DPoP IETF [RFC9449] OAuth Authorization Endpoint Response Types Registration Procedure(s) Specification Required Expert(s) Hannes Tschofenig, Mike Jones Reference [RFC6749] Note Registration requests should be sent to [oauth-ext-review@ietf.org], as described in [RFC6749]. If they approve, designated experts should notify IANA within two weeks. For assistance, please contact iana@iana.org. IANA does not monitor the list. Available Formats [IMG] CSV Name Change Controller Reference code IETF [RFC6749] code id_token [OpenID_Foundation_Artifact_Binding_WG] [OAuth 2.0 Multiple Response Type Encoding Practices] code id_token token [OpenID_Foundation_Artifact_Binding_WG] [OAuth 2.0 Multiple Response Type Encoding Practices] code token [OpenID_Foundation_Artifact_Binding_WG] [OAuth 2.0 Multiple Response Type Encoding Practices] id_token [OpenID_Foundation_Artifact_Binding_WG] [OAuth 2.0 Multiple Response Type Encoding Practices] id_token token [OpenID_Foundation_Artifact_Binding_WG] [OAuth 2.0 Multiple Response Type Encoding Practices] none [OpenID_Foundation_Artifact_Binding_WG] [OAuth 2.0 Multiple Response Type Encoding Practices] token IETF [RFC6749] vp_token [OpenID_Foundation_Digital_Credentials_Protocols_WG] [OpenID for Verifiable Presentations 1.0, Section 8] vp_token id_token [OpenID_Foundation_Digital_Credentials_Protocols_WG] [OpenID for Verifiable Presentations 1.0, Section 8] OAuth Extensions Error Registry Registration Procedure(s) Specification Required Expert(s) Hannes Tschofenig, Mike Jones Reference [RFC6749] Note Registration requests should be sent to [oauth-ext-review@ietf.org], as described in [RFC6749]. If they approve, designated experts should notify IANA within two weeks. For assistance, please contact iana@iana.org. IANA does not monitor the list. Available Formats [IMG] CSV Name Usage Location Protocol Extension Change Controller Reference authorization endpoint, OAuth 2.0 invalid_request token endpoint, Authorization IETF [RFC6749][RFC6750] resource access error Framework, bearer response access token type authorization endpoint, OAuth 2.0 unauthorized_client token endpoint Authorization IETF [RFC6749] Framework OAuth 2.0 access_denied authorization endpoint Authorization IETF [RFC6749] Framework OAuth 2.0 unsupported_response_type authorization endpoint Authorization IETF [RFC6749] Framework authorization endpoint, OAuth 2.0 invalid_scope token endpoint Authorization IETF [RFC6749] Framework OAuth 2.0 server_error authorization endpoint Authorization IETF [RFC6749] Framework OAuth 2.0 temporarily_unavailable authorization endpoint Authorization IETF [RFC6749] Framework token endpoint, OAuth 2.0 invalid_client authorization endpoint Authorization IETF [RFC6749] Framework OAuth 2.0 invalid_grant token endpoint Authorization IETF [RFC6749] Framework OAuth 2.0 unsupported_grant_type token endpoint Authorization IETF [RFC6749] Framework invalid_token resource access error bearer access token IETF [RFC6750] response type insufficient_scope resource access error bearer access token IETF [RFC6750] response type unsupported_token_type revocation endpoint token revocation IETF [RFC7009] error response endpoint [OpenID Connect Core interaction_required authorization endpoint OpenID Connect [OpenID_Foundation_Artifact_Binding_WG] 1.0 incorporating errata set 1] [OpenID Connect Core login_required authorization endpoint OpenID Connect [OpenID_Foundation_Artifact_Binding_WG] 1.0 incorporating errata set 1] [OpenID Connect Core account_selection_required authorization endpoint OpenID Connect [OpenID_Foundation_Artifact_Binding_WG] 1.0 incorporating errata set 1] [OpenID Connect Core consent_required authorization endpoint OpenID Connect [OpenID_Foundation_Artifact_Binding_WG] 1.0 incorporating errata set 1] [OpenID Connect Core invalid_request_uri authorization endpoint OpenID Connect [OpenID_Foundation_Artifact_Binding_WG] 1.0 incorporating errata set 1] [OpenID Connect Core invalid_request_object authorization endpoint OpenID Connect [OpenID_Foundation_Artifact_Binding_WG] 1.0 incorporating errata set 1] [OpenID Connect Core request_not_supported authorization endpoint OpenID Connect [OpenID_Foundation_Artifact_Binding_WG] 1.0 incorporating errata set 1] [OpenID Connect Core request_uri_not_supported authorization endpoint OpenID Connect [OpenID_Foundation_Artifact_Binding_WG] 1.0 incorporating errata set 1] [OpenID Connect Core registration_not_supported authorization endpoint OpenID Connect [OpenID_Foundation_Artifact_Binding_WG] 1.0 incorporating errata set 1] need_info (and its subsidiary authorization server [UMA 2.0 Grant for parameters) response, token Kantara UMA [Kantara_UMA_WG] OAuth 2.0, Section endpoint 3.3.6] authorization server [UMA 2.0 Grant for request_denied response, token Kantara UMA [Kantara_UMA_WG] OAuth 2.0, Section endpoint 3.3.6] request_submitted (and its authorization server [UMA 2.0 Grant for subsidiary parameters) response, token Kantara UMA [Kantara_UMA_WG] OAuth 2.0, Section endpoint 3.3.6] invalid_redirect_uri registration endpoint Dynamic Client IETF [RFC7591, Section Registration 3.2.2] invalid_client_metadata registration endpoint Dynamic Client IETF [RFC7591, Section Registration 3.2.2] invalid_software_statement registration endpoint Dynamic Client IETF [RFC7591, Section Registration 3.2.2] unapproved_software_statement registration endpoint Dynamic Client IETF [RFC7591, Section Registration 3.2.2] authorization_pending Token endpoint response [RFC8628] IETF [RFC8628, Section 3.5] access_denied Token endpoint response [RFC8628] IETF [RFC8628, Section 3.5] slow_down Token endpoint response [RFC8628] IETF [RFC8628, Section 3.5] expired_token Token endpoint response [RFC8628] IETF [RFC8628, Section 3.5] implicit grant error invalid_target response, token error resource parameter IESG [RFC8707] response unsupported_pop_key token error response [RFC9200] IETF [RFC9200, Section 5.8.3] incompatible_ace_profiles token error response [RFC9200] IETF [RFC9200, Section 5.8.3] token endpoint, OAuth 2.0 Rich invalid_authorization_details authorization endpoint Authorization IETF [RFC9396, Section 5] Requests token error response, Demonstrating Proof invalid_dpop_proof resource access error of Possession IETF [RFC9449] response (DPoP) token error response, Demonstrating Proof use_dpop_nonce resource access error of Possession IETF [RFC9449] response (DPoP) resource access error OAuth 2.0 Step Up insufficient_user_authentication response Authentication IETF [RFC9470, Section 3] Challenge Protocol [Section 8.9 of invalid_issuer authorization endpoint OpenID Federation [OpenID_Foundation_Artifact_Binding_WG] OpenID Federation 1.0] [Section 8.9 of invalid_subject authorization endpoint OpenID Federation [OpenID_Foundation_Artifact_Binding_WG] OpenID Federation 1.0] [Section 8.9 of invalid_trust_anchor authorization endpoint OpenID Federation [OpenID_Foundation_Artifact_Binding_WG] OpenID Federation 1.0] [Section 8.9 of invalid_trust_chain authorization endpoint OpenID Federation [OpenID_Foundation_Artifact_Binding_WG] OpenID Federation 1.0] [Section 8.9 of invalid_metadata authorization endpoint OpenID Federation [OpenID_Foundation_Artifact_Binding_WG] OpenID Federation 1.0] [Section 8.9 of not_found authorization endpoint OpenID Federation [OpenID_Foundation_Artifact_Binding_WG] OpenID Federation 1.0] [Section 8.9 of unsupported_parameter authorization endpoint OpenID Federation [OpenID_Foundation_Artifact_Binding_WG] OpenID Federation 1.0] OpenID for [OpenID for vp_formats_not_supported authorization endpoint, Verifiable [OpenID_Foundation_Digital_Credentials_Protocols_WG] Verifiable token endpoint Presentations Presentations 1.0, Section 8.5] OpenID for [OpenID for invalid_request_uri_method authorization endpoint Verifiable [OpenID_Foundation_Digital_Credentials_Protocols_WG] Verifiable Presentations Presentations 1.0, Section 8.5] OpenID for [OpenID for wallet_unavailable authorization endpoint, Verifiable [OpenID_Foundation_Digital_Credentials_Protocols_WG] Verifiable token endpoint Presentations Presentations 1.0, Section 8.5] OAuth Parameters Registration Procedure(s) Specification Required Expert(s) Hannes Tschofenig, Mike Jones Reference [RFC6749] Note Registration requests should be sent to [oauth-ext-review@ietf.org], as described in [RFC6749]. If they approve, designated experts should notify IANA within two weeks. For assistance, please contact iana@iana.org. IANA does not monitor the list. Available Formats [IMG] CSV Name Parameter Usage Location Change Controller Reference client_id authorization request, IETF [RFC6749] token request client_secret token request IETF [RFC6749] response_type authorization request IETF [RFC6749] redirect_uri authorization request, IETF [RFC6749] token request authorization request, scope authorization response, IETF [RFC6749] token request, token response state authorization request, IETF [RFC6749] authorization response code authorization response, IETF [RFC6749] token request error authorization response, IETF [RFC6749] token response error_description authorization response, IETF [RFC6749] token response error_uri authorization response, IETF [RFC6749] token response grant_type token request IETF [RFC6749] access_token authorization response, IETF [RFC6749] token response token_type authorization response, IETF [RFC6749] token response expires_in authorization response, IETF [RFC6749] token response username token request IETF [RFC6749] password token request IETF [RFC6749] refresh_token token request, token IETF [RFC6749] response nonce authorization request [OpenID_Foundation_Artifact_Binding_WG] [OpenID Connect Core 1.0 incorporating errata set 1] display authorization request [OpenID_Foundation_Artifact_Binding_WG] [OpenID Connect Core 1.0 incorporating errata set 1] prompt authorization request [OpenID_Foundation_Artifact_Binding_WG] [OpenID Connect Core 1.0 incorporating errata set 1] max_age authorization request [OpenID_Foundation_Artifact_Binding_WG] [OpenID Connect Core 1.0 incorporating errata set 1] ui_locales authorization request [OpenID_Foundation_Artifact_Binding_WG] [OpenID Connect Core 1.0 incorporating errata set 1] claims_locales authorization request [OpenID_Foundation_Artifact_Binding_WG] [OpenID Connect Core 1.0 incorporating errata set 1] id_token_hint authorization request [OpenID_Foundation_Artifact_Binding_WG] [OpenID Connect Core 1.0 incorporating errata set 1] login_hint authorization request [OpenID_Foundation_Artifact_Binding_WG] [OpenID Connect Core 1.0 incorporating errata set 1] acr_values authorization request [OpenID_Foundation_Artifact_Binding_WG] [OpenID Connect Core 1.0 incorporating errata set 1] claims authorization request [OpenID_Foundation_Artifact_Binding_WG] [OpenID Connect Core 1.0 incorporating errata set 1] registration authorization request [OpenID_Foundation_Artifact_Binding_WG] [OpenID Connect Core 1.0 incorporating errata set 1] request authorization request [OpenID_Foundation_Artifact_Binding_WG] [OpenID Connect Core 1.0 incorporating errata set 1] request_uri authorization request [OpenID_Foundation_Artifact_Binding_WG] [OpenID Connect Core 1.0 incorporating errata set 1] id_token authorization response, [OpenID_Foundation_Artifact_Binding_WG] [OpenID Connect Core 1.0 incorporating errata access token response set 1] session_state authorization response, [OpenID_Foundation_Artifact_Binding_WG] [OpenID Connect Session Management 1.0, Section access token response 2] assertion token request IESG [RFC7521] client_assertion token request IESG [RFC7521] client_assertion_type token request IESG [RFC7521] code_verifier token request IESG [RFC7636] code_challenge authorization request IESG [RFC7636] code_challenge_method authorization request IESG [RFC7636] claim_token client request, token [Kantara_UMA_WG] [UMA 2.0 Grant for OAuth 2.0, Section 3.3.1] endpoint pct client request, token [Kantara_UMA_WG] [UMA 2.0 Grant for OAuth 2.0, Section 3.3.1] endpoint pct authorization server [Kantara_UMA_WG] [UMA 2.0 Grant for OAuth 2.0, Section 3.3.5] response, token endpoint rpt client request, token [Kantara_UMA_WG] [UMA 2.0 Grant for OAuth 2.0, Section 3.3.1] endpoint ticket client request, token [Kantara_UMA_WG] [UMA 2.0 Grant for OAuth 2.0, Section 3.3.1] endpoint upgraded authorization server [Kantara_UMA_WG] [UMA 2.0 Grant for OAuth 2.0, Section 3.3.5] response, token endpoint vtr authorization request, IESG [RFC8485] token request device_code token request IESG [RFC8628, Section 3.1] resource authorization request, IESG [RFC8707] token request audience token request IESG [RFC8693, Section 2.1] requested_token_type token request IESG [RFC8693, Section 2.1] subject_token token request IESG [RFC8693, Section 2.1] subject_token_type token request IESG [RFC8693, Section 2.1] actor_token token request IESG [RFC8693, Section 2.1] actor_token_type token request IESG [RFC8693, Section 2.1] issued_token_type token response IESG [RFC8693, Section 2.2.1] response_mode Authorization Request [OpenID_Foundation_Artifact_Binding_WG] [OAuth 2.0 Multiple Response Type Encoding Practices] nfv_token Access Token Response [ETSI] [ETSI GS NFV-SEC 022 V2.7.1] iss authorization request, IETF [RFC9207, Section 2][RFC9101][RFC7519, Section authorization response 4.1.1] sub authorization request IETF [RFC7519, Section 4.1.2][RFC9101] aud authorization request IETF [RFC7519, Section 4.1.3][RFC9101] exp authorization request IETF [RFC7519, Section 4.1.4][RFC9101] nbf authorization request IETF [RFC7519, Section 4.1.5][RFC9101] iat authorization request IETF [RFC7519, Section 4.1.6][RFC9101] jti authorization request IETF [RFC7519, Section 4.1.7][RFC9101] ace_profile token response IETF [RFC9200, Sections 5.8.2, 5.8.4.3] nonce1 client-rs request IETF [RFC9203] nonce2 rs-client response IETF [RFC9203] ace_client_recipientid client-rs request IETF [RFC9203] ace_server_recipientid rs-client response IETF [RFC9203] req_cnf token request IETF [RFC9201, Section 5] rs_cnf token response IETF [RFC9201, Section 5] cnf token response IETF [RFC9201, Section 5] authorization request, authorization_details token request, token IETF [RFC9396] response dpop_jkt authorization request IETF [RFC9449, Section 10] sign_info client-rs request, IETF [RFC9594] rs-client response kdcchallenge rs-client response IETF [RFC9594] trust_chain authorization request [OpenID_Foundation_Artifact_Binding_WG] [Section 12.1.1.1.1 of OpenID Federation 1.0] dcql_query authorization request [OpenID_Foundation_Digital_Credentials_Protocols_WG] [OpenID for Verifiable Presentations 1.0, Section 5.1] client_metadata authorization request [OpenID_Foundation_Digital_Credentials_Protocols_WG] [OpenID for Verifiable Presentations 1.0, Section 5.1] request_uri_method authorization request [OpenID_Foundation_Digital_Credentials_Protocols_WG] [OpenID for Verifiable Presentations 1.0, Section 5.1] transaction_data authorization request [OpenID_Foundation_Digital_Credentials_Protocols_WG] [OpenID for Verifiable Presentations 1.0, Section 5.1] wallet_nonce authorization request, [OpenID_Foundation_Digital_Credentials_Protocols_WG] [OpenID for Verifiable Presentations 1.0, token response Section 5.10] response_uri authorization request [OpenID_Foundation_Digital_Credentials_Protocols_WG] [OpenID for Verifiable Presentations 1.0, Section 8.2] vp_token authorization request, [OpenID_Foundation_Digital_Credentials_Protocols_WG] [OpenID for Verifiable Presentations 1.0, token response Section 8.1] verifier_info authorization request [OpenID_Foundation_Digital_Credentials_Protocols_WG] [OpenID for Verifiable Presentations 1.0, Section 5.1] expected_origins authorization request [OpenID_Foundation_Digital_Credentials_Protocols_WG] [OpenID for Verifiable Presentations 1.0, Appendix A.2] ecdh_info client-rs request, IETF [RFC-ietf-ace-key-groupcomm-oscore-21] rs-client response kdc_dh_creds client-rs request, IETF [RFC-ietf-ace-key-groupcomm-oscore-21] rs-client response OAuth Token Type Hints Registration Procedure(s) Specification Required Expert(s) Torsten Lodderstedt, Mike Jones Reference [RFC7009] Note Registration requests should be sent to [oauth-ext-review@ietf.org], as described in [RFC7009]. If they approve, designated experts should notify IANA within two weeks. For assistance, please contact iana@iana.org. IANA does not monitor the list. Available Formats [IMG] CSV Hint Value Change Controller Reference access_token IETF [RFC7009] refresh_token IETF [RFC7009] pct [Kantara_UMA_WG] [UMA 2.0 Grant for OAuth 2.0, Section 3.7] OAuth URI Registration Procedure(s) Specification Required Expert(s) Hannes Tschofenig, Mike Jones Reference [RFC6755] Note Prefix: urn:ietf:params:oauth Available Formats [IMG] CSV URN Common Name Change Controller Reference urn:ietf:params:oauth:grant-type:jwt-bearer JWT Bearer Token Grant Type Profile IESG [RFC7523][RFC-ietf-oauth-rfc7523bis-11] for OAuth 2.0 urn:ietf:params:oauth:client-assertion-type:jwt-bearer JWT Bearer Token Profile for OAuth IESG [RFC7523][RFC-ietf-oauth-rfc7523bis-11] 2.0 Client Authentication urn:ietf:params:oauth:grant-type:saml2-bearer SAML 2.0 Bearer Assertion Grant IESG [RFC7522][RFC-ietf-oauth-rfc7523bis-11] Type Profile for OAuth 2.0 urn:ietf:params:oauth:client-assertion-type:saml2-bearer SAML 2.0 Bearer Assertion Profile IESG [RFC7522][RFC-ietf-oauth-rfc7523bis-11] for OAuth 2.0 Client Authentication urn:ietf:params:oauth:token-type:jwt JSON Web Token (JWT) Token Type IESG [RFC7519] urn:ietf:params:oauth:grant-type:device_code Device flow grant type for OAuth IESG [RFC8628, Section 3.1] 2.0 urn:ietf:params:oauth:grant-type:token-exchange Token exchange grant type for OAuth IESG [RFC8693, Section 2.1] 2.0 urn:ietf:params:oauth:token-type:access_token Token type URI for an OAuth 2.0 IESG [RFC8693, Section 3] access token urn:ietf:params:oauth:token-type:refresh_token Token type URI for an OAuth 2.0 IESG [RFC8693, Section 3] refresh token urn:ietf:params:oauth:token-type:id_token Token type URI for an ID Token IESG [RFC8693, Section 3] Token type URI for a urn:ietf:params:oauth:token-type:saml1 base64url-encoded SAML 1.1 IESG [RFC8693, Section 3] assertion Token type URI for a urn:ietf:params:oauth:token-type:saml2 base64url-encoded SAML 2.0 IESG [RFC8693, Section 3] assertion urn:ietf:params:oauth:request_uri A URN Sub-Namespace for OAuth IESG [RFC9126, Section 2.2] Request URIs. urn:ietf:params:oauth:jwk-thumbprint JWK Thumbprint URI IESG [RFC9278] urn:ietf:params:oauth:ckt COSE Key Thumbprint URI IETF [RFC9679] OAuth Dynamic Client Registration Metadata Registration Procedure(s) Specification Required Expert(s) Justin Richer Reference [RFC7591] Note Registration requests should be sent to [oauth-ext-review@ietf.org], as described in [RFC7591]. If they approve, designated experts should notify IANA within two weeks. For assistance, please contact iana@iana.org. IANA does not monitor the list. Available Formats [IMG] CSV Client Metadata Name Client Metadata Change Controller Reference Description Array of redirection URIs redirect_uris for use in redirect-based IESG [RFC7591] flows Requested authentication token_endpoint_auth_method method for the token IESG [RFC7591] endpoint Array of OAuth 2.0 grant grant_types types that the client may IESG [RFC7591] use Array of the OAuth 2.0 response_types response types that the IESG [RFC7591] client may use Human-readable name of client_name the client to be IESG [RFC7591] presented to the user URL of a web page client_uri providing information IESG [RFC7591] about the client logo_uri URL that references a IESG [RFC7591] logo for the client scope Space-separated list of IESG [RFC7591] OAuth 2.0 scope values Array of strings representing ways to contacts contact people IESG [RFC7591] responsible for this client, typically email addresses URL that points to a tos_uri human-readable terms of IESG [RFC7591] service document for the client URL that points to a policy_uri human-readable policy IESG [RFC7591] document for the client URL referencing the client's JSON Web Key Set jwks_uri [RFC7517] document IESG [RFC7591] representing the client's public keys Client's JSON Web Key Set jwks [RFC7517] document IESG [RFC7591] representing the client's public keys Identifier for the software_id software that comprises a IESG [RFC7591] client Version identifier for software_version the software that IESG [RFC7591] comprises a client client_id Client identifier IESG [RFC7591] client_secret Client secret IESG [RFC7591] client_id_issued_at Time at which the client IESG [RFC7591] identifier was issued client_secret_expires_at Time at which the client IESG [RFC7591] secret will expire A software statement containing client metadata values about the software_statement client software as IESG [RFC7591] claims. This is a string value containing the entire signed JWT. OAuth 2.0 Bearer Token registration_access_token used to access the client IESG [RFC7592] configuration endpoint Fully qualified URI of registration_client_uri the client registration IESG [RFC7592] endpoint [OpenID Connect Dynamic application_type Kind of the application [OpenID_Foundation_Artifact_Binding_WG] Client -- "native" or "web" Registration 1.0 incorporating errata set 2] [OpenID Connect URL using the https Dynamic sector_identifier_uri scheme to be used in [OpenID_Foundation_Artifact_Binding_WG] Client calculating Pseudonymous Registration Identifiers by the OP 1.0 incorporating errata set 2] [OpenID Connect subject_type requested Dynamic subject_type for responses to this [OpenID_Foundation_Artifact_Binding_WG] Client Client -- "pairwise" or Registration "public" 1.0 incorporating errata set 2] [OpenID Connect JWS alg algorithm Dynamic id_token_signed_response_alg REQUIRED for signing the [OpenID_Foundation_Artifact_Binding_WG] Client ID Token issued to this Registration Client 1.0 incorporating errata set 2] [OpenID Connect JWE alg algorithm Dynamic id_token_encrypted_response_alg REQUIRED for encrypting [OpenID_Foundation_Artifact_Binding_WG] Client the ID Token issued to Registration this Client 1.0 incorporating errata set 2] [OpenID Connect JWE enc algorithm Dynamic id_token_encrypted_response_enc REQUIRED for encrypting [OpenID_Foundation_Artifact_Binding_WG] Client the ID Token issued to Registration this Client 1.0 incorporating errata set 2] [OpenID Connect JWS alg algorithm Dynamic userinfo_signed_response_alg REQUIRED for signing [OpenID_Foundation_Artifact_Binding_WG] Client UserInfo Responses Registration 1.0 incorporating errata set 2] [OpenID Connect JWE alg algorithm Dynamic userinfo_encrypted_response_alg REQUIRED for encrypting [OpenID_Foundation_Artifact_Binding_WG] Client UserInfo Responses Registration 1.0 incorporating errata set 2] [OpenID Connect JWE enc algorithm Dynamic userinfo_encrypted_response_enc REQUIRED for encrypting [OpenID_Foundation_Artifact_Binding_WG] Client UserInfo Responses Registration 1.0 incorporating errata set 2] [OpenID Connect JWS alg algorithm that Dynamic request_object_signing_alg MUST be used for signing [OpenID_Foundation_Artifact_Binding_WG] Client Request Objects sent to Registration the OP 1.0 incorporating errata set 2] [OpenID JWE alg algorithm the RP Connect is declaring that it may Dynamic request_object_encryption_alg use for encrypting [OpenID_Foundation_Artifact_Binding_WG] Client Request Objects sent to Registration the OP 1.0 incorporating errata set 2] [OpenID JWE enc algorithm the RP Connect is declaring that it may Dynamic request_object_encryption_enc use for encrypting [OpenID_Foundation_Artifact_Binding_WG] Client Request Objects sent to Registration the OP 1.0 incorporating errata set 2] JWS alg algorithm that [OpenID MUST be used for signing Connect the JWT used to Dynamic token_endpoint_auth_signing_alg authenticate the Client [OpenID_Foundation_Artifact_Binding_WG] Client at the Token Endpoint for Registration the private_key_jwt and 1.0 client_secret_jwt incorporating authentication methods errata set 2] [OpenID Connect Dynamic default_max_age Default Maximum [OpenID_Foundation_Artifact_Binding_WG] Client Authentication Age Registration 1.0 incorporating errata set 2] [OpenID Connect Boolean value specifying Dynamic require_auth_time whether the auth_time [OpenID_Foundation_Artifact_Binding_WG] Client Claim in the ID Token is Registration REQUIRED 1.0 incorporating errata set 2] [OpenID Connect Default requested Dynamic default_acr_values Authentication Context [OpenID_Foundation_Artifact_Binding_WG] Client Class Reference values Registration 1.0 incorporating errata set 2] [OpenID Connect URI using the https Dynamic initiate_login_uri scheme that a third party [OpenID_Foundation_Artifact_Binding_WG] Client can use to initiate a Registration login by the RP 1.0 incorporating errata set 2] [OpenID Connect Array of request_uri Dynamic request_uris values that are [OpenID_Foundation_Artifact_Binding_WG] Client pre-registered by the RP Registration for use at the OP 1.0 incorporating errata set 2] [UMA 2.0 claims_redirect_uris claims redirection [Kantara_UMA_WG] Grant for endpoints OAuth 2.0, Section 2] JWS alg algorithm [ETSI GS nfv_token_signed_response_alg required for signing the [ETSI] NFV-SEC 022 nfv Token issued to this V2.7.1] Client JWE alg algorithm [ETSI GS nfv_token_encrypted_response_alg required for encrypting [ETSI] NFV-SEC 022 the nfv Token issued to V2.7.1] this Client JWE enc algorithm [ETSI GS nfv_token_encrypted_response_enc required for encrypting [ETSI] NFV-SEC 022 the nfv Token issued to V2.7.1] this Client Indicates the client's intention to use [RFC8705, tls_client_certificate_bound_access_tokens mutual-TLS client [IESG] Section 3.4] certificate-bound access tokens. String value specifying [RFC8705, tls_client_auth_subject_dn the expected subject DN [IESG] Section of the client 2.1.2] certificate. String value specifying [RFC8705, tls_client_auth_san_dns the expected dNSName SAN [IESG] Section entry in the client 2.1.2] certificate. String value specifying the expected [RFC8705, tls_client_auth_san_uri uniformResourceIdentifier [IESG] Section SAN entry in the client 2.1.2] certificate. String value specifying [RFC8705, tls_client_auth_san_ip the expected iPAddress [IESG] Section SAN entry in the client 2.1.2] certificate. String value specifying [RFC8705, tls_client_auth_san_email the expected rfc822Name [IESG] Section SAN entry in the client 2.1.2] certificate. Indicates where authorization request needs to be protected as [RFC9101, require_signed_request_object Request Object and [IETF] Section 10.5] provided through either request or request_uri parameter. Indicates whether the require_pushed_authorization_requests client is required to use [IESG] [RFC9126, PAR to initiate Section 6] authorization requests. String value indicating introspection_signed_response_alg the client’s desired [IETF] [RFC9701, introspection response Section 6] signing algorithm String value specifying the desired introspection [RFC9701, introspection_encrypted_response_alg response content key [IETF] Section 6] encryption algorithm (alg value) String value specifying the desired introspection [RFC9701, introspection_encrypted_response_enc response content [IETF] Section 6] encryption algorithm (enc value) RP URL that will cause [OpenID the RP to log itself out Connect frontchannel_logout_uri when rendered in an [OpenID_Foundation_Artifact_Binding_WG] Front-Channel iframe by the OP Logout 1.0, Section 2] Boolean value specifying whether the RP requires that a sid (session ID) [OpenID query parameter be Connect frontchannel_logout_session_required included to identify the [OpenID_Foundation_Artifact_Binding_WG] Front-Channel RP session with the OP Logout 1.0, when the Section 2] frontchannel_logout_uri is used RP URL that will cause [OpenID the RP to log itself out Connect backchannel_logout_uri when sent a Logout Token [OpenID_Foundation_Artifact_Binding_WG] Back-Channel by the OP Logout 1.0, Section 2.2] Boolean value specifying whether the RP requires that a sid (session ID) [OpenID Claim be included in the Connect backchannel_logout_session_required Logout Token to identify [OpenID_Foundation_Artifact_Binding_WG] Back-Channel the RP session with the Logout 1.0, OP when the Section 2.2] backchannel_logout_uri is used Array of URLs supplied by the RP to which it MAY [OpenID request that the Connect post_logout_redirect_uris End-User's User Agent be [OpenID_Foundation_Artifact_Binding_WG] RP-Initiated redirected using the Logout 1.0, post_logout_redirect_uri Section 3.1] parameter after a logout has been performed Indicates what [RFC9396, authorization_details_types authorization details [IETF] Section 10] types the client uses. Boolean value specifying dpop_bound_access_tokens whether the client always [IETF] [RFC9449, uses DPoP for token Section 5.2] requests An array of strings [Section specifying the client 5.1.2 of client_registration_types registration types the RP [OpenID_Foundation_Artifact_Binding_WG] OpenID wants to use Federation 1.0] URL referencing a signed [Section JWT having the client's 5.2.1 of signed_jwks_uri JWK Set document as its [OpenID_Foundation_Artifact_Binding_WG] OpenID payload Federation 1.0] Human-readable name [Section representing the 5.2.2 of organization_name organization owning this [OpenID_Foundation_Artifact_Binding_WG] OpenID client Federation 1.0] Human-readable brief [Section description of this 5.2.2 of description client presentable to the [OpenID_Foundation_Artifact_Binding_WG] OpenID End-User Federation 1.0] JSON array with one or [Section more strings representing 5.2.2 of keywords search keywords, tags, [OpenID_Foundation_Artifact_Binding_WG] OpenID categories, or labels Federation that apply to this client 1.0] URL for documentation of [Section additional information 5.2.2 of information_uri about this client [OpenID_Foundation_Artifact_Binding_WG] OpenID viewable by the End-User Federation 1.0] [Section URL of a Web page for the 5.2.2 of organization_uri organization owning this [OpenID_Foundation_Artifact_Binding_WG] OpenID client Federation 1.0] Boolean value indicating the requirement for a client to use mutual-TLS endpoint aliases [Section [RFC8705] declared by the 5.2.2.1.1 of use_mtls_endpoint_aliases authorization server in [OpenID_Foundation_FAPI_WG] FAPI 2.0 its metadata even beyond Security the Mutual-TLS Client Profile] Authentication and Certificate-Bound Access Tokens use cases. Non-empty array of strings, where each [Section 5.1 string is a JWE [RFC7516] of OpenID for encrypted_response_enc_values_supported enc algorithm that can be [OpenID_Foundation_Digital_Credentials_Protocols_WG] Verifiable used as the content Presentations encryption algorithm for 1.0] encrypting the Response An object containing a [Section 11.1 list of name/value pairs, of OpenID for vp_formats_supported where the name is a [OpenID_Foundation_Digital_Credentials_Protocols_WG] Verifiable string identifying a Presentations Credential format 1.0] supported by the Verifier [Section 2 of JSON array containing a OpenID subject_types_supported list of the subject_type [OpenID_Foundation_Artifact_Binding_WG] Connect values supported by the Relying Party RP Metadata Choices 1.0] JSON array containing a [Section 2 of list of the [JWS] alg OpenID id_token_signing_alg_values_supported values supported by the [OpenID_Foundation_Artifact_Binding_WG] Connect RP when validating the ID Relying Party Token signature Metadata Choices 1.0] JSON array containing a [Section 2 of list of the [JWE] alg OpenID id_token_encryption_alg_values_supported values supported by the [OpenID_Foundation_Artifact_Binding_WG] Connect RP when decrypting the ID Relying Party Token Metadata Choices 1.0] JSON array containing a [Section 2 of list of the JWE enc OpenID id_token_encryption_enc_values_supported values supported by the [OpenID_Foundation_Artifact_Binding_WG] Connect RP when decrypting the ID Relying Party Token Metadata Choices 1.0] JSON array containing a [Section 2 of list of the JWS alg OpenID userinfo_signing_alg_values_supported values supported by the [OpenID_Foundation_Artifact_Binding_WG] Connect RP when validating the Relying Party UserInfo Response Metadata signature Choices 1.0] JSON array containing a [Section 2 of list of the JWE alg OpenID userinfo_encryption_alg_values_supported values supported by the [OpenID_Foundation_Artifact_Binding_WG] Connect RP when decrypting the Relying Party UserInfo Response Metadata Choices 1.0] JSON array containing a [Section 2 of list of the JWE enc OpenID userinfo_encryption_enc_values_supported values supported by the [OpenID_Foundation_Artifact_Binding_WG] Connect RP when decrypting the Relying Party UserInfo Response Metadata Choices 1.0] JSON array containing a [Section 2 of list of the JWS alg OpenID request_object_signing_alg_values_supported values supported by the [OpenID_Foundation_Artifact_Binding_WG] Connect Client when signing Relying Party Request Objects Metadata Choices 1.0] JSON array containing a [Section 2 of list of the JWE alg OpenID request_object_encryption_alg_values_supported values supported by the [OpenID_Foundation_Artifact_Binding_WG] Connect Client when encrypting Relying Party Request Objects Metadata Choices 1.0] JSON array containing a [Section 2 of list of the JWE enc OpenID request_object_encryption_enc_values_supported values supported by the [OpenID_Foundation_Artifact_Binding_WG] Connect Client when encrypting Relying Party Request Objects Metadata Choices 1.0] [Section 2 of JSON array containing a OpenID token_endpoint_auth_methods_supported list of the Client [OpenID_Foundation_Artifact_Binding_WG] Connect Authentication methods Relying Party supported by the Client Metadata Choices 1.0] JSON array containing a [Section 2 of list of the JWS alg OpenID values supported by the Connect token_endpoint_auth_signing_alg_values_supported Client when signing the [OpenID_Foundation_Artifact_Binding_WG] Relying Party JWT used to authenticate Metadata the Client at the Token Choices 1.0] Endpoint JSON array containing a [Section 2 of list of the JWS alg OpenID backchannel_authentication_request_signing_alg_values_supported values supported by the [OpenID_Foundation_Artifact_Binding_WG] Connect Client when signing the Relying Party JWT used for CIBA Metadata authentication requests Choices 1.0] JSON array containing a [Section 2 of list of the JWS alg OpenID authorization_signing_alg_values_supported values supported by the [OpenID_Foundation_Artifact_Binding_WG] Connect Client for signed Relying Party responses Metadata Choices 1.0] JSON array containing a [Section 2 of list of the JWE alg OpenID authorization_encryption_alg_values_supported values supported by the [OpenID_Foundation_Artifact_Binding_WG] Connect Client for encrypted Relying Party responses Metadata Choices 1.0] JSON array containing a [Section 2 of list of the JWE enc OpenID authorization_encryption_enc_values_supported values supported by the [OpenID_Foundation_Artifact_Binding_WG] Connect Client for encrypted Relying Party responses Metadata Choices 1.0] JSON array containing a [Section 2 of list of the JWS alg OpenID introspection_signing_alg_values_supported values supported by the [OpenID_Foundation_Artifact_Binding_WG] Connect Client when validating Relying Party the Introspection Metadata Response signature Choices 1.0] JSON array containing a [Section 2 of list of the JWE alg OpenID introspection_encryption_alg_values_supported values supported by the [OpenID_Foundation_Artifact_Binding_WG] Connect Client when decrypting Relying Party the Introspection Metadata Response Choices 1.0] JSON array containing a [Section 2 of list of the JWE enc OpenID introspection_encryption_enc_values_supported values supported by the [OpenID_Foundation_Artifact_Binding_WG] Connect Client when decrypting Relying Party the Introspection Metadata Response Choices 1.0] [Section 3 of JWT Secured String value indicating Authorization authorization_signed_response_alg the client's desired IESG Response Mode authorization response for OAuth 2.0 signing algorithm. (JARM) incorporating errata set 1] OAuth Token Endpoint Authentication Methods Registration Procedure(s) Specification Required Expert(s) Justin Richer Reference [RFC7591][RFC8414] Note Registration requests should be sent to [oauth-ext-review@ietf.org], as described in [RFC7591]. If they approve, designated experts should notify IANA within two weeks. For assistance, please contact iana@iana.org. IANA does not monitor the list. Available Formats [IMG] CSV Token Endpoint Authentication Method Name Change Controller Reference none IESG [RFC7591] client_secret_post IESG [RFC7591] client_secret_basic IESG [RFC7591] client_secret_jwt IESG [OpenID Connect Core 1.0, Section 9][RFC-ietf-oauth-rfc7523bis-11] private_key_jwt IESG [OpenID Connect Core 1.0, Section 9][RFC-ietf-oauth-rfc7523bis-11] tls_client_auth IESG [RFC8705, Section 2.1.1] self_signed_tls_client_auth IESG [RFC8705, Section 2.2.1] PKCE Code Challenge Methods Registration Procedure(s) Specification Required Expert(s) John Bradley, Mike Jones Reference [RFC7636] Note Registration requests should be sent to [oauth-ext-review@ietf.org], as described in [RFC7636]. If they approve, designated experts should notify IANA within two weeks. For assistance, please contact iana@iana.org. IANA does not monitor the list. Available Formats [IMG] CSV Code Challenge Method Parameter Name Change Controller Reference plain IESG [RFC7636, Section 4.2] S256 IESG [RFC7636, Section 4.2] OAuth Token Introspection Response Registration Procedure(s) Specification Required Expert(s) Justin Richer Reference [RFC7662] Note Registration requests should be sent to [oauth-ext-review@ietf.org], as described in [RFC7662]. If they approve, designated experts should notify IANA within two weeks. For assistance, please contact iana@iana.org. IANA does not monitor the list. Available Formats [IMG] CSV Name Description Change Controller Reference active Token active status IESG [RFC7662, Section 2.2] username User identifier of the resource owner IESG [RFC7662, Section 2.2] client_id Client identifier of the client IESG [RFC7662, Section 2.2] scope Authorized scopes of the token IESG [RFC7662, Section 2.2] token_type Type of the token IESG [RFC7662, Section 2.2] exp Expiration timestamp of the token IESG [RFC7662, Section 2.2] iat Issuance timestamp of the token IESG [RFC7662, Section 2.2] nbf Timestamp which the token is not valid before IESG [RFC7662, Section 2.2] sub Subject of the token IESG [RFC7662, Section 2.2] aud Audience of the token IESG [RFC7662, Section 2.2] iss Issuer of the token IESG [RFC7662, Section 2.2] jti Unique identifier of the token IESG [RFC7662, Section 2.2] permissions array of objects, each describing a scoped, time-limitable permission [Kantara_UMA_WG] [Federated Authorization for UMA 2.0, for a resource Section 5.1.1] vot Vector of Trust value IESG [RFC8485] vtm Vector of Trust trustmark URL IESG [RFC8485] act Actor IESG [RFC8693, Section 4.1] may_act Authorized Actor - the party that is authorized to become the actor IESG [RFC8693, Section 4.4] cnf Confirmation IESG [RFC7800][RFC8705] ace_profile The ACE profile used between the client and RS. IETF [RFC9200, Section 5.9.2] "client-nonce". A nonce previously provided to the AS by the RS via the cnonce client. Used to verify token freshness when the RS cannot synchronize IETF [RFC9200, Section 5.9.2] its clock with the AS. cti "CWT ID". The identifier of a CWT as defined in [RFC8392]. IETF [RFC9200, Section 5.9.2] "Expires in". Lifetime of the token in seconds from the time the RS exi first sees it. Used to implement a weaker form of token expiration for IETF [RFC9200, Section 5.9.2] devices that cannot synchronize their internal clocks. The member authorization_details contains a JSON array of JSON objects authorization_details representing the rights of the access token. Each JSON object contains IETF [RFC9396, Section 9.2] the data to specify the authorization requirements for a certain type of resource. acr Authentication Context Class Reference IETF [RFC9470, Section 6.2] auth_time Time when the user authentication occurred IETF [RFC9470, Section 6.2] OAuth Authorization Server Metadata Registration Procedure(s) Specification Required Expert(s) Mike Jones, Nat Sakimura, John Bradley, Dick Hardt Reference [RFC8414] Note Registration requests should be sent to [oauth-ext-review@ietf.org], as described in [RFC8414]. If they approve, designated experts should notify IANA within two weeks. For assistance, please contact iana@iana.org. IANA does not monitor the list. Available Formats [IMG] CSV Metadata Name Metadata Description Change Controller Reference Authorization issuer server's issuer IESG [RFC8414, Section 2] identifier URL URL of the authorization authorization_endpoint server's IESG [RFC8414, Section 2] authorization endpoint URL of the token_endpoint authorization IESG [RFC8414, Section 2] server's token endpoint URL of the jwks_uri authorization IESG [RFC8414, Section 2] server's JWK Set document URL of the authorization registration_endpoint server's OAuth 2.0 IESG [RFC8414, Section 2] Dynamic Client Registration Endpoint JSON array containing a list of scopes_supported the OAuth 2.0 IESG [RFC8414, Section 2] "scope" values that this authorization server supports JSON array containing a list of the OAuth 2.0 response_types_supported "response_type" IESG [RFC8414, Section 2] values that this authorization server supports JSON array containing a list of the OAuth 2.0 response_modes_supported "response_mode" IESG [RFC8414, Section 2] values that this authorization server supports JSON array containing a list of grant_types_supported the OAuth 2.0 grant IESG [RFC8414, Section 2] type values that this authorization server supports JSON array containing a list of token_endpoint_auth_methods_supported client IESG [RFC8414, Section 2] authentication methods supported by this token endpoint JSON array containing a list of the JWS signing algorithms supported token_endpoint_auth_signing_alg_values_supported by the token IESG [RFC8414, Section 2] endpoint for the signature on the JWT used to authenticate the client at the token endpoint URL of a page containing human-readable service_documentation information that IESG [RFC8414, Section 2] developers might want or need to know when using the authorization server Languages and scripts supported for the user interface, ui_locales_supported represented as a IESG [RFC8414, Section 2] JSON array of language tag values from BCP 47 [RFC5646] URL that the authorization server provides to the person registering the client to read about the op_policy_uri authorization IESG [RFC8414, Section 2] server's requirements on how the client can use the data provided by the authorization server URL that the authorization server provides to the person registering op_tos_uri the client to read IESG [RFC8414, Section 2] about the authorization server's terms of service URL of the revocation_endpoint authorization IESG [RFC8414, Section 2] server's OAuth 2.0 revocation endpoint JSON array containing a list of client revocation_endpoint_auth_methods_supported authentication IESG [RFC8414, Section 2] methods supported by this revocation endpoint JSON array containing a list of the JWS signing algorithms supported revocation_endpoint_auth_signing_alg_values_supported by the revocation IESG [RFC8414, Section 2] endpoint for the signature on the JWT used to authenticate the client at the revocation endpoint URL of the authorization introspection_endpoint server's OAuth 2.0 IESG [RFC8414, Section 2] introspection endpoint JSON array containing a list of client introspection_endpoint_auth_methods_supported authentication IESG [RFC8414, Section 2] methods supported by this introspection endpoint JSON array containing a list of the JWS signing algorithms supported by the introspection introspection_endpoint_auth_signing_alg_values_supported endpoint for the IESG [RFC8414, Section 2] signature on the JWT used to authenticate the client at the introspection endpoint PKCE code challenge code_challenge_methods_supported methods supported by IESG [RFC8414, Section 2] this authorization server Signed JWT containing metadata signed_metadata values about the IESG [RFC8414, Section 2.1] authorization server as claims URL of the authorization device_authorization_endpoint server's device IESG [RFC8628, Section 4] authorization endpoint Indicates authorization server tls_client_certificate_bound_access_tokens support for IESG [RFC8705, Section 3.3] mutual-TLS client certificate-bound access tokens. JSON object containing alternative authorization server mtls_endpoint_aliases endpoints, which a IESG [RFC8705, Section 5] client intending to do mutual TLS will use in preference to the conventional endpoints. JSON array containing a list of the JWS signing nfv_token_signing_alg_values_supported algorithms supported [ETSI] [ETSI GS NFV-SEC 022 V2.7.1] by the server for signing the JWT used as NFV Token JSON array containing a list of the JWE encryption nfv_token_encryption_alg_values_supported algorithms (alg [ETSI] [ETSI GS NFV-SEC 022 V2.7.1] values) supported by the server to encode the JWT used as NFV Token JSON array containing a list of the JWE encryption nfv_token_encryption_enc_values_supported algorithms (enc [ETSI] [ETSI GS NFV-SEC 022 V2.7.1] values) supported by the server to encode the JWT used as NFV Token userinfo_endpoint URL of the OP's [OpenID_Foundation_Artifact_Binding_WG] [OpenID Connect Discovery 1.0, UserInfo Endpoint Section 3] JSON array containing a list of acr_values_supported the Authentication [OpenID_Foundation_Artifact_Binding_WG] [OpenID Connect Discovery 1.0, Context Class Section 3] References that this OP supports JSON array containing a list of subject_types_supported the Subject [OpenID_Foundation_Artifact_Binding_WG] [OpenID Connect Discovery 1.0, Identifier types Section 3] that this OP supports JSON array containing a list of [OpenID Connect Discovery 1.0, id_token_signing_alg_values_supported the JWS "alg" values [OpenID_Foundation_Artifact_Binding_WG] Section 3] supported by the OP for the ID Token JSON array containing a list of [OpenID Connect Discovery 1.0, id_token_encryption_alg_values_supported the JWE "alg" values [OpenID_Foundation_Artifact_Binding_WG] Section 3] supported by the OP for the ID Token JSON array containing a list of [OpenID Connect Discovery 1.0, id_token_encryption_enc_values_supported the JWE "enc" values [OpenID_Foundation_Artifact_Binding_WG] Section 3] supported by the OP for the ID Token JSON array containing a list of [OpenID Connect Discovery 1.0, userinfo_signing_alg_values_supported the JWS "alg" values [OpenID_Foundation_Artifact_Binding_WG] Section 3] supported by the UserInfo Endpoint JSON array containing a list of [OpenID Connect Discovery 1.0, userinfo_encryption_alg_values_supported the JWE "alg" values [OpenID_Foundation_Artifact_Binding_WG] Section 3] supported by the UserInfo Endpoint JSON array containing a list of [OpenID Connect Discovery 1.0, userinfo_encryption_enc_values_supported the JWE "enc" values [OpenID_Foundation_Artifact_Binding_WG] Section 3] supported by the UserInfo Endpoint JSON array containing a list of [OpenID Connect Discovery 1.0, request_object_signing_alg_values_supported the JWS "alg" values [OpenID_Foundation_Artifact_Binding_WG] Section 3] supported by the OP for Request Objects JSON array containing a list of [OpenID Connect Discovery 1.0, request_object_encryption_alg_values_supported the JWE "alg" values [OpenID_Foundation_Artifact_Binding_WG] Section 3] supported by the OP for Request Objects JSON array containing a list of [OpenID Connect Discovery 1.0, request_object_encryption_enc_values_supported the JWE "enc" values [OpenID_Foundation_Artifact_Binding_WG] Section 3] supported by the OP for Request Objects JSON array containing a list of display_values_supported the "display" [OpenID_Foundation_Artifact_Binding_WG] [OpenID Connect Discovery 1.0, parameter values Section 3] that the OpenID Provider supports JSON array containing a list of [OpenID Connect Discovery 1.0, claim_types_supported the Claim Types that [OpenID_Foundation_Artifact_Binding_WG] Section 3] the OpenID Provider supports JSON array containing a list of the Claim Names of [OpenID Connect Discovery 1.0, claims_supported the Claims that the [OpenID_Foundation_Artifact_Binding_WG] Section 3] OpenID Provider MAY be able to supply values for Languages and scripts supported for values in Claims claims_locales_supported being returned, [OpenID_Foundation_Artifact_Binding_WG] [OpenID Connect Discovery 1.0, represented as a Section 3] JSON array of BCP 47 [RFC5646] language tag values Boolean value specifying whether [OpenID Connect Discovery 1.0, claims_parameter_supported the OP supports use [OpenID_Foundation_Artifact_Binding_WG] Section 3] of the "claims" parameter Boolean value specifying whether [OpenID Connect Discovery 1.0, request_parameter_supported the OP supports use [OpenID_Foundation_Artifact_Binding_WG] Section 3] of the "request" parameter Boolean value specifying whether [OpenID Connect Discovery 1.0, request_uri_parameter_supported the OP supports use [OpenID_Foundation_Artifact_Binding_WG] Section 3] of the "request_uri" parameter Boolean value specifying whether require_request_uri_registration the OP requires any [OpenID_Foundation_Artifact_Binding_WG] [OpenID Connect Discovery 1.0, "request_uri" values Section 3] used to be pre-registered Indicates where authorization request needs to be protected as Request require_signed_request_object Object and provided IETF [RFC9101, Section 10.5] through either request or request_uri parameter. URL of the authorization pushed_authorization_request_endpoint server's pushed IESG [RFC9126, Section 5] authorization request endpoint Indicates whether the authorization require_pushed_authorization_requests server accepts IESG [RFC9126, Section 5] authorization requests only via PAR. JSON array containing a list of algorithms supported introspection_signing_alg_values_supported by the authorization IETF [RFC9701, Section 7] server for introspection response signing JSON array containing a list of algorithms supported by the authorization introspection_encryption_alg_values_supported server for IETF [RFC9701, Section 7] introspection response content key encryption (alg value) JSON array containing a list of algorithms supported by the authorization introspection_encryption_enc_values_supported server for IETF [RFC9701, Section 7] introspection response content encryption (enc value) Boolean value indicating whether the authorization authorization_response_iss_parameter_supported server provides the IETF [RFC9207, Section 3] iss parameter in the authorization response. URL of an OP iframe that supports cross-origin communications for [OpenID Connect Session Management check_session_iframe session state [OpenID_Foundation_Artifact_Binding_WG] 1.0, Section 3.3] information with the RP Client, using the HTML5 postMessage API Boolean value specifying whether frontchannel_logout_supported the OP supports [OpenID_Foundation_Artifact_Binding_WG] [OpenID Connect Front-Channel Logout HTTP-based logout, 1.0, Section 3] with true indicating support Boolean value specifying whether backchannel_logout_supported the OP supports [OpenID_Foundation_Artifact_Binding_WG] [OpenID Connect Back-Channel Logout back-channel logout, 1.0, Section 2] with true indicating support Boolean value specifying whether the OP can pass a backchannel_logout_session_supported sid (session ID) [OpenID_Foundation_Artifact_Binding_WG] [OpenID Connect Back-Channel Logout Claim in the Logout 1.0, Section 2] Token to identify the RP session with the OP URL at the OP to which an RP can end_session_endpoint perform a redirect [OpenID_Foundation_Artifact_Binding_WG] [OpenID Connect RP-Initiated Logout to request that the 1.0, Section 2.1] End-User be logged out at the OP Supported CIBA [OpenID Connect Client-Initiated backchannel_token_delivery_modes_supported authentication [OpenID_Foundation_MODRNA_WG] Backchannel Authentication Flow - result delivery Core 1.0, Section 4] modes CIBA Backchannel [OpenID Connect Client-Initiated backchannel_authentication_endpoint Authentication [OpenID_Foundation_MODRNA_WG] Backchannel Authentication Flow - Endpoint Core 1.0, Section 4] JSON array containing a list of the JWS signing [OpenID Connect Client-Initiated backchannel_authentication_request_signing_alg_values_supported algorithms supported [OpenID_Foundation_MODRNA_WG] Backchannel Authentication Flow - for validation of Core 1.0, Section 4] signed CIBA authentication requests Indicates whether [OpenID Connect Client-Initiated backchannel_user_code_parameter_supported the OP supports the [OpenID_Foundation_MODRNA_WG] Backchannel Authentication Flow - use of the CIBA Core 1.0, Section 4] user_code parameter. JSON array containing the authorization_details_types_supported authorization IETF [RFC9396, Section 10] details types the AS supports JSON array containing a list of dpop_signing_alg_values_supported the JWS algorithms IETF [RFC9449, Section 5.1] supported for DPoP proof JWTs client_registration_types_supported Client Registration [OpenID_Foundation_Artifact_Binding_WG] [Section 5.1.3 of OpenID Federation Types Supported 1.0] Federation [Section 5.1.3 of OpenID Federation federation_registration_endpoint Registration [OpenID_Foundation_Artifact_Binding_WG] 1.0] Endpoint URL referencing a signed JWT having signed_jwks_uri this authorization [OpenID_Foundation_Artifact_Binding_WG] [Section 5.2.1 of OpenID Federation server's JWK Set 1.0] document as its payload JSON Web Key Set [Section 5.2.1 of OpenID Federation jwks document, passed by [OpenID_Foundation_Artifact_Binding_WG] 1.0] value Human-readable name representing the [Section 5.2.2 of OpenID Federation organization_name organization owning [OpenID_Foundation_Artifact_Binding_WG] 1.0] this authorization server Human-readable name of the authorization [Section 5.2.2 of OpenID Federation display_name server to be [OpenID_Foundation_Artifact_Binding_WG] 1.0] presented to the End-User Human-readable brief description of this [Section 5.2.2 of OpenID Federation description authorization server [OpenID_Foundation_Artifact_Binding_WG] 1.0] presentable to the End-User JSON array with one or more strings representing search keywords keywords, tags, [OpenID_Foundation_Artifact_Binding_WG] [Section 5.2.2 of OpenID Federation categories, or 1.0] labels that apply to this authorization server Array of strings representing ways to contact people [Section 5.2.2 of OpenID Federation contacts responsible for this [OpenID_Foundation_Artifact_Binding_WG] 1.0] authorization server, typically email addresses URL that references a logo for the [Section 5.2.2 of OpenID Federation logo_uri organization owning [OpenID_Foundation_Artifact_Binding_WG] 1.0] this authorization server URL for documentation of additional [Section 5.2.2 of OpenID Federation information_uri information about [OpenID_Foundation_Artifact_Binding_WG] 1.0] this authorization server viewable by the End-User URL of a Web page organization_uri for the organization [OpenID_Foundation_Artifact_Binding_WG] [Section 5.2.2 of OpenID Federation owning this 1.0] authorization server JSON array containing a list of protected_resources resource identifiers IETF [RFC9728, Section 4] for OAuth protected resources URL of the Authorization Server status_list_aggregation_endpoint aggregating OAuth IESG [RFC-ietf-oauth-status-list-21, Token Status List Section 9] URLs for token status management. JSON array containing a list of Token Type Identifiers supported as a [RFC-ietf-oauth-identity-chaining-16, identity_chaining_requested_token_types_supported requested_token_type IESG Section 3] in an Identity and Authorization Chaining Token Exchange [RFC8693] request. OAuth Protected Resource Metadata Registration Procedure(s) Specification Required Expert(s) Michael Jones, Dick Hardt Reference [RFC9728] Note Registration requests should be sent to [oauth-ext-review@ietf.org], as described in [RFC9728]. If they approve, designated experts should notify IANA within two weeks. For assistance, please contact iana@iana.org. IANA does not monitor the list. Available Formats [IMG] CSV Metadata Name Metadata Description Change Controller Reference resource Protected resource's resource identifier URL IETF [RFC9728, Section 2] authorization_servers JSON array containing a list of OAuth IETF [RFC9728, Section 2] authorization server issuer identifiers jwks_uri URL of the protected resource's JWK Set IETF [RFC9728, Section 2] document JSON array containing a list of the OAuth 2.0 scopes_supported scope values that are used in authorization IETF [RFC9728, Section 2] requests to request access to this protected resource JSON array containing a list of the OAuth 2.0 bearer_methods_supported bearer token presentation methods that this IETF [RFC9728, Section 2] protected resource supports JSON array containing a list of the JWS resource_signing_alg_values_supported signing algorithms (alg values) supported by IETF [RFC9728, Section 2] the protected resource for signed content resource_name Human-readable name of the protected resource IETF [RFC9728, Section 2] URL of a page containing human-readable resource_documentation information that developers might want or need IETF [RFC9728, Section 2] to know when using the protected resource URL of a page containing human-readable resource_policy_uri information about the protected resource's IETF [RFC9728, Section 2] requirements on how the client can use the data provided by the protected resource URL of a page containing human-readable resource_tos_uri information about the protected resource's IETF [RFC9728, Section 2] terms of service Boolean value indicating protected resource tls_client_certificate_bound_access_tokens support for mutual-TLS client IETF [RFC9728, Section 2] certificate-bound access tokens JSON array containing a list of the authorization details type values supported by authorization_details_types_supported the resource server when the IETF [RFC9728, Section 2] authorization_details request parameter is used JSON array containing a list of the JWS alg dpop_signing_alg_values_supported values supported by the resource server for IETF [RFC9728, Section 2] validating DPoP proof JWTs Boolean value specifying whether the protected dpop_bound_access_tokens_required resource always requires the use of DPoP-bound IETF [RFC9728, Section 2] access tokens signed_metadata Signed JWT containing metadata parameters IETF [RFC9728, Section about the protected resource as claims 2.2] URL referencing a signed JWT having the [Section 5.2.1 of signed_jwks_uri protected resource's JWK Set document as its [OpenID_Foundation_Artifact_Binding_WG] OpenID Federation payload 1.0] [Section 5.2.1 of jwks JSON Web Key Set document, passed by value [OpenID_Foundation_Artifact_Binding_WG] OpenID Federation 1.0] Human-readable name representing the [Section 5.2.2 of organization_name organization owning this protected resource [OpenID_Foundation_Artifact_Binding_WG] OpenID Federation 1.0] Human-readable brief description of this [Section 5.2.2 of description protected resource presentable to the End-User [OpenID_Foundation_Artifact_Binding_WG] OpenID Federation 1.0] JSON array with one or more strings [Section 5.2.2 of keywords representing search keywords, tags, [OpenID_Foundation_Artifact_Binding_WG] OpenID Federation categories, or labels that apply to this 1.0] protected resource Array of strings representing ways to contact [Section 5.2.2 of contacts people responsible for this protected [OpenID_Foundation_Artifact_Binding_WG] OpenID Federation resource, typically email addresses 1.0] URL that references a logo for the [Section 5.2.2 of logo_uri organization owning this protected resource [OpenID_Foundation_Artifact_Binding_WG] OpenID Federation 1.0] URL of a Web page for the organization owning [Section 5.2.2 of organization_uri this protected resource [OpenID_Foundation_Artifact_Binding_WG] OpenID Federation 1.0] OAuth Status Types Registration Procedure(s) Specification Required Expert(s) Unassigned Reference [RFC-ietf-oauth-status-list-21] Note Registration requests should be sent to [oauth-ext-review@ietf.org], as described in [RFC-ietf-oauth-status-list-21]. If they approve, designated experts should notify IANA within two weeks. For assistance, please contact iana@iana.org. IANA does not monitor the list. Available Formats [IMG] CSV Status Type Name Status Type Description Status Type Value Change Controller Reference VALID The status of the Referenced Token is valid, 0x00 IETF [RFC-ietf-oauth-status-list-21, Section 7] correct or legal. INVALID The status of the Referenced Token is revoked, 0x01 IETF [RFC-ietf-oauth-status-list-21, Section 7] annulled, taken back, recalled or cancelled. The status of the Referenced Token is temporarily SUSPENDED invalid, hanging or debarred from privilege. This 0x02 IETF [RFC-ietf-oauth-status-list-21, Section 7] state is usually temporary. APPLICATION_SPECIFIC The status of the Referenced Token is application 0x03 IETF [RFC-ietf-oauth-status-list-21, Section 7] specific. Unassigned 0x04-0x0B APPLICATION_SPECIFIC The status of the Referenced Token is application 0x0C-0x0F IETF [RFC-ietf-oauth-status-list-21, Section 7] specific. Unassigned 0x10-0xFF Contact Information ID Name Contact URI Last Updated [ETSI] ETSI mailto:pnns&etsi.org 2019-07-22 Internet [IESG] Engineering mailto:iesg&ietf.org Steering Group Internet [IETF] Engineering Task mailto:ietf&ietf.org Force Kantara [Kantara_UMA_WG] Initiative mailto:staff&kantarainitiative.org 2018-04-23 User-Managed Access Work Group OpenID Foundation [OpenID_Foundation_Artifact_Binding_WG] Artifact Binding mailto:openid-specs-ab&lists.openid.net 2022-09-23 Working Group OpenID Foundation Digital [OpenID_Foundation_Digital_Credentials_Protocols_WG] Credentials mailto:openid-specs-digital-credentials-protocols&lists.openid.net 2025-10-03 Protocols Working Group OpenID Foundation [OpenID_Foundation_FAPI_WG] FAPI Working mailto:openid-specs-fapi&lists.openid.net 2025-04-28 Group OpenID Foundation [OpenID_Foundation_MODRNA_WG] MODRNA Working mailto:openid-specs-mobile-profile&lists.openid.net 2022-12-01 Group Licensing Terms