Skip to content

Conversation

@tplooker
Copy link
Collaborator

@tplooker tplooker commented Sep 9, 2025

Closes #56
Fixes #114

Looking for feedback on the approach here @panva.

I've opted to not require this behaviour via RECOMMENDED over a MUST this also makes it forward compatible with future OAuth2 extensions that might define new protocol artefacts.

@c2bo
Copy link
Member

c2bo commented Sep 14, 2025

I think it would make sense to reference the refresh token description that is given above this section as an example?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Further attest_jwt_client_auth client instance bindings Authorization code binding to client instance

5 participants