Specification: RFC 8707
Resource Indicators allow clients to specify which resource server(s) the access token will be used with, enabling audience-restricted tokens and improved security.
Authorization Request
-
resourceparameter — specify target resource server(s) — implemented - Multiple
resourceparameters — request access to multiple resources — implemented
Token Response
-
audclaim in access token — contains requested resource(s); omitted entirely when no resource was requested — implemented
Resource Credentials
Resources can be registered as internal or public:
- Internal resources are issued a generated credential. Edge authenticates to them on the caller’s behalf with
Authorization: Basicusing that credential, instead of forwarding the caller’s own access token. - Public resources have no credential. Edge forwards the caller’s original access token as-is, so the resource server itself is responsible for validating the token’s audience.
Internal resource credentials support rotation (a previous credential remains valid until explicitly deleted), mirroring how OAuth client secrets are managed.
Benefits
Resource indicators provide:
- Audience-restricted tokens (tokens valid only for specific resource servers)
- Protection against token misuse across different APIs
- Fine-grained access control per resource
Status
- Implemented