Draft -10<https://tools.ietf.org/html/draft-ietf-oauth-token-exchange-10> added 
the token type URIs urn:ietf:params:oauth:token-type:saml1 and 
urn:ietf:params:oauth:token-type:saml2 in response to actual developer token 
exchange use cases that needed identifiers for both kinds of SAML tokens.

                                                                -- Mike

From: Mike Jones
Sent: Tuesday, October 3, 2017 6:51 AM
To: oauth@ietf.org
Subject: Adding a SAML 2 token type to the OAuth Token Exchange spec

A Microsoft use case has come up in which people would like to perform a token 
exchange for a SAML token. The spec already defines 
urn:ietf:params:oauth:token-type:jwt for requesting JWT tokens.  Would anybody 
object to us adding urn:ietf:params:oauth:token-type:saml2 to the next draft to 
also give us a standard way to ask for SAML 2.0 tokens?

It could always be done in its own spec, but adding it in Token Exchange seems 
more expedient.

                                                                     -- Mike

OAuth mailing list

Reply via email to