Client Id Metadata Document

The oauth_client_id_metadata_document feature implements the Client ID Metadata Document Standard (also known as CIMD), which provides a way by which a Client Application can identify itself to the authorization server, without prior dynamic client registration or other existing registration. This is through the usage of a URL as a client_id in an OAuth flow, where the URL refers to a document containing the necessary client metadata, enabling the authorization server to fetch the metadata about the client as needed

Who is it for

Clients with strong security standards (as CIMD foregoes prior coordination of client credentials, clients should use authentication methods that use public/private key pairs) which have resources to expose the required endpoint to retrieve the client application info by client ID.

How to enable it

plugin :rodauth do
  enable :oauth_client_id_metadata_document
end