Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.
Comment: Published by Scroll Versions from space PDOIDC and version xID_Demo_OIDC

OIDC Clients must authenticate with the OIDC Provider for the Authorize, Token and Introspect Endpoints. The following authentication scheme is currently supported:Among the standardized authentication methods the following are currently supported by the OIDC Provider from BankID: 

The required scheme for any OIDC Client is determined when the OIDC Client is configured at the OIDC Provider.

Warning
titleNote

Support for other OIDC authentication schemes like client_secret_post,  client_secret_jwt and private_key_jwt will may be added as future options, eg. in conjunction with PSD2-support

OIDC Clients requesting access to Protected Resources VAS-services that uses the OIDC Provider for authorization must in addition authenticate with Resource VAS-Servers using Access Tokens from the OIDC Provider. The type of Access Token and also the scheme for passing such tokens to Resources Servers VAS-servers are specific for each of the supported kinds of Protected Resources Value Added Services (VAS).