Re: [OAUTH-WG] Conflicting definitions in JWT Response for OAuth Token Introspection

2020-03-06 Thread Takahiko Kawasaki
Regarding the name of the JSON property in the payload of the introspection response JWT. If we choose a more generic name (e.g. "content") than "token_data", the approach discussed here can be used as a generic way to wrap a JSON response in JWT. If we are ambitious, we can even add "content_type

Re: [OAUTH-WG] I-D Action: draft-ietf-oauth-access-token-jwt-04.txt

2020-03-06 Thread Vittorio Bertocci
Dear all, I am still not sure if I'll have approval to travel to Vancouver and attend IETF107 in person- but in any case, here's a new revision of the JWT AT profile. The main changes are all about Brian and Annabelle's feedback and suggestions. Notable: o Eliminated all the references to res

[OAUTH-WG] I-D Action: draft-ietf-oauth-access-token-jwt-04.txt

2020-03-06 Thread internet-drafts
A New Internet-Draft is available from the on-line Internet-Drafts directories. This draft is a work item of the Web Authorization Protocol WG of the IETF. Title : JSON Web Token (JWT) Profile for OAuth 2.0 Access Tokens Author : Vittorio Bertocci File

[OAUTH-WG] TxAuth WG formation consensus call

2020-03-06 Thread Yaron Sheffer
Hi, We have just posted a call for consensus on the TxAuth list. People on this list might want to pop over and review it [1] and possibly respond. All discussion will take place on the TxAuth list. Thanks,     Yaron [1] https://mailarchive.ietf.org/arch/msg/txauth/G7kcSq