RFC 9396 — Rich Authorization Requests — Versola Docs
VersolaVersola/docs
versola.kzGitHub

RFC 9396 — Rich Authorization Requests

OAuth 2.0 Rich Authorization Requests (authorization_details)

Specification: RFC 9396

Rich Authorization Requests (RAR) allow clients to specify fine-grained authorization requirements using the authorization_details parameter, going beyond simple scopes.

Authorization Request

  • authorization_details parameter — JSON array of authorization details, validated at /authorize — implemented
  • Custom authorization types — registered per tenant with a JSON Schema that each detail object must satisfy — implemented
  • authorization_details through pushed authorization requests — carried from /par to the token — implemented
  • invalid_authorization_details error — returned for an unknown type, a schema violation, or an unregistered location — implemented

Authorization Details Structure

Each authorization detail object contains:

  • type — authorization type; must resolve to a type registered for the tenant
  • locations — target resource servers, resolved against the resource registry exactly like the RFC 8707 resource parameter
  • actions — permitted actions
  • Custom fields per authorization type

Only type and locations are interpreted by auth itself. Everything else, including actions, is validated against the type’s registered JSON Schema and then stored verbatim, because the authorization server must echo granted details back unchanged and compare them against a later request exactly as they were granted.

Token Request

  • authorization_details on the refresh token grant — implemented
  • authorization_details on the client credentials grant — implemented
  • Down-scoping per §6.1 — a detail not covered by the underlying grant is rejected; member order alone does not make two otherwise identical objects differ — implemented

Token Response

  • authorization_details in token response — granted authorizations, unchanged from how they were granted — implemented
  • Access token contains granted authorization details — implemented

Server Metadata

  • authorization_details_types_supported — maintained as types are registered and removed — implemented

Use Cases

Rich Authorization Requests enable:

  • Payment authorization with specific amounts and payees
  • Document access with specific permissions (read/write/delete)
  • Fine-grained API access beyond simple scopes

Status

  • Implemented