[OAUTH-WG] Query on RFC 7591 - dynamic client registration protocol

2019-05-14 Thread Sahler, Frank
Hello, I read in the dynamic client registration documentation of the company curity (https://developer.curity.io/tutorials/dynamic-client-registration-overview) that they use the scope "dcr" in the authorization request to get an initial access token i.e. a bearer token that only allows access

[OAUTH-WG] Query on RFC6749

2019-05-14 Thread NARAIN, SHISHIR (DD & MI (L), Group Transformation)
Classification: Public Hello, I have a query about OAuth error message structure. I understand that the message structure is defined at https://tools.ietf.org/html/rfc6749#section-5.2 but I am not sure if the following response is a valid OAuth response as per the spec? HTTP/1.1 400 Bad Reques