Hi Vittorio,
Thanks for the good starting point of standardizing JWT-ized AT.
One feedback.
The “sub” claim can include 2 types of identifier, end-user and client, in this
spec.
It requires those 2 types of identifiers to be unique each other in the IdP
context.
I prefer omitting “sub” claim
Dear all,
I just submitted a draft describing a JWT profile for OAuth 2.0 access
tokens. You can find it in
https://datatracker.ietf.org/doc/draft-bertocci-oauth-access-token-jwt/.
I have a slot to discuss this tomorrow at IETF 104 (I'll be presenting
remotely). I look forward for your comments!
H