ConsumerDataStandardsAustralia / infosec

Work space for the consumer data right information security profile development in Australia
MIT License
16 stars 5 forks source link

Refine Introspection Endpoint section #11

Closed lukepopp closed 5 years ago

lukepopp commented 5 years ago

The introspection endpoint section will be updated to remove the capability for introspection of the access tokens by Relying Parties. This is not needed by RPs (nor is it appropriate) and will be replaced with introspection of the refresh tokens. Furthermore, in accordance with RAPI-R profile, scopes granted will be returned from the Token Endpoint:

  1. shall return the list of granted scopes with the issued access token
    https://openid.net/specs/openid-financial-api-part-1.html#token-request-and-response