<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
</head>
<body>
<div dir="ltr" style="font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt;">
Thanks Scott…</div>
<div dir="ltr" style="font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Think I am good now.</div>
<div dir="ltr" style="font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt;">
<br>
</div>
<div id="mail-editor-reference-message-container">
<div class="ms-outlook-mobile-reference-message skipProofing">
<meta name="Generator" content="Microsoft Exchange Server">
</div>
<div class="ms-outlook-mobile-reference-message skipProofing" style="text-align: left; padding: 3pt 0in 0in; border-width: 1pt medium medium; border-style: solid none none; border-color: rgb(181, 196, 223) currentcolor currentcolor; font-family: Aptos; font-size: 12pt; color: black;">
<b>From: </b>Cantor, Scott <cantor.2@osu.edu><br>
<b>Date: </b>Wednesday, August 6, 2025 at 12:30 PM<br>
<b>To: </b>Hall, Gerry <gerry.hall@emory.edu>, Shib Users <users@shibboleth.net><br>
<b>Subject: </b>Re: [External] Re: OIDC for Mobile App<br>
<br>
</div>
<div class="PlainText" style="font-size: 11pt;">>Scott, There is no client metadata for the OIDC services.<br>
> The extent of the config is below.<br>
<br>
That is (JSON format) client metadata and I see it specifies the relevant setting.<br>
<br>
The OP I think defaults to global rules that limit what registered client authn methods for the token endpoint are allowed, so the logs should say that clearly and trip up on that. The OAUTH.Token profile config bean has settings we document for the rules it
applies.<br>
<br>
<a href="https://shibboleth.atlassian.net/wiki/spaces/IDPPLUGINS/pages/2931327005/OPToken" data-outlook-id="4cfa41f6-e65f-40ab-9aec-c4faa34b5a40">https://nam11.safelinks.protection.outlook.com/?url=https%3A%2F%2Fshibboleth.atlassian.net%2Fwiki%2Fspaces%2FIDPPLUGINS%2Fpages%2F2931327005%2FOPToken&data=05%7C02%7Cgerry.hall%40emory.edu%7Cca5c816a57dd4920d8ff08ddd5067c23%7Ce004fb9cb0a4424fbcd0322606d5df38%7C0%7C0%7C638900946027330568%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=H6og85A%2B2WMG2k2uJd2qlZuN3IsuCSfmmkq1yrXGGv4%3D&reserved=0</a><br>
<br>
tokenEndpointAuthMethods<br>
<br>
-- Scott<br>
<br>
<br>
</div>
</div>
</body>
</html>