Expand description
How this client authenticates to the authorization server.
Two shapes, and which one applies is not a detail:
none— the localhost development client. Credentials are just theclient_id; there is no assertion, because a public client has no key registered to sign one with.private_key_jwt— production. A short-lived ES256 assertion signed with the confidential client’s key.
Sending an assertion unconditionally would make every dev login fail at PAR (a public client presenting credentials it never registered), leaving the flow only exercisable against production. Sending none in production is a silent downgrade to an unauthenticated client. So the method is negotiated, stored in the state row, and re-checked at token time.
Enums§
- Auth
Method - The client-authentication method in use for a flow.
Functions§
- client_
assertion - Mint a
private_key_jwtclient assertion. - credential_
params - The client-credential form parameters for a request.