RFC 8707 — Resource Indicators — Versola Docs
VersolaVersola/docs
versola.kzGitHub

RFC 8707 — Resource Indicators

OAuth 2.0 Resource Indicators for Authorization Request

Specification: RFC 8707

Resource Indicators allow clients to specify which resource server(s) the access token will be used with, enabling audience-restricted tokens and improved security.

Authorization Request

  • resource parameter — specify target resource server(s) — implemented
  • Multiple resource parameters — request access to multiple resources — implemented

Token Response

  • aud claim in access token — contains requested resource(s); omitted entirely when no resource was requested — implemented

Resource Credentials

Resources can be registered as internal or public:

  • Internal resources are issued a generated credential. Edge authenticates to them on the caller’s behalf with Authorization: Basic using that credential, instead of forwarding the caller’s own access token.
  • Public resources have no credential. Edge forwards the caller’s original access token as-is, so the resource server itself is responsible for validating the token’s audience.

Internal resource credentials support rotation (a previous credential remains valid until explicitly deleted), mirroring how OAuth client secrets are managed.

Benefits

Resource indicators provide:

  • Audience-restricted tokens (tokens valid only for specific resource servers)
  • Protection against token misuse across different APIs
  • Fine-grained access control per resource

Status

  • Implemented