Which specs Nauthera implements today, which only in part, and which not at all.
Implemented: the spec's flows are served end to end. Notes name notable gaps.
| Specification | Status | Notes |
|---|---|---|
| The OAuth 2.0 Authorization FrameworkRFC 6749Code, refresh, client credentials; implicit and password refused. | Implemented | Code, refresh, client credentials; implicit and password refused. |
| Proof Key for Code ExchangeRFC 7636S256 only; required by default. | Implemented | S256 only; required by default. |
JWT Profile for OAuth 2.0 Access TokensRFC 9068Signed JWTs, typ at+jwt. | Implemented | Signed JWTs, typ at+jwt. |
Token IntrospectionRFC 7662Includes the cnf confirmation claim. | Implemented | Includes the cnf confirmation claim. |
| Token RevocationRFC 7009Refresh tokens only; access tokens run to expiry. | Partial | Refresh tokens only; access tokens run to expiry. |
| Authorization Server MetadataRFC 8414Per organization, including the path-inserted form. | Implemented | Per organization, including the path-inserted form. |
| Authorization Server Issuer IdentificationRFC 9207 | Implemented | |
| Resource IndicatorsRFC 8707One resource per request; restricts the token audience. | Implemented | One resource per request; restricts the token audience. |
| Device Authorization GrantRFC 8628Code entry and approval in the hosted UI. | Implemented | Code entry and approval in the hosted UI. |
| Token ExchangeRFC 8693Not advertised. | Not supported | Not advertised. |
| Specification | Status | Notes |
|---|---|---|
| Pushed Authorization RequestsRFC 9126Can be required; always required in FAPI mode. | Implemented | Can be required; always required in FAPI mode. |
| JWT-Secured Authorization Request (JAR)RFC 9101By value only, signed ES256 or RS256. | Partial | By value only, signed ES256 or RS256. |
| Rich Authorization RequestsRFC 9396Refused until clients can register detail types. | Not supported | Refused until clients can register detail types. |
| FAPI 2.0 Security ProfileOpenID FAPI 2.0Per-org mode; secrets and unbound tokens still allowed. | Partial | Per-org mode; secrets and unbound tokens still allowed. |
| Specification | Status | Notes |
|---|---|---|
Client secrets (basic and post)RFC 6749 §2.3Public clients use none. | Implemented | Public clients use none. |
private_key_jwtRFC 7523 §2.2ES256 and RS256, via the client's jwks_uri. | Implemented | ES256 and RS256, via the client's jwks_uri. |
| client_secret_jwtOIDC Core §9 | Not supported | |
| Mutual-TLS client authentication and certificate-bound tokensRFC 8705Refused at registration. | Not supported | Refused at registration. |
| Dynamic Client RegistrationRFC 7591Requires an initial access token. | Implemented | Requires an initial access token. |
| Dynamic Client Registration ManagementRFC 7592Read and update omit the registration token. | Partial | Read and update omit the registration token. |
| JWT bearer grantRFC 7523 §2.1Not advertised. | Not supported | Not advertised. |
| Specification | Status | Notes |
|---|---|---|
| Demonstrating Proof of Possession (DPoP)RFC 9449Client-initiated; PAR's DPoP header ignored. | Partial | Client-initiated; PAR's DPoP header ignored. |
| Specification | Status | Notes |
|---|---|---|
| OpenID Connect Core 1.0OIDC CoreNo claims parameter; query response mode only. | Partial | No claims parameter; query response mode only. |
| OpenID Connect Discovery 1.0OIDC DiscoveryOne document and JWKS per organization. | Implemented | One document and JWKS per organization. |
| RP-Initiated Logout 1.0OIDC LogoutConfirmation step; expired hints refused. | Implemented | Confirmation step; expired hints refused. |
| Front-Channel Logout 1.0OIDC Logout | Implemented | |
| Back-Channel Logout 1.0OIDC LogoutDynamically registered clients only. | Implemented | Dynamically registered clients only. |
Session Management 1.0OIDC SessionOff by default; iframe needs a client_id parameter. | Partial | Off by default; iframe needs a client_id parameter. |
| Specification | Status | Notes |
|---|---|---|
| JSON Web Signature and JSON Web KeyRFC 7515, RFC 7517Signing with ES256 and RS256 only. | Implemented | Signing with ES256 and RS256 only. |
| Problem Details for HTTP APIsRFC 9457Non-OAuth JSON API errors; no internal detail. | Implemented | Non-OAuth JSON API errors; no internal detail. |
Pre-1.0. We'll email you when the operator ships.
By joining, you agree to our Privacy Policy and Terms.