standards-maintenance icon indicating copy to clipboard operation
standards-maintenance copied to clipboard

Re-examine how Data Holder Brand JWKS endpoints are to be referenced

Open CDR-API-Stream opened this issue 2 years ago • 0 comments

Description

There are two areas in the standards where a data holder can describe their JWKS endpoints:

Security Endpoints > JSON Web Key Set End Point - Used to expose public keys to meet OIDC requirements

GetDataHolderBrands > RegisterDataHolderAuth - JWKS endpoint used for authentication by the Data Holder with the Data Recipient. Issue #441 / Register Issue 189 provided clarification on how this endpoint is used,


There is an opportunity to re-evaluate how these fields are being used in production and whether the facilty of two JWKS endpoint configurations adds value or is redundant.

CDR-API-Stream avatar Jul 12 '22 05:07 CDR-API-Stream