Specification: RFC 8414
Authorization Server Metadata allows clients to discover an authorization server’s capabilities and endpoint URLs automatically, without requiring manual configuration.
Status: Implemented
-
GET /.well-known/oauth-authorization-server -
GET /.well-known/openid-configuration(OIDC-compatible alias)
Both endpoints return the same JSON document. No authentication required.
Response Example
{
"issuer": "https://id.example.com",
"authorization_endpoint": "https://id.example.com/authorize",
"token_endpoint": "https://id.example.com/token",
"userinfo_endpoint": "https://id.example.com/userinfo",
"jwks_uri": "https://id.example.com/.well-known/jwks.json",
"introspection_endpoint": "https://id.example.com/introspect",
"revocation_endpoint": "https://id.example.com/revoke",
"pushed_authorization_request_endpoint": "https://id.example.com/par",
"scopes_supported": ["openid", "profile", "email", "phone", "offline_access"],
"response_types_supported": ["code", "code id_token"],
"grant_types_supported": ["authorization_code", "client_credentials", "refresh_token"],
"subject_types_supported": ["public", "pairwise"],
"id_token_signing_alg_values_supported": ["RS256"],
"token_endpoint_auth_methods_supported": ["client_secret_basic", "client_secret_post"],
"claims_supported": ["sub", "iss", "aud", "exp", "iat", "jti", "nonce", "auth_time", "acr", "amr"]
}
Implemented Metadata Fields
Required:
-
issuer— authorization server identifier -
authorization_endpoint— URL of the authorization endpoint -
token_endpoint— URL of the token endpoint
Recommended:
-
jwks_uri— URL of the JWKS endpoint -
response_types_supported— list of supportedresponse_typevalues -
grant_types_supported— list of supported grant types -
token_endpoint_auth_methods_supported -
revocation_endpoint— URL of the revocation endpoint -
introspection_endpoint— URL of the introspection endpoint -
scopes_supported— list of supported scope values -
code_challenge_methods_supported—["S256", "plain"] -
pushed_authorization_request_endpoint— URL of the pushed authorization request endpoint (RFC 9126)
OIDC Extensions (OpenID Connect Discovery):
-
userinfo_endpoint -
id_token_signing_alg_values_supported -
claims_supported -
subject_types_supported