Browse Source
RFC 9068 requires that access token JWTs include the `client_id` claim, but it does not require resource servers to validate it against a specific value. Relates to gh-18381 Signed-off-by: Giacomo Baso <gbaso@users.noreply.github.com>pull/18890/head
2 changed files with 22 additions and 1 deletions
Loading…
Reference in new issue