Hi,

both options are viable. It depends on the purpose the token is used for in a particular deployment, esp. whether it carries the data about the resource and it owner or whether it merely represents the authorization of the particular client.

regards,
Torsten.

Am 15.11.2012 21:03, schrieb Security Developer:
Hi,

If an access token is either SAML or JWT in OAuth then what would be the value in subject either resource owner or client application name?

Thanks for your time.

Regards,


_______________________________________________
OAuth mailing list
OAuth@ietf.org
https://www.ietf.org/mailman/listinfo/oauth

_______________________________________________
OAuth mailing list
OAuth@ietf.org
https://www.ietf.org/mailman/listinfo/oauth

Reply via email to