Section 3 <>

"If signed, the Authorization Request Object SHOULD contain the Claims
"iss" (issuer) and "aud" (audience) as members, with their semantics being
the same as defined in the JWT [RFC7519
<>] specification."

however OAuth doesn't really define an identifier for an AS (like Connect
does with its Issuer). What value should a client use for 'aud' to identify
the AS?

The example later in the section has "aud": "";.
However, the example seems to have just been copied from OpenID Connect
<> and is
using the Connect concept of Issuer which isn't currently defined or
meaningful in the context of this document.
OAuth mailing list

Reply via email to