Specification: RFC 9396
Rich Authorization Requests (RAR) allow clients to specify fine-grained authorization requirements using the authorization_details parameter, going beyond simple scopes.
Authorization Request
-
authorization_detailsparameter — JSON array of authorization details, validated at/authorize— implemented - Custom authorization types — registered per tenant with a JSON Schema that each detail object must satisfy — implemented
-
authorization_detailsthrough pushed authorization requests — carried from/parto the token — implemented -
invalid_authorization_detailserror — returned for an unknown type, a schema violation, or an unregistered location — implemented
Authorization Details Structure
Each authorization detail object contains:
type— authorization type; must resolve to a type registered for the tenantlocations— target resource servers, resolved against the resource registry exactly like the RFC 8707resourceparameteractions— permitted actions- Custom fields per authorization type
Only type and locations are interpreted by auth itself. Everything else, including actions, is validated against the type’s registered JSON Schema and then stored verbatim, because the authorization server must echo granted details back unchanged and compare them against a later request exactly as they were granted.
Token Request
-
authorization_detailson the refresh token grant — implemented -
authorization_detailson the client credentials grant — implemented - Down-scoping per §6.1 — a detail not covered by the underlying grant is rejected; member order alone does not make two otherwise identical objects differ — implemented
Token Response
-
authorization_detailsin token response — granted authorizations, unchanged from how they were granted — implemented - Access token contains granted authorization details — implemented
Server Metadata
-
authorization_details_types_supported— maintained as types are registered and removed — implemented
Use Cases
Rich Authorization Requests enable:
- Payment authorization with specific amounts and payees
- Document access with specific permissions (read/write/delete)
- Fine-grained API access beyond simple scopes
Status
- Implemented