Closed martin-lindstrom closed 11 months ago
Closes #91
Added writing telling that if something else than private_key_jwt is used for client authentication at the Token endpoint this method must be explicitly allowed by the policy under which an OP is functioning.
private_key_jwt
Late to the party here, but I think this addition looks good !
Closes #91
Added writing telling that if something else than
private_key_jwt
is used for client authentication at the Token endpoint this method must be explicitly allowed by the policy under which an OP is functioning.