[External] Re: OIDC for Mobile App

Hall, Gerry gerry.hall at emory.edu
Wed Aug 6 17:18:51 UTC 2025


Thanks Scott…
Think I am good now.

From: Cantor, Scott <cantor.2 at osu.edu>
Date: Wednesday, August 6, 2025 at 12:30 PM
To: Hall, Gerry <gerry.hall at emory.edu>, Shib Users <users at shibboleth.net>
Subject: Re: [External] Re: OIDC for Mobile App

>Scott, There is no client metadata for the OIDC services.
> The extent of the config is below.

That is (JSON format) client metadata and I see it specifies the relevant setting.

The OP I think defaults to global rules that limit what registered client authn methods for the token endpoint are allowed, so the logs should say that clearly and trip up on that. The OAUTH.Token profile config bean has settings we document for the rules it applies.

https://nam11.safelinks.protection.outlook.com/?url=https%3A%2F%2Fshibboleth.atlassian.net%2Fwiki%2Fspaces%2FIDPPLUGINS%2Fpages%2F2931327005%2FOPToken&data=05%7C02%7Cgerry.hall%40emory.edu%7Cca5c816a57dd4920d8ff08ddd5067c23%7Ce004fb9cb0a4424fbcd0322606d5df38%7C0%7C0%7C638900946027330568%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=H6og85A%2B2WMG2k2uJd2qlZuN3IsuCSfmmkq1yrXGGv4%3D&reserved=0<https://shibboleth.atlassian.net/wiki/spaces/IDPPLUGINS/pages/2931327005/OPToken>

tokenEndpointAuthMethods

-- Scott


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20250806/f0c62b41/attachment.htm>


More information about the users mailing list