openapi: 3.2.0 info: title: Janssen Authorization Server Registration API description: Janssen Authorization Server - OAuth 2.0 server; OpenID Connect Provider (OP) & UMA Authorization Server (AS) contact: name: Contact url: https://github.com/JanssenProject/jans/discussions license: name: License url: https://github.com/JanssenProject/jans/blob/main/LICENSE version: OAS Version servers: - url: https://jans.local.io/jans-auth tags: - name: Registration paths: /restv1/bc-deviceRegistration: post: tags: - Registration summary: Performs backchannel device registration description: Performs backchannel device registration. operationId: bc-deviceRegistration requestBody: required: true content: application/x-www-form-urlencoded: schema: type: object required: - id_token_hint - device_registration_token properties: id_token_hint: type: string description: An ID Token previously issued to the Client by the OpenID Provider being passed back as a hint to identify the end-user for whom the device registration is being requested. device_registration_token: type: string description: OAuth 2.0 Client Identifier valid at the Authorization Serve responses: 200: description: OK content: {} 400: description: Invalid parameters are provided to endpoint. content: application/json: schema: type: object required: - error - error_description properties: error: type: string format: enum example: - invalid_request - invalid_scope - expired_login_hint_token - unknown_user_id - unauthorized_client - missing_user_code - invalid_user_code - invalid_binding_message - invalid_client - unauthorized_end_user_device - access_denied error_description: type: string details: type: string 403: $ref: '#/components/responses/AccessDenied' /restv1/register: post: tags: - Registration summary: Registers new client dynamically description: The Client Registration Endpoint is an OAuth 2.0 Protected Resource through which a new Client registration can be requested. operationId: post-register requestBody: content: application/json: schema: title: RegisterParams required: - redirect_uris type: object properties: redirect_uris: type: array description: Redirection URI values used by the Client. One of these registered Redirection URI values must exactly match the redirect_uri parameter value used in each Authorization Request items: type: string example: - https://client.example.org/cb claims_redirect_uri: type: array description: Array of The Claims Redirect URIs to which the client wishes the authorization server to direct the requesting party's user agent after completing its interaction. items: type: string response_types: type: array description: A list of the OAuth 2.0 response_type values that the Client is declaring that it will restrict itself to using. If omitted, the default is that the Client will use only the code Response Type. Allowed values are code, token, id_token. items: type: string grant_types: type: array description: A list of the OAuth 2.0 Grant Types that the Client is declaring that it will restrict itself to using. items: type: string contacts: type: array description: e-mail addresses of people responsible for this Client. items: type: string client_name: type: string description: Name of the Client to be presented to the user. authorization_details_types: type: array description: authorization details types (RFC9396). Fine-graned access. items: type: string logo_uri: type: string description: URL that references a logo for the Client application client_uri: type: string description: URL of the home page of the Client. The value of this field must point to a valid Web page. policy_uri: type: string description: URL that the Relying Party Client provides to the End-User to read about the how the profile data will be used. tos_uri: type: string description: URL that the Relying Party Client provides to the End-User to read about the Relying Party's terms of service. jwks_uri: type: string description: URL for the Client's JSON Web Key Set (JWK) document containing key(s) that are used for signing requests to the OP. The JWK Set may also contain the Client's encryption keys(s) that are used by the OP to encrypt the responses to the Client. When both signing and encryption keys are made available, a use (Key Use) parameter value is required for all keys in the document to indicate each key's intended usage . jwks: type: array description: List of JSON Web Key (JWK) - A JSON object that represents a cryptographic key. The members of the object represent properties of the key, including its value. items: $ref: '#/components/schemas/JsonWebKey' example: '{ "keys" : [ { "e" : "AQAB", "n" : "gmlDX_mgMcHX.." ] }' sector_identifier_uri: type: string description: URL using the https scheme to be used in calculating Pseudonymous Identifiers by the OP. subject_type: type: string description: Subject type requested for the Client ID. Valid types include pairwise and public. rpt_as_jwt: type: boolean description: Specifies whether RPT should be return as signed JWT. access_token_as_jwt: type: boolean description: Specifies whether access token as signed JWT. access_token_signing_alg: type: string description: Specifies signing algorithm that has to be used during JWT signing. If it's not specified, then the default OP signing algorithm will be used . id_token_signed_response_alg: type: string description: JWS alg algorithm (JWA) required for signing the ID Token issued to this Client. id_token_encrypted_response_alg: type: string description: JWE alg algorithm (JWA) required for encrypting the ID Token issued to this Client. id_token_encrypted_response_enc: type: string description: JWE enc algorithm (JWA) required for encrypting the ID Token issued to this Client. userinfo_signed_response_alg: type: string description: JWS alg algorithm (JWA) required for signing UserInfo Responses. userinfo_encrypted_response_alg: type: string description: JWE alg algorithm (JWA) required for encrypting UserInfo Responses. userinfo_encrypted_response_enc: type: string description: JWE enc algorithm (JWA) required for encrypting UserInfo Responses. introspection_signed_response_alg: type: string description: JWS alg algorithm (JWA) required for signing Introspection Responses. introspection_encrypted_response_alg: type: string description: JWE alg algorithm (JWA) required for encrypting Introspection Responses. introspection_encrypted_response_enc: type: string description: JWE enc algorithm (JWA) required for encrypting Introspection Responses. logout_status_jwt_signed_response_alg: type: string description: JWS alg algorithm (JWA) required for signing Logout Status JWT. tx_token_signed_response_alg: type: string description: JWS alg algorithm (JWA) required for signing Transaction Token Responses. tx_token_encrypted_response_alg: type: string description: JWE alg algorithm (JWA) required for encrypting Transaction Token Responses. tx_token_encrypted_response_enc: type: string description: JWE enc algorithm (JWA) required for encrypting Transaction Token Responses. request_object_signing_alg: type: string description: JWS alg algorithm (JWA) that must be used for signing Request Objects sent to the OP. request_object_encryption_alg: type: string description: JWE alg algorithm (JWA) the RP is declaring that it may use for encrypting Request Objects sent to the OP. request_object_encryption_enc: type: string description: JWE enc algorithm (JWA) the RP is declaring that it may use for encrypting Request Objects sent to the OP. token_endpoint_auth_method: type: string description: Requested Client Authentication method for the Token Endpoint. additional_token_endpoint_auth_method: type: array description: Array of additional Client Authentication methods for the Token Endpoint items: type: string token_endpoint_auth_signing_alg: type: string description: JWS alg algorithm (JWA) that must be used for signing the JWT used to authenticate the Client at the Token Endpoint for the private_key_jwt and client_secret_jwt authentication methods. default_max_age: type: integer description: Specifies the Default Maximum Authentication Age. example: 1000000 require_pkce: type: boolean description: Boolean specifying whether PKCE is required by client. Defalut value is false. require_auth_time: type: boolean description: Boolean value specifying whether the auth_time Claim in the ID Token is required. It is required when the value is true. default_acr_values: type: array description: Array of default requested Authentication Context Class Reference values that the Authorization Server must use for processing requests from the Client. items: type: string minimum_acr_level: type: integer description: Integer value which sets minimum acr level. example: 10 minimum_acr_level_autoresolve: type: boolean description: boolean value, if false and minimum_acr_level is higher then current acr_values then reject request. If true - resolve acr according to either client's minimum_acr_priority_list or AS auth_level_mapping minimum_acr_priority_list: type: array description: enables client to specify the acr order of preference, rather then just the next lowest integer value items: type: string groups: type: array description: Array of client's groups. items: type: string initiate_login_uri: type: string description: Specifies the URI using the https scheme that the authorization server can call to initiate a login at the client. post_logout_redirect_uris: type: array description: Provide the URLs supplied by the RP to request that the user be redirected to this location after a logout has been performed. example: - https://client.example.org/logout/page1 - https://client.example.org/logout/page2 - https://client.example.org/logout/page3 items: type: string frontchannel_logout_uri: type: string description: RP URL that will cause the RP to log itself out when rendered in an iframe by the OP. frontchannel_logout_session_required: type: boolean description: Boolean value specifying whether the RP requires that a session ID query parameter be included to identify the RP session at the OP when the logout_uri is used. If omitted, the default value is false. backchannel_logout_uri: type: string description: RP URL that will cause the RP to log itself out when sent a Logout Token by the OP. backchannel_logout_session_required: type: boolean description: Boolean value specifying whether the RP requires that a session ID Claim be included in the Logout Token to identify the RP session with the OP when the backchannel_logout_uri is used. If omitted, the default value is false. request_uris: type: array description: Provide a list of request_uri values that are pre-registered by the Client for use at the Authorization Server. items: type: string scopes: type: string deprecated: true description: This param will be removed in a future version because the correct is 'scope' not 'scopes', see (rfc7591). claims: type: string description: String containing a space-separated list of claims that can be requested individually. id_token_token_binding_cnf: type: string description: Specifies the JWT Confirmation Method member name (e.g. tbh) that the Relying Party expects when receiving Token Bound ID Tokens. The presence of this parameter indicates that the Relying Party supports Token Binding of ID Tokens. If omitted, the default is that the Relying Party does not support Token Binding of ID Tokens. tls_client_auth_subject_dn: type: string description: An string representation of the expected subject distinguished name of the certificate, which the OAuth client will use in mutual TLS authentication. spiffe_id: type: string description: The SPIFFE ID of the client (e.g. spiffe://example.org/my-oauth-client), used by SPIFFE-based client authentication (draft-ietf-oauth-spiffe-client-auth). May have a trailing "/*" for path-segment prefix matching against presented SVIDs. spiffe_bundle_endpoint: type: string description: URL of the SPIFFE Bundle Endpoint for the client's trust domain, per draft-ietf-oauth-spiffe-client-auth. Informational only - the authorization server validates SVIDs against its own admin-configured trust bundle mapping, not this client-supplied value. allow_spontaneous_scopes: type: boolean description: Specifies whether to allow spontaneous scopes for client. The default value is false. example: false spontaneous_scopes: type: array description: List of spontaneous scopes items: type: string run_introspection_script_before_jwt_creation: type: boolean description: Boolean value with default value false. If true and access_token_as_jwt=true then run introspection script and transfer claims into JWT. keep_client_authorization_after_expiration: type: boolean description: Boolean value indicating if the client authorization will not be removed afer expiration (expiration date is same as client's expiration that created it). The default value is false. scope: type: array description: Provide list of scope which are used during authentication to authorize access to resource. example: - openid items: type: string authorized_origins: type: array description: specifies authorized JavaScript origins. items: type: string access_token_lifetime: type: integer description: Specifies the Client-specific access token expiration in seconds. example: 600 id_token_lifetime: type: integer description: Specifies the Client-specific id_token expiration in seconds. example: 600 tx_token_lifetime: type: integer description: Specifies the Client-specific tx_token expiration in seconds. example: 600 par_lifetime: type: integer description: Specifies the Client-specific PAR expiration in seconds. example: 600 lifetime: type: integer description: Specifies the client expiration in seconds. example: 600 evidence: type: string description: Evidence is a set of claims generated by an attester to be appraised by a verifier. Evidence may include configuration data, measurements, telemetry, or inferences. This is a string value containing the evidence, as produced by the selected attestation technology. dpop_bound_access_tokens: type: boolean description: boolean value specifying whether the client always uses DPoP for token requests. If omitted, the default value is false additional_token_endpoint_auth_methods: type: array description: requested additional authentication methods for the Token Endpoint. items: type: string require_pushed_authorization_requests: type: boolean description: Boolean parameter indicating whether the only means of initiating an authorization request the client is allowed to use is a pushed authorization request. If omitted, the default value is "false". software_id: type: string description: Specifies a unique identifier string (UUID) assigned by the client developer or software publisher used by registration endpoints to identify the client software to be dynamically registered. example: 4NRB1-0XZABZI9E6-5SM3R software_version: type: string description: Specifies a version identifier string for the client software identified by 'software_id'. The value of the 'software_version' should change on any update to the client software identified by the same 'software_id'. example: '2.1' software_statement: type: string description: specifies a software statement containing client metadata values about the client software as claims. This is a string value containing the entire signed JWT. backchannel_token_delivery_mode: type: string description: specifies how backchannel token will be deliveried. example: push, poll, ping backchannel_client_notification_endpoint: type: string description: Client Initiated Backchannel Authentication (CIBA) enables a Client to initiate the authentication of an end-user by means of out-of-band mechanisms. Upon receipt of the notification, the Client makes a request to the token endpoint to obtain the tokens. backchannel_authentication_request_signing_alg: type: string description: The JWS algorithm alg value that the Client will use for signing authentication request, as described in Section 7.1.1. of OAuth 2.0 [RFC6749]. When omitted, the Client will not send signed authentication requests. backchannel_user_code_parameter: type: boolean description: Boolean value specifying whether the Client supports the user_code parameter. If omitted, the default value is false. additional_audience: type: array description: Additional audiences. items: type: string spontaneous_scope_script_dns: type: array description: Spontaneous scope script dns items: type: string par_script_dns: type: array description: PAR script dns items: type: string tx_token_script_dns: type: array description: Transaction Token script dns items: type: string logout_status_jwt_script_dns: type: array description: Logout status jwt script dns items: type: string update_token_script_dns: type: array description: Update token script dns items: type: string logout_status_script_dns: type: array description: Logout status jwt script dns items: type: string post_authn_script_dns: type: array description: Post Authn script dns items: type: string token_exchange_script_dns: type: array description: Token Exchange script dns items: type: string id_jag_script_dns: type: array description: Identity Assertion (ID-JAG) script dns items: type: string consent_gathering_script_dns: type: array description: Consent Gathering script dns items: type: string introspection_script_dns: type: array description: Introspection script dns items: type: string rpt_claims_script_dns: type: array description: RPT Claims script dns items: type: string ropc_script_dns: type: array description: ROPC script dns items: type: string org_id: type: string description: Organization Id responses: 200: description: OK content: application/json: schema: title: RegisterResponseParam type: object required: - client_id properties: client_id: type: string description: Unique Client Identifier. It MUST NOT be currently valid for any other registered Client. client_secret: type: string description: This value is used by Confidential Clients to authenticate to the Token Endpoint registration_access_token: type: string description: Registration Access Token that can be used at the Client Configuration Endpoint to perform subsequent operations upon the Client registration. registration_client_uri: type: string description: Location of the Client Configuration Endpoint where the Registration Access Token can be used to perform subsequent operations upon the resulting Client registration. client_id_issued_at: type: integer description: Time at which the Client Identifier was issued. client_secret_expires_at: type: integer description: Time at which the client_secret will expire or 0 if it will not expire. org_id: type: string description: Organization Id. Present only when organization id is set. 400: description: Invalid parameters provided to endpoint. content: application/json: schema: type: object required: - error - error_description properties: error: type: string format: enum example: - invalid_redirect_uri - invalid_claims_redirect_uri - invalid_client_metadata - invalid_token - invalid_logout_uri - invalid_software_statement - access_denied error_description: type: string details: type: string 500: $ref: '#/components/responses/InternalServerError' put: tags: - Registration summary: Updates Client Metadata for a registered client description: Updates Client Metadata for a registered client. operationId: put-register parameters: - name: client_id in: query required: true description: Client ID that identifies client that must be updated by this request. schema: type: string - name: Authorization in: header required: true description: Authorization header carrying \"registration_access_token\" issued before as a Bearer token schema: type: string requestBody: content: application/json: schema: title: RegisterParams required: - redirect_uris type: object properties: redirect_uris: type: array description: Redirection URI values used by the Client. One of these registered Redirection URI values must exactly match the redirect_uri parameter value used in each Authorization Request items: type: string example: - https://client.example.org/cb claims_redirect_uri: type: array description: Array of The Claims Redirect URIs to which the client wishes the authorization server to direct the requesting party's user agent after completing its interaction. items: type: string response_types: type: array description: A list of the OAuth 2.0 response_type values that the Client is declaring that it will restrict itself to using. If omitted, the default is that the Client will use only the code Response Type. Allowed values are code, token, id_token. items: type: string grant_types: type: array description: A list of the OAuth 2.0 Grant Types that the Client is declaring that it will restrict itself to using. items: type: string contacts: type: array description: e-mail addresses of people responsible for this Client. items: type: string authorization_details_types: type: array description: authorization details types (RFC9396). Fine-graned access. items: type: string client_name: type: string description: Name of the Client to be presented to the user. logo_uri: type: string description: URL that references a logo for the Client application client_uri: type: string description: URL of the home page of the Client. The value of this field must point to a valid Web page. policy_uri: type: string description: URL that the Relying Party Client provides to the End-User to read about the how the profile data will be used. tos_uri: type: string description: URL that the Relying Party Client provides to the End-User to read about the Relying Party's terms of service. jwks_uri: type: string description: URL for the Client's JSON Web Key Set (JWK) document containing key(s) that are used for signing requests to the OP. The JWK Set may also contain the Client's encryption keys(s) that are used by the OP to encrypt the responses to the Client. When both signing and encryption keys are made available, a use (Key Use) parameter value is required for all keys in the document to indicate each key's intended usage . jwks: type: array description: List of JSON Web Key (JWK) - A JSON object that represents a cryptographic key. The members of the object represent properties of the key, including its value. items: $ref: '#/components/schemas/JsonWebKey' example: '{ "keys" : [ { "e" : "AQAB", "n" : "gmlDX_mgMcHX.." ] }' sector_identifier_uri: type: string description: URL using the https scheme to be used in calculating Pseudonymous Identifiers by the OP. subject_type: type: string description: Subject type requested for the Client ID. Valid types include pairwise and public. rpt_as_jwt: type: boolean description: Specifies whether RPT should be return as signed JWT. access_token_as_jwt: type: boolean description: Specifies whether access token as signed JWT. access_token_signing_alg: type: string description: Specifies signing algorithm that has to be used during JWT signing. If it's not specified, then the default OP signing algorithm will be used . id_token_signed_response_alg: type: string description: JWS alg algorithm (JWA) required for signing the ID Token issued to this Client. id_token_encrypted_response_alg: type: string description: JWE alg algorithm (JWA) required for encrypting the ID Token issued to this Client. id_token_encrypted_response_enc: type: string description: JWE enc algorithm (JWA) required for encrypting the ID Token issued to this Client. userinfo_signed_response_alg: type: string description: JWS alg algorithm (JWA) required for signing UserInfo Responses. userinfo_encrypted_response_alg: type: string description: JWE alg algorithm (JWA) required for encrypting UserInfo Responses. userinfo_encrypted_response_enc: type: string description: JWE enc algorithm (JWA) required for encrypting UserInfo Responses. introspection_signed_response_alg: type: string description: JWS alg algorithm (JWA) required for signing Introspection Responses. introspection_encrypted_response_alg: type: string description: JWE alg algorithm (JWA) required for encrypting Introspection Responses. introspection_encrypted_response_enc: type: string description: JWE enc algorithm (JWA) required for encrypting Introspection Responses. logout_status_jwt_signed_response_alg: type: string description: JWS alg algorithm (JWA) required for signing Logout Status JWT. tx_token_signed_response_alg: type: string description: JWS alg algorithm (JWA) required for signing Transaction Token Responses. tx_token_encrypted_response_alg: type: string description: JWE alg algorithm (JWA) required for encrypting Transaction Token Responses. tx_token_encrypted_response_enc: type: string description: JWE enc algorithm (JWA) required for encrypting Transaction Token Responses. request_object_signing_alg: type: string description: JWS alg algorithm (JWA) that must be used for signing Request Objects sent to the OP. request_object_encryption_alg: type: string description: JWE alg algorithm (JWA) the RP is declaring that it may use for encrypting Request Objects sent to the OP. request_object_encryption_enc: type: string description: JWE enc algorithm (JWA) the RP is declaring that it may use for encrypting Request Objects sent to the OP. token_endpoint_auth_method: type: string description: Requested Client Authentication method for the Token Endpoint. additional_token_endpoint_auth_method: type: array description: Array of additional Client Authentication methods for the Token Endpoint items: type: string token_endpoint_auth_signing_alg: type: string description: JWS alg algorithm (JWA) that must be used for signing the JWT used to authenticate the Client at the Token Endpoint for the private_key_jwt and client_secret_jwt authentication methods. default_max_age: type: integer description: Specifies the Default Maximum Authentication Age. example: 1000000 require_pkce: type: boolean description: Boolean specifying whether PKCE is required by client. Defalut value is false. require_auth_time: type: boolean description: Boolean value specifying whether the auth_time Claim in the ID Token is required. It is required when the value is true. default_acr_values: type: array description: Array of default requested Authentication Context Class Reference values that the Authorization Server must use for processing requests from the Client. items: type: string minimum_acr_level: type: integer description: Integer value which sets minimum acr level. example: 10 minimum_acr_level_autoresolve: type: boolean description: boolean value, if false and minimum_acr_level is higher then current acr_values then reject request. If true - resolve acr according to either client's minimum_acr_priority_list or AS auth_level_mapping minimum_acr_priority_list: type: array description: enables client to specify the acr order of preference, rather then just the next lowest integer value items: type: string initiate_login_uri: type: string description: Specifies the URI using the https scheme that the authorization server can call to initiate a login at the client. groups: type: array description: Array of client's groups. items: type: string post_logout_redirect_uris: type: array description: Provide the URLs supplied by the RP to request that the user be redirected to this location after a logout has been performed. example: - https://client.example.org/logout/page1 - https://client.example.org/logout/page2 - https://client.example.org/logout/page3 items: type: string frontchannel_logout_uri: type: string description: RP URL that will cause the RP to log itself out when rendered in an iframe by the OP. frontchannel_logout_session_required: type: boolean description: Boolean value specifying whether the RP requires that a session ID query parameter be included to identify the RP session at the OP when the logout_uri is used. If omitted, the default value is false. backchannel_logout_uri: type: string description: RP URL that will cause the RP to log itself out when sent a Logout Token by the OP. backchannel_logout_session_required: type: boolean description: Boolean value specifying whether the RP requires that a session ID Claim be included in the Logout Token to identify the RP session with the OP when the backchannel_logout_uri is used. If omitted, the default value is false. request_uris: type: array description: Provide a list of request_uri values that are pre-registered by the Client for use at the Authorization Server. items: type: string scopes: type: string deprecated: true description: This param will be removed in a future version because the correct is 'scope' not 'scopes', see (rfc7591). claims: type: string description: String containing a space-separated list of claims that can be requested individually. id_token_token_binding_cnf: type: string description: Specifies the JWT Confirmation Method member name (e.g. tbh) that the Relying Party expects when receiving Token Bound ID Tokens. The presence of this parameter indicates that the Relying Party supports Token Binding of ID Tokens. If omitted, the default is that the Relying Party does not support Token Binding of ID Tokens. tls_client_auth_subject_dn: type: string description: An string representation of the expected subject distinguished name of the certificate, which the OAuth client will use in mutual TLS authentication. spiffe_id: type: string description: The SPIFFE ID of the client (e.g. spiffe://example.org/my-oauth-client), used by SPIFFE-based client authentication (draft-ietf-oauth-spiffe-client-auth). May have a trailing "/*" for path-segment prefix matching against presented SVIDs. spiffe_bundle_endpoint: type: string description: URL of the SPIFFE Bundle Endpoint for the client's trust domain, per draft-ietf-oauth-spiffe-client-auth. Informational only - the authorization server validates SVIDs against its own admin-configured trust bundle mapping, not this client-supplied value. allow_spontaneous_scopes: type: boolean description: Specifies whether to allow spontaneous scopes for client. The default value is false. example: false spontaneous_scopes: type: array description: List of spontaneous scopes items: type: string run_introspection_script_before_jwt_creation: type: boolean description: Boolean value with default value false. If true and access_token_as_jwt=true then run introspection script and transfer claims into JWT. keep_client_authorization_after_expiration: type: boolean description: Boolean value indicating if the client authorization will not be removed afer expiration (expiration date is same as client's expiration that created it). The default value is false. scope: type: array description: Provide list of scope which are used during authentication to authorize access to resource. example: - openid items: type: string authorized_origins: type: array description: specifies authorized JavaScript origins. items: type: string access_token_lifetime: type: integer description: Specifies the Client-specific access token expiration in seconds. example: 600 id_token_lifetime: type: integer description: Specifies the Client-specific id_token expiration in seconds. example: 600 tx_token_lifetime: type: integer description: Specifies the Client-specific tx_token expiration in seconds. example: 600 par_lifetime: type: integer description: Specifies the Client-specific PAR expiration in seconds. example: 600 require_pushed_authorization_requests: type: boolean description: Boolean parameter indicating whether the only means of initiating an authorization request the client is allowed to use is a pushed authorization request. If omitted, the default value is "false". software_id: type: string description: Specifies a unique identifier string (UUID) assigned by the client developer or software publisher used by registration endpoints to identify the client software to be dynamically registered. example: 4NRB1-0XZABZI9E6-5SM3R software_version: type: string description: Specifies a version identifier string for the client software identified by 'software_id'. The value of the 'software_version' should change on any update to the client software identified by the same 'software_id'. example: '2.1' software_statement: type: string description: specifies a software statement containing client metadata values about the client software as claims. This is a string value containing the entire signed JWT. backchannel_token_delivery_mode: type: string description: specifies how backchannel token will be deliveried. example: push, poll, ping backchannel_client_notification_endpoint: type: string description: Client Initiated Backchannel Authentication (CIBA) enables a Client to initiate the authentication of an end-user by means of out-of-band mechanisms. Upon receipt of the notification, the Client makes a request to the token endpoint to obtain the tokens. backchannel_authentication_request_signing_alg: type: string description: The JWS algorithm alg value that the Client will use for signing authentication request, as described in Section 7.1.1. of OAuth 2.0 [RFC6749]. When omitted, the Client will not send signed authentication requests. backchannel_user_code_parameter: type: boolean description: Boolean value specifying whether the Client supports the user_code parameter. If omitted, the default value is false. additional_audience: type: array description: Additional audiences. items: type: string spontaneous_scope_script_dns: type: array description: Spontaneous scope script dns items: type: string logout_status_jwt_script_dns: type: array description: Logout status jwt script dns items: type: string par_script_dns: type: array description: PAR script dns items: type: string tx_token_script_dns: type: array description: Transaction Token script dns items: type: string update_token_script_dns: type: array description: Update token script dns items: type: string logout_status_script_dns: type: array description: Logout status jwt script dns items: type: string post_authn_script_dns: type: array description: Post Authn script dns items: type: string token_exchange_script_dns: type: array description: Token Exchange script dns items: type: string id_jag_script_dns: type: array description: Identity Assertion (ID-JAG) script dns items: type: string consent_gathering_script_dns: type: array description: Consent Gathering script dns items: type: string introspection_script_dns: type: array description: Introspection script dns items: type: string rpt_claims_script_dns: type: array description: RPT Claims script dns items: type: string ropc_script_dns: type: array description: ROPC script dns items: type: string responses: 200: description: OK content: application/json: schema: title: RegisterResponseParam type: object required: - client_id properties: client_id: type: string description: Unique Client Identifier. It MUST NOT be currently valid for any other registered Client. client_secret: type: string description: This value is used by Confidential Clients to authenticate to the Token Endpoint registration_access_token: type: string description: Registration Access Token that can be used at the Client Configuration Endpoint to perform subsequent operations upon the Client registration. registration_client_uri: type: string description: Location of the Client Configuration Endpoint where the Registration Access Token can be used to perform subsequent operations upon the resulting Client registration. client_id_issued_at: type: integer description: Time at which the Client Identifier was issued. client_secret_expires_at: type: integer description: Time at which the client_secret will expire or 0 if it will not expire. 400: description: Invalid parameters provided to endpoint. content: application/json: schema: type: object required: - error - error_description properties: error: type: string format: enum example: - invalid_client_metadata - invalid_token error_description: type: string details: type: string 500: $ref: '#/components/responses/InternalServerError' get: tags: - Registration summary: Get client information for a previously registered client description: Get client information for a previously registered client. operationId: get-register parameters: - name: client_id in: query required: true description: Client ID that identifies client. schema: type: string - name: Authorization in: header required: true description: Authorization header carrying \"registration_access_token\" issued before as a Bearer token schema: type: string responses: 200: description: OK content: application/json: schema: title: ClientResponse type: object properties: redirect_uris: type: array description: Redirection URI values used by the Client. One of these registered Redirection URI values must exactly match the redirect_uri parameter value used in each Authorization Request items: type: string example: - https://client.example.org/cb claims_redirect_uri: type: array description: Array of The Claims Redirect URIs to which the client wishes the authorization server to direct the requesting party's user agent after completing its interaction. items: type: string response_types: type: array description: A list of the OAuth 2.0 response_type values that the Client is declaring that it will restrict itself to using. If omitted, the default is that the Client will use only the code Response Type. Allowed values are code, token, id_token. items: type: string grant_types: type: array description: A list of the OAuth 2.0 Grant Types that the Client is declaring that it will restrict itself to using. items: type: string contacts: type: array description: e-mail addresses of people responsible for this Client. items: type: string authorization_details_types: type: array description: authorization details types (RFC9396). Fine-graned access. items: type: string client_name: type: string description: Name of the Client to be presented to the user. logo_uri: type: string description: URL that references a logo for the Client application client_uri: type: string description: URL of the home page of the Client. The value of this field must point to a valid Web page. policy_uri: type: string description: URL that the Relying Party Client provides to the End-User to read about the how the profile data will be used. tos_uri: type: string description: URL that the Relying Party Client provides to the End-User to read about the Relying Party's terms of service. jwks_uri: type: string description: URL for the Client's JSON Web Key Set (JWK) document containing key(s) that are used for signing requests to the OP. The JWK Set may also contain the Client's encryption keys(s) that are used by the OP to encrypt the responses to the Client. When both signing and encryption keys are made available, a use (Key Use) parameter value is required for all keys in the document to indicate each key's intended usage . jwks: type: string description: Client's JSON Web Key Set (JWK) document, passed by value. The semantics of the jwks parameter are the same as the jwks_uri parameter, other than that the JWK Set is passed by value, rather than by reference. This parameter is intended only to be used by Clients that, for some reason, are unable to use the jwks_uri parameter, for instance, by native applications that might not have a location to host the contents of the JWK Set. If a Client can use jwks_uri, it must not use jwks. One significant downside of jwks is that it does not enable key rotation. The jwks_uri and jwks parameters must not be used together. example: '{"key1": "value1", "key2": "value2"}' sector_identifier_uri: type: string description: URL using the https scheme to be used in calculating Pseudonymous Identifiers by the OP. subject_type: type: string description: Subject type requested for the Client ID. Valid types include pairwise and public. rpt_as_jwt: type: boolean description: Specifies whether RPT should be return as signed JWT. access_token_as_jwt: type: boolean description: Specifies whether access token as signed JWT. access_token_signing_alg: type: string description: Specifies signing algorithm that has to be used during JWT signing. If it's not specified, then the default OP signing algorithm will be used . id_token_signed_response_alg: type: string description: JWS alg algorithm (JWA) required for signing the ID Token issued to this Client. id_token_encrypted_response_alg: type: string description: JWE alg algorithm (JWA) required for encrypting the ID Token issued to this Client. id_token_encrypted_response_enc: type: string description: JWE enc algorithm (JWA) required for encrypting the ID Token issued to this Client. userinfo_signed_response_alg: type: string description: JWS alg algorithm (JWA) required for signing UserInfo Responses. userinfo_encrypted_response_alg: type: string description: JWE alg algorithm (JWA) required for encrypting UserInfo Responses. userinfo_encrypted_response_enc: type: string description: JWE enc algorithm (JWA) required for encrypting UserInfo Responses. introspection_signed_response_alg: type: string description: JWS alg algorithm (JWA) required for signing Introspection Responses. introspection_encrypted_response_alg: type: string description: JWE alg algorithm (JWA) required for encrypting Introspection Responses. introspection_encrypted_response_enc: type: string description: JWE enc algorithm (JWA) required for encrypting Introspection Responses. logout_status_jwt_signed_response_alg: type: string description: JWS alg algorithm (JWA) required for signing Logout Status JWT. tx_token_signed_response_alg: type: string description: JWS alg algorithm (JWA) required for signing Transaction Token Responses. tx_token_encrypted_response_alg: type: string description: JWE alg algorithm (JWA) required for encrypting Transaction Token Responses. tx_token_encrypted_response_enc: type: string description: JWE enc algorithm (JWA) required for encrypting Transaction Token Responses. request_object_signing_alg: type: string description: JWS alg algorithm (JWA) that must be used for signing Request Objects sent to the OP. request_object_encryption_alg: type: string description: JWE alg algorithm (JWA) the RP is declaring that it may use for encrypting Request Objects sent to the OP. request_object_encryption_enc: type: string description: JWE enc algorithm (JWA) the RP is declaring that it may use for encrypting Request Objects sent to the OP. token_endpoint_auth_method: type: string description: Requested Client Authentication method for the Token Endpoint. additional_token_endpoint_auth_method: type: array description: Array of additional Client Authentication methods for the Token Endpoint items: type: string token_endpoint_auth_signing_alg: type: string description: JWS alg algorithm (JWA) that must be used for signing the JWT used to authenticate the Client at the Token Endpoint for the private_key_jwt and client_secret_jwt authentication methods. default_max_age: type: integer description: Specifies the Default Maximum Authentication Age. example: 1000000 require_auth_time: type: boolean description: Boolean value specifying whether the auth_time Claim in the ID Token is required. It is required when the value is true. default_acr_values: type: array description: Array of default requested Authentication Context Class Reference values that the Authorization Server must use for processing requests from the Client. items: type: string minimum_acr_level: type: integer description: Integer value which sets minimum acr level. example: 10 minimum_acr_level_autoresolve: type: boolean description: boolean value, if false and minimum_acr_level is higher then current acr_values then reject request. If true - resolve acr according to either client's minimum_acr_priority_list or AS auth_level_mapping minimum_acr_priority_list: type: array description: enables client to specify the acr order of preference, rather then just the next lowest integer value items: type: string initiate_login_uri: type: string description: Specifies the URI using the https scheme that the authorization server can call to initiate a login at the client. groups: type: array description: Array of client's groups. items: type: string post_logout_redirect_uris: type: array description: Provide the URLs supplied by the RP to request that the user be redirected to this location after a logout has been performed. example: - https://client.example.org/logout/page1 - https://client.example.org/logout/page2 - https://client.example.org/logout/page3 items: type: string frontchannel_logout_uri: type: string description: RP URL that will cause the RP to log itself out when rendered in an iframe by the OP. frontchannel_logout_session_required: type: boolean description: Boolean value specifying whether the RP requires that a session ID query parameter be included to identify the RP session at the OP when the logout_uri is used. If omitted, the default value is false. backchannel_logout_uri: type: string description: RP URL that will cause the RP to log itself out when sent a Logout Token by the OP. backchannel_logout_session_required: type: boolean description: Boolean value specifying whether the RP requires that a session ID Claim be included in the Logout Token to identify the RP session with the OP when the backchannel_logout_uri is used. If omitted, the default value is false. request_uris: type: array description: Provide a list of request_uri values that are pre-registered by the Client for use at the Authorization Server. items: type: string scopes: type: string deprecated: true description: This param will be removed in a future version because the correct is 'scope' not 'scopes', see (rfc7591). claims: type: string description: String containing a space-separated list of claims that can be requested individually. id_token_token_binding_cnf: type: string description: Specifies the JWT Confirmation Method member name (e.g. tbh) that the Relying Party expects when receiving Token Bound ID Tokens. The presence of this parameter indicates that the Relying Party supports Token Binding of ID Tokens. If omitted, the default is that the Relying Party does not support Token Binding of ID Tokens. tls_client_auth_subject_dn: type: string description: An string representation of the expected subject distinguished name of the certificate, which the OAuth client will use in mutual TLS authentication. spiffe_id: type: string description: The SPIFFE ID of the client (e.g. spiffe://example.org/my-oauth-client), used by SPIFFE-based client authentication (draft-ietf-oauth-spiffe-client-auth). May have a trailing "/*" for path-segment prefix matching against presented SVIDs. spiffe_bundle_endpoint: type: string description: URL of the SPIFFE Bundle Endpoint for the client's trust domain, per draft-ietf-oauth-spiffe-client-auth. Informational only - the authorization server validates SVIDs against its own admin-configured trust bundle mapping, not this client-supplied value. allow_spontaneous_scopes: type: boolean description: Specifies whether to allow spontaneous scopes for client. The default value is false. example: false spontaneous_scopes: type: array description: List of spontaneous scopes items: type: string run_introspection_script_before_jwt_creation: type: boolean description: Boolean value with default value false. If true and access_token_as_jwt=true then run introspection script and transfer claims into JWT. keep_client_authorization_after_expiration: type: boolean description: Boolean value indicating if the client authorization will not be removed afer expiration (expiration date is same as client's expiration that created it). The default value is false. scope: type: array description: Provide list of scope which are used during authentication to authorize access to resource. example: - openid items: type: string authorized_origins: type: array description: specifies authorized JavaScript origins. items: type: string access_token_lifetime: type: integer description: Specifies the Client-specific access token expiration. example: 100 id_token_lifetime: type: integer description: Specifies the Client-specific id_token expiration in seconds. example: 600 tx_token_lifetime: type: integer description: Specifies the Client-specific tx_token expiration in seconds. example: 600 par_lifetime: type: integer description: Specifies the Client-specific PAR expiration in seconds. example: 600 require_pushed_authorization_requests: type: boolean description: Boolean parameter indicating whether the only means of initiating an authorization request the client is allowed to use is a pushed authorization request. If omitted, the default value is "false". software_id: type: string description: Specifies a unique identifier string (UUID) assigned by the client developer or software publisher used by registration endpoints to identify the client software to be dynamically registered. example: 4NRB1-0XZABZI9E6-5SM3R software_version: type: string description: Specifies a version identifier string for the client software identified by 'software_id'. The value of the 'software_version' should change on any update to the client software identified by the same 'software_id'. example: '2.1' software_statement: type: string description: specifies a software statement containing client metadata values about the client software as claims. This is a string value containing the entire signed JWT. backchannel_token_delivery_mode: type: string description: specifies how backchannel token will be deliveried. example: push, poll, ping backchannel_client_notification_endpoint: type: string description: Client Initiated Backchannel Authentication (CIBA) enables a Client to initiate the authentication of an end-user by means of out-of-band mechanisms. Upon receipt of the notification, the Client makes a request to the token endpoint to obtain the tokens. backchannel_authentication_request_signing_alg: type: string description: The JWS algorithm alg value that the Client will use for signing authentication request, as described in Section 7.1.1. of OAuth 2.0 [RFC6749]. When omitted, the Client will not send signed authentication requests. backchannel_user_code_parameter: type: boolean description: Boolean value specifying whether the Client supports the user_code parameter. If omitted, the default value is false. 400: description: Invalid parameters provided to endpoint. content: application/json: schema: type: object required: - error - error_description properties: error: type: string format: enum example: - invalid_token - invalid_client_metadata - access_denied error_description: type: string details: type: string 401: $ref: '#/components/responses/InvalidRequest' 500: $ref: '#/components/responses/InternalServerError' components: schemas: ErrorResponse: required: - error - error_description type: object properties: error: type: string error_description: type: string details: type: string JsonWebKey: required: - alg - exp - kid - kty - use - x5c type: object properties: kid: type: string kty: type: string use: type: string alg: type: string crv: type: string exp: type: integer format: int64 x5c: type: array items: type: string n: type: string e: type: string x: type: string y: type: string responses: InvalidRequest: description: Invalid parameters are provided to endpoint. content: application/json: schema: $ref: '#/components/schemas/ErrorResponse' InternalServerError: description: Internal error occured. Please check log file for details. content: application/json: schema: $ref: '#/components/schemas/ErrorResponse' AccessDenied: description: Invalid details provided hence access denied. content: application/json: schema: $ref: '#/components/schemas/ErrorResponse' securitySchemes: bearer: type: http scheme: bearer