Skip to main content

Module client_auth

Module client_auth 

Source
Expand description

How this client authenticates to the authorization server.

Two shapes, and which one applies is not a detail:

  • none — the localhost development client. Credentials are just the client_id; there is no assertion, because a public client has no key registered to sign one with.
  • private_key_jwt — production. A short-lived ES256 assertion signed with the confidential client’s key.

Sending an assertion unconditionally would make every dev login fail at PAR (a public client presenting credentials it never registered), leaving the flow only exercisable against production. Sending none in production is a silent downgrade to an unauthenticated client. So the method is negotiated, stored in the state row, and re-checked at token time.

Enums§

AuthMethod
The client-authentication method in use for a flow.

Functions§

client_assertion
Mint a private_key_jwt client assertion.
credential_params
The client-credential form parameters for a request.