RFC 8414 — Authorization Server Metadata — Versola Docs
VersolaVersola/docs
versola.kzGitHub

RFC 8414 — Authorization Server Metadata

OAuth 2.0 Authorization Server Metadata (Discovery)

Specification: RFC 8414

Authorization Server Metadata allows clients to discover an authorization server’s capabilities and endpoint URLs automatically, without requiring manual configuration.

Status: Implemented

  • GET /.well-known/oauth-authorization-server
  • GET /.well-known/openid-configuration (OIDC-compatible alias)

Both endpoints return the same JSON document. No authentication required.

Response Example

{
  "issuer": "https://id.example.com",
  "authorization_endpoint": "https://id.example.com/authorize",
  "token_endpoint": "https://id.example.com/token",
  "userinfo_endpoint": "https://id.example.com/userinfo",
  "jwks_uri": "https://id.example.com/.well-known/jwks.json",
  "introspection_endpoint": "https://id.example.com/introspect",
  "revocation_endpoint": "https://id.example.com/revoke",
  "pushed_authorization_request_endpoint": "https://id.example.com/par",
  "scopes_supported": ["openid", "profile", "email", "phone", "offline_access"],
  "response_types_supported": ["code", "code id_token"],
  "grant_types_supported": ["authorization_code", "client_credentials", "refresh_token"],
  "subject_types_supported": ["public", "pairwise"],
  "id_token_signing_alg_values_supported": ["RS256"],
  "token_endpoint_auth_methods_supported": ["client_secret_basic", "client_secret_post"],
  "claims_supported": ["sub", "iss", "aud", "exp", "iat", "jti", "nonce", "auth_time", "acr", "amr"]
}

Implemented Metadata Fields

Required:

  • issuer — authorization server identifier
  • authorization_endpoint — URL of the authorization endpoint
  • token_endpoint — URL of the token endpoint

Recommended:

  • jwks_uri — URL of the JWKS endpoint
  • response_types_supported — list of supported response_type values
  • grant_types_supported — list of supported grant types
  • token_endpoint_auth_methods_supported
  • revocation_endpoint — URL of the revocation endpoint
  • introspection_endpoint — URL of the introspection endpoint
  • scopes_supported — list of supported scope values
  • code_challenge_methods_supported — ["S256", "plain"]
  • pushed_authorization_request_endpoint — URL of the pushed authorization request endpoint (RFC 9126)

OIDC Extensions (OpenID Connect Discovery):

  • userinfo_endpoint
  • id_token_signing_alg_values_supported
  • claims_supported
  • subject_types_supported