You may want to explicitly state that additional elements are allowed but not standardized. FWIW, the wording we settled on in UMA, after consulting similar specs like OpenID Connect, was: “Authorization server configuration data MAY contain extension properties that are not defined in this specification. Extension names that are unprotected from collisions are outside the scope of this specification.”
3.9. Extensions
TBD
You may want to explicitly state that additional elements are allowed but not standardized. FWIW, the wording we settled on in UMA, after consulting similar specs like OpenID Connect, was: “Authorization server configuration data MAY contain extension properties that are not defined in this specification. Extension names that are unprotected from collisions are outside the scope of this specification.”