> ## Documentation Index
> Fetch the complete documentation index at: https://developers.authlete.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Process Federation Registration Request

> The Authlete API is for implementations of the **federation registration
endpoint** that accepts "explicit client registration". Its details are
defined in [OpenID Connect Federation 1.0](https://openid.net/specs/openid-connect-federation-1_0.html).
The endpoint accepts `POST` requests whose `Content-Type`
is either of the following.
1. `application/entity-statement+jwt`- `application/trust-chain+json`
When the `Content-Type` of a request is
`application/entity-statement+jwt`, the content of the request is
the entity configuration of a relying party that is to be registered.
In this case, the implementation of the federation registration endpoint
should call Authlete's `/federation/registration` API with the
entity configuration set to the `entityConfiguration` request
parameter.
On the other hand, when the `Content-Type` of a request is
`application/trust-chain+json`, the content of the request is a
JSON array that contains entity statements in JWT format. The sequence
of the entity statements composes the trust chain of a relying party
that is to be registered. In this case, the implementation of the
federation registration endpoint should call Authlete's
`/federation/registration` API with the trust chain set to the
`trustChain` request parameter.




## OpenAPI

````yaml https://spec.speakeasy.com/authlete/sdk-workspace/authlete-api-explorer-with-code-samples post /api/{serviceId}/federation/registration
openapi: 3.0.3
info:
  title: Authlete API
  description: ''
  version: 3.0.16
  license:
    name: Apache 2.0
    url: https://www.apache.org/licenses/LICENSE-2.0.html
servers:
  - description: 🇺🇸 US Cluster
    url: https://us.authlete.com
  - description: 🇯🇵 Japan Cluster
    url: https://jp.authlete.com
  - description: 🇪🇺 Europe Cluster
    url: https://eu.authlete.com
  - description: 🇧🇷 Brazil Cluster
    url: https://br.authlete.com
security:
  - bearer: []
tags:
  - name: Service Management
    description: >-
      API endpoints for managing services, including creation, update, and
      deletion of services.
    x-tag-expanded: false
  - name: Client Management
    description: >-
      API endpoints for managing OAuth clients, including creation, update, and
      deletion of clients.
    x-tag-expanded: false
  - name: Authorization Endpoint
    description: API endpoints for implementing OAuth 2.0 Authorization Endpoint.
    x-tag-expanded: false
  - name: Pushed Authorization Endpoint
    description: >-
      API endpoints for implementing OAuth 2.0 Pushed Authorization Requests
      (PAR).
    x-tag-expanded: false
  - name: Token Endpoint
    description: API endpoints for implementing OAuth 2.0 Token Endpoint.
    x-tag-expanded: false
  - name: Token Operations
    description: >-
      API endpoints for various token related operations, including creating,
      revoking and deleting access_tokens with specified scopes.
    x-tag-expanded: false
  - name: Introspection Endpoint
    description: API endpoints for implementing OAuth 2.0 Introspection Endpoint.
    x-tag-expanded: false
  - name: Revocation Endpoint
    description: API endpoint for implementing OAuth 2.0 Revocation Endpoint.
    x-tag-expanded: false
  - name: UserInfo Endpoint
    description: API endpoints for implementing OpenID Connect UserInfo Endpoint.
    x-tag-expanded: false
  - name: JWK Set Endpoint
    description: API endpoints for to generate JSON Web Key Set (JWKS) for a service.
    x-tag-expanded: false
  - name: Discovery Endpoint
    description: API endpoints for implementing OpenID Connect Discovery.
    x-tag-expanded: false
  - name: Configuration Endpoint
    description: API endpoint for accessing configuration settings for a service.
    x-tag-expanded: false
  - name: Dynamic Client Registration
    description: API endpoints for implementing OAuth 2.0 Dynamic Client Registration.
    x-tag-expanded: false
  - name: CIBA
    description: >-
      API endpoints for implementing Client-Initiated Backchannel Authentication
      (CIBA).
    x-tag-expanded: false
  - name: Grant Management Endpoint
    description: >-
      API endpoint for implementing OAuth 2.0 grants, including grant management
      actions like updating and revoking grants.
    x-tag-expanded: false
  - name: Jose Object
    description: API endpoints for JOSE objects.
    x-tag-expanded: false
  - name: Device Flow
    description: API endpoints for implementing OAuth 2.0 Device Flow
    x-tag-expanded: false
  - name: Federation Endpoint
    description: API endpoints for implementing OpenID Federation using Authlete.
    x-tag-expanded: false
  - name: Verifiable Credential Issuer
    description: >-
      API endpoints for implementing and running a Verifiable Credential Issuer
      (VCI).
    x-tag-expanded: false
  - name: Hardware Security Key
    description: API endpoints for managing hardware security keys (HSK).
    x-tag-expanded: false
  - name: Utility Endpoints
    description: API endpoints for various utility operations.
    x-tag-expanded: false
  - name: Native SSO
    description: API endpoints for Native SSO
    x-tag-expanded: false
paths:
  /api/{serviceId}/federation/registration:
    post:
      tags:
        - Federation Endpoint
      summary: Process Federation Registration Request
      description: >
        The Authlete API is for implementations of the **federation registration

        endpoint** that accepts "explicit client registration". Its details are

        defined in [OpenID Connect Federation
        1.0](https://openid.net/specs/openid-connect-federation-1_0.html).

        The endpoint accepts `POST` requests whose `Content-Type`

        is either of the following.

        1. `application/entity-statement+jwt`- `application/trust-chain+json`

        When the `Content-Type` of a request is

        `application/entity-statement+jwt`, the content of the request is

        the entity configuration of a relying party that is to be registered.

        In this case, the implementation of the federation registration endpoint

        should call Authlete's `/federation/registration` API with the

        entity configuration set to the `entityConfiguration` request

        parameter.

        On the other hand, when the `Content-Type` of a request is

        `application/trust-chain+json`, the content of the request is a

        JSON array that contains entity statements in JWT format. The sequence

        of the entity statements composes the trust chain of a relying party

        that is to be registered. In this case, the implementation of the

        federation registration endpoint should call Authlete's

        `/federation/registration` API with the trust chain set to the

        `trustChain` request parameter.
      operationId: federation_registration_api
      parameters:
        - in: path
          name: serviceId
          description: A service ID.
          schema:
            type: string
          required: true
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/federation_registration_request'
          application/x-www-form-urlencoded:
            schema:
              $ref: '#/components/schemas/federation_registration_request'
      responses:
        '200':
          description: ''
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/federation_registration_response'
        '400':
          $ref: '#/components/responses/400'
        '401':
          $ref: '#/components/responses/401'
        '403':
          $ref: '#/components/responses/403'
        '500':
          $ref: '#/components/responses/500'
      x-codeSamples:
        - lang: typescript
          label: Typescript (SDK)
          source: |-
            import { Authlete } from "@authlete/typescript-sdk";

            const authlete = new Authlete({
              bearer: process.env["AUTHLETE_BEARER"] ?? "",
            });

            async function run() {
              const result = await authlete.federation.registration({
                serviceId: "<id>",
                federationRegistrationRequest: {},
              });

              console.log(result);
            }

            run();
        - lang: ruby
          label: Ruby (SDK)
          source: >-
            require 'authlete_ruby_sdk'


            Models = ::Authlete::Models

            s = ::Authlete::Client.new(
              bearer: '<YOUR_BEARER_TOKEN_HERE>'
            )

            res = s.federation.registration(service_id: '<id>',
            federation_registration_request:
            Models::Components::FederationRegistrationRequest.new)


            unless res.federation_registration_response.nil?
              # handle response
            end
        - lang: go
          label: Go (SDK)
          source: "package main\n\nimport(\n\t\"context\"\n\t\"os\"\n\tauthlete \"github.com/authlete/authlete-go-sdk\"\n\t\"github.com/authlete/authlete-go-sdk/models/components\"\n\t\"log\"\n)\n\nfunc main() {\n    ctx := context.Background()\n\n    s := authlete.New(\n        authlete.WithSecurity(os.Getenv(\"AUTHLETE_BEARER\")),\n    )\n\n    res, err := s.Federation.Registration(ctx, \"<id>\", components.FederationRegistrationRequest{})\n    if err != nil {\n        log.Fatal(err)\n    }\n    if res.FederationRegistrationResponse != nil {\n        // handle response\n    }\n}"
components:
  schemas:
    federation_registration_request:
      type: object
      properties:
        entityConfiguration:
          type: string
          description: |
            The entity configuration of a relying party.
        trustChain:
          type: string
          description: |
            The trust chain of a relying party.
    federation_registration_response:
      type: object
      properties:
        resultCode:
          type: string
          description: The code which represents the result of the API call.
        resultMessage:
          type: string
          description: A short message which explains the result of the API call.
        action:
          type: string
          enum:
            - OK
            - BAD_REQUEST
            - NOT_FOUND
            - INTERNAL_SERVER_ERROR
          description: >-
            The next action that the authorization server implementation should
            take.
        responseContent:
          type: string
          description: >
            The content that the authorization server implementation can use as
            the value of `WWW-Authenticate`

            header on errors.
        client:
          $ref: '#/components/schemas/client'
    client:
      type: object
      additionalProperties: true
      example:
        number: 1140735077
        serviceNumber: 715948317
        clientName: My Test Client
        clientId: '1140735077'
        clientSecret: >-
          gXz97ISgLs4HuXwOZWch8GEmgL4YMvUJwu3er_kDVVGcA0UOhA9avLPbEmoeZdagi9yC_-tEiT2BdRyH9dbrQQ
        clientType: PUBLIC
        redirectUris:
          - https://example.com/callback
        responseTypes:
          - CODE
        grantTypes:
          - AUTHORIZATION_CODE
      properties:
        number:
          type: integer
          format: int32
          readOnly: true
          description: >
            The sequential number of the client. The value of this property is
            assigned by Authlete.
        serviceNumber:
          type: integer
          format: int32
          readOnly: true
          description: >
            The sequential number of the service of the client application. The
            value of this property is

            assigned by Authlete.
        clientName:
          type: string
          description: >
            The name of the client application. This property corresponds to
            `client_name` in

            [OpenID Connect Dynamic Client Registration 1.0, 2. Client
            Metadata](https://openid.net/specs/openid-connect-registration-1_0.html#ClientMetadata).
        clientNames:
          type: array
          items:
            $ref: '#/components/schemas/tagged_value'
          description: >
            Client names with language tags. If the client application has
            different names for different

            languages, this property can be used to register the names.
        description:
          type: string
          description: The description about the client application.
        descriptions:
          type: array
          items:
            $ref: '#/components/schemas/tagged_value'
          description: >
            Descriptions about the client application with language tags. If the
            client application has different

            descriptions for different languages, this property can be used to
            register the descriptions.
        clientId:
          type: integer
          format: int64
          readOnly: true
          description: >-
            The client identifier used in Authlete API calls. The value of this
            property is assigned by Authlete.
        clientSecret:
          type: string
          readOnly: true
          description: >
            The client secret. A random 512-bit value encoded by base64url (86
            letters). The value of this

            property is assigned by Authlete.
          x-mint:
            metadata:
              description: >-
                The client secret. A random 512-bit value encoded by base64url
                (86 letters). The value of this property is assigned by
                Authlete.
            content: >
              <Accordion title="Full description" defaultOpen={false}>

              Note that Authlete issues a client secret even to a "public"
              client application, but the client

              application should not use the client secret unless it changes its
              client type to "confidential".

              That is, a public client application should behave as if it had
              not been issued a client secret.

              To be specific, a token request from a public client of Authlete
              should not come along with a

              client secret although [RFC 6749, 3.2.1. Client
              Authentication](https://datatracker.ietf.org/doc/html/rfc6749#section-3.2.1)

              says as follows.


              > Confidential clients or other clients issued client credentials
              MUST authenticate with the

              authorization server as described in Section 2.3 when making
              requests to the token endpoint.

              </Accordion>
        clientIdAlias:
          type: string
          description: >
            The value of the client's `client_id` property used in OAuth and
            OpenID Connect calls. By

            default, this is a string version of the `clientId` property.
        clientIdAliasEnabled:
          type: boolean
          description: Deprecated. Always set to `true`.
        clientType:
          $ref: '#/components/schemas/client_type'
        applicationType:
          $ref: '#/components/schemas/application_type'
        logoUri:
          type: string
          description: >
            The URL pointing to the logo image of the client application.


            This property corresponds to `logo_uri` in [OpenID Connect Dynamic
            Client Registration 1.0, 2.

            Client
            Metadata](https://openid.net/specs/openid-connect-registration-1_0.html#ClientMetadata).
        logoUris:
          type: array
          items:
            $ref: '#/components/schemas/tagged_value'
          description: >
            Logo image URLs with language tags. If the client application has
            different logo images for

            different languages, this property can be used to register URLs of
            the images.
        contacts:
          type: array
          items:
            type: string
          description: >
            An array of email addresses of people responsible for the client
            application.


            This property corresponds to contacts in [OpenID Connect Dynamic
            Client Registration 1.0, 2. Client

            Metadata](https://openid.net/specs/openid-connect-registration-1_0.html#ClientMetadata).
        tlsClientCertificateBoundAccessTokens:
          type: boolean
          description: >
            The flag to indicate whether this client use TLS client certificate
            bound access tokens.
        dynamicallyRegistered:
          type: boolean
          readOnly: true
          description: >
            The flag to indicate whether this client has been registered
            dynamically.

            For more details, see [RFC
            7591](https://datatracker.ietf.org/doc/html/rfc7591).
        softwareId:
          type: string
          description: >
            The unique identifier string assigned by the client developer or
            software publisher used by

            registration endpoints to identify the client software to be
            dynamically registered.


            This property corresponds to the `software_id metadata` defined in
            [2. Client
            Metadata](https://datatracker.ietf.org/doc/html/rfc7591#section-2)

            of [RFC 7591](https://datatracker.ietf.org/doc/html/rfc7591).
        developer:
          type: string
          description: >
            The unique identifier of the developer who created this client
            application.
        softwareVersion:
          type: string
          description: >
            The version identifier string for the client software identified by
            the software ID.


            This property corresponds to the software_version metadata defined
            in [2. Client
            Metadata](https://datatracker.ietf.org/doc/html/rfc7591#section-2)

            of [RFC 7591](https://datatracker.ietf.org/doc/html/rfc7591).
        registrationAccessTokenHash:
          type: string
          description: |
            The hash of the registration access token for this client.
        createdAt:
          type: integer
          format: int64
          readOnly: true
          description: >-
            The time at which this client was created. The value is represented
            as milliseconds since the UNIX epoch (1970-01-01).
        modifiedAt:
          type: integer
          format: int64
          readOnly: true
          description: >-
            The time at which this client was last modified. The value is
            represented as milliseconds since the UNIX epoch (1970-01-01).
        grantTypes:
          type: array
          items:
            $ref: '#/components/schemas/grant_type'
          description: >
            A string array of grant types which the client application declares
            that it will restrict itself to using.

            This property corresponds to `grant_types` in [OpenID Connect
            Dynamic Client Registration 1.0,

            2. Client
            Metadata](https://openid.net/specs/openid-connect-registration-1_0.html#ClientMetadata).
        responseTypes:
          type: array
          items:
            $ref: '#/components/schemas/response_type'
          description: >
            A string array of response types which the client application
            declares that it will restrict itself to using.

            This property corresponds to `response_types` in [OpenID Connect
            Dynamic Client Registration 1.0,

            2. Client
            Metadata](https://openid.net/specs/openid-connect-registration-1_0.html#ClientMetadata).
        redirectUris:
          type: array
          items:
            type: string
          description: >
            Redirect URIs that the client application uses to receive a response
            from the authorization endpoint.

            Requirements for a redirect URI are as follows.
          x-mint:
            metadata:
              description: >-
                Redirect URIs that the client application uses to receive a
                response from the authorization endpoint. Requirements for a
                redirect URI are as follows.
            content: >
              <Accordion title="Full description" defaultOpen={false}>

              **Requirements by RFC 6749** (From [RFC 6749, 3.1.2. Redirection
              Endpoint](https://datatracker.ietf.org/doc/html/rfc6749#section-3.1.2))


              - Must be an absolute URI.

              - Must not have a fragment component.


              **Requirements by OpenID Connect** (From "[OpenID Connect Dynamic
              Client Registration 1.0, 2.

              Client
              Metadata](https://openid.net/specs/openid-connect-registration-1_0.html#ClientMetadata),

              application_type")


              - The scheme of the redirect URI used for Implicit Grant by a
              client application whose application

              is `web` must be `https`. This is checked at runtime by Authlete.

              - The hostname of the redirect URI used for Implicit Grant by a
              client application whose application

              type is `web` must not be `localhost`. This is checked at runtime
              by Authlete.

              - The scheme of the redirect URI used by a client application
              whose application type is `native`

              must be either (1) a custom scheme or (2) `http`, which is allowed
              only when the hostname part

              is `localhost`. This is checked at runtime by Authlete.


              ## Requirements by Authlete


              - Must consist of printable ASCII letters only.

              - Must not exceed 200 letters.


              Note that Authlete allows the application type to be `null`. In
              other words, a client application

              does not have to choose `web` or `native` as its application type.

              If the application type is `null`, the requirements by OpenID
              Connect are not checked at runtime.


              An authorization request from a client application which has not
              registered any redirect URI

              fails unless at least all the following conditions are satisfied.


              - The client type of the client application is `confidential`.

              - The value of `response_type` request parameter is `code`.

              - The authorization request has the `redirect_uri` request
              parameter.

              - The value of `scope` request parameter does not contain
              `openid`.


              RFC 6749 allows partial match of redirect URI under some
              conditions (see [RFC 6749, 3.1.2.2.

              Registration
              Requirements](https://datatracker.ietf.org/doc/html/rfc6749#section-3.1.2.2)
              for

              details), but OpenID Connect requires exact match.

              </Accordion>
        authorizationSignAlg:
          $ref: '#/components/schemas/jws_alg'
        authorizationEncryptionAlg:
          $ref: '#/components/schemas/jwe_alg'
        authorizationEncryptionEnc:
          $ref: '#/components/schemas/jwe_enc'
        tokenAuthMethod:
          $ref: '#/components/schemas/client_auth_method'
        tokenAuthSignAlg:
          $ref: '#/components/schemas/jws_alg'
        selfSignedCertificateKeyId:
          type: string
          description: >
            The key ID of a JWK containing a self-signed certificate of this
            client.
        tlsClientAuthSubjectDn:
          type: string
          description: >
            The string representation of the expected subject distinguished name
            of the certificate this

            client will use in mutual TLS authentication.


            See `tls_client_auth_subject_dn` in "Mutual TLS Profiles for OAuth
            Clients, 2.3. Dynamic Client

            Registration" for details.
        tlsClientAuthSanDns:
          type: string
          description: >
            The string representation of the expected DNS subject alternative
            name of the certificate this

            client will use in mutual TLS authentication.


            See `tls_client_auth_san_dns` in "Mutual TLS Profiles for OAuth
            Clients, 2.3. Dynamic Client

            Registration" for details.
        tlsClientAuthSanUri:
          type: string
          description: >
            The string representation of the expected URI subject alternative
            name of the certificate this

            client will use in mutual TLS authentication.


            See `tls_client_auth_san_uri` in "Mutual TLS Profiles for OAuth
            Clients, 2.3. Dynamic Client

            Registration" for details.
        tlsClientAuthSanIp:
          type: string
          description: >
            The string representation of the expected IP address subject
            alternative name of the certificate

            this client will use in mutual TLS authentication.


            See `tls_client_auth_san_ip` in "Mutual TLS Profiles for OAuth
            Clients, 2.3. Dynamic Client

            Registration" for details.
        tlsClientAuthSanEmail:
          type: string
          description: >
            The string representation of the expected email address subject
            alternative name of the certificate

            this client will use in mutual TLS authentication.


            See `tls_client_auth_san_email` in "Mutual TLS Profiles for OAuth
            Clients, 2.3. Dynamic Client

            Registration" for details.
        parRequired:
          type: boolean
          description: >
            The flag to indicate whether this client is required to use the
            pushed authorization request endpoint.

            This property corresponds to the
            `require_pushed_authorization_requests` client metadata defined

            in "OAuth 2.0 Pushed Authorization Requests".
        requestObjectRequired:
          type: boolean
          description: >
            The flag to indicate whether authorization requests from this client
            are always required to

            utilize a request object by using either `request` or `request_uri`
            request parameter.


            If this flag is set to `true` and the service's
            `traditionalRequestObjectProcessingApplied` is

            set to `false`, authorization requests from this client are
            processed as if `require_signed_request_object`

            client metadata of this client is `true`. The metadata is defined in
            "JAR (JWT Secured Authorization Request)".
        requestSignAlg:
          $ref: '#/components/schemas/jws_alg'
        requestEncryptionAlg:
          $ref: '#/components/schemas/jwe_alg'
        requestEncryptionEnc:
          $ref: '#/components/schemas/jwe_enc'
        requestUris:
          type: array
          items:
            type: string
          description: >
            An array of URLs each of which points to a request object.


            Authlete requires that URLs used as values for `request_uri` request
            parameter be pre-registered.

            This property is used for the pre-registration.

            See [OpenID Connect Core 1.0, 6.2. Passing a Request Object by
            Reference](https://openid.net/specs/openid-connect-core-1_0.html#RequestUriParameter)
            for details.
        defaultMaxAge:
          type: integer
          format: int32
          description: >
            The default maximum authentication age in seconds. This value is
            used when an authorization request from the client application does
            not have `max_age` request parameter.


            This property corresponds to `default_max_age` in

            [OpenID Connect Dynamic Client Registration 1.0, 2. Client
            Metadata](https://openid.net/specs/openid-connect-registration-1_0.html#ClientMetadata).
        defaultAcrs:
          type: array
          items:
            type: string
          description: >
            The default ACRs (Authentication Context Class References). This
            value is used when an authorization

            request from the client application has neither `acr_values` request
            parameter nor `acr` claim

            in claims request parameter.
        idTokenSignAlg:
          $ref: '#/components/schemas/jws_alg'
        idTokenEncryptionAlg:
          $ref: '#/components/schemas/jwe_alg'
        idTokenEncryptionEnc:
          $ref: '#/components/schemas/jwe_enc'
        authTimeRequired:
          type: boolean
          description: >
            The flag to indicate whether this client requires `auth_time` claim
            to be embedded in the ID token.


            This property corresponds to `require_auth_time` in

            [OpenID Connect Dynamic Client Registration 1.0, 2. Client
            Metadata](https://openid.net/specs/openid-connect-registration-1_0.html#ClientMetadata).
        subjectType:
          $ref: '#/components/schemas/subject_type'
        sectorIdentifierUri:
          type: string
          description: >
            The value of the sector identifier URI.

            This represents the `sector_identifier_uri` client metadata which is
            defined in

            [OpenID Connect Dynamic Client Registration 1.0, 2. Client
            Metadata](https://openid.net/specs/openid-connect-registration-1_0.html#ClientMetadata)
        derivedSectorIdentifier:
          type: string
          readOnly: true
          description: >
            The sector identifier host component as derived from either the
            `sector_identifier_uri` or the

            registered redirect URI. If no `sector_identifier_uri` is registered
            and multiple redirect URIs

            are also registered, the value of this property is `null`.
        jwksUri:
          type: string
          description: >
            The URL pointing to the JWK Set of the client application.

            The content pointed to by the URL is JSON which complies with the
            format described in

            [JSON Web Key (JWK), 5. JWK Set
            Format](https://datatracker.ietf.org/doc/html/rfc7517#section-5).

            The JWK Set must not include private keys of the client application.
          x-mint:
            metadata:
              description: >-
                The URL pointing to the JWK Set of the client application. The
                content pointed to by the URL is JSON which complies with the
                format described in [JSON Web Key (JWK), 5. JWK Set
                Format](https://datatracker.ietf.org/doc/html/rfc7517#section-5).
                The JWK Set must not include private keys of the client
                application.
            content: >
              <Accordion title="Full description" defaultOpen={false}>

              If the client application requests encryption for ID tokens (from
              the authorization/token/userinfo endpoints)

              and/or signs request objects, it must make available its JWK Set
              containing public keys for the

              encryption and/or the signature at the URL of `jwksUri`. The
              service (Authlete) fetches the JWK

              Set from the URL as necessary.


              [OpenID Connect Dynamic Client Registration
              1.0](https://openid.net/specs/openid-connect-registration-1_0.html)

              says that `jwks` must not be used when the client can use
              `jwks_uri`, but Authlete allows both

              properties to be registered at the same time. However, Authlete
              does not use the content of `jwks`

              when `jwksUri` is registered.


              This property corresponds to `jwks_uri` in [OpenID Connect Dynamic
              Client Registration 1.0, 2.

              Client
              Metadata](https://openid.net/specs/openid-connect-registration-1_0.html#ClientMetadata).

              </Accordion>
        jwks:
          type: string
          description: >
            The content of the JWK Set of the client application.

            The format is described in

            [JSON Web Key (JWK), 5. JWK Set
            Format](https://datatracker.ietf.org/doc/html/rfc7517#section-5).

            The JWK Set must not include private keys of the client application.
          x-mint:
            metadata:
              description: >-
                The content of the JWK Set of the client application. The format
                is described in [JSON Web Key (JWK), 5. JWK Set
                Format](https://datatracker.ietf.org/doc/html/rfc7517#section-5).
                The JWK Set must not include private keys of the client
                application.
            content: >
              <Accordion title="Full description" defaultOpen={false}>

              [OpenID Connect Dynamic Client Registration
              1.0](https://openid.net/specs/openid-connect-registration-1_0.html)

              says that `jwks` must not be used when the client can use
              `jwks_uri`, but Authlete allows both

              properties to be registered at the same time. However, Authlete
              does not use the content of `jwks`

              when `jwksUri` is registered.


              This property corresponds to `jwks_uri` in [OpenID Connect Dynamic
              Client Registration 1.0, 2.

              Client
              Metadata](https://openid.net/specs/openid-connect-registration-1_0.html#ClientMetadata).

              </Accordion>
        userInfoSignAlg:
          $ref: '#/components/schemas/jws_alg'
          nullable: true
        userInfoEncryptionAlg:
          $ref: '#/components/schemas/jwe_alg'
          nullable: true
        userInfoEncryptionEnc:
          $ref: '#/components/schemas/jwe_enc'
          nullable: true
        loginUri:
          type: string
          description: >
            The URL which a third party can use to initiate a login by the
            client application.


            This property corresponds to `initiate_login_uri` in

            [OpenID Connect Dynamic Client Registration 1.0, 2. Client
            Metadata](https://openid.net/specs/openid-connect-registration-1_0.html#ClientMetadata).
        tosUri:
          type: string
          description: >
            The URL pointing to the "Terms Of Service" page.


            This property corresponds to `tos_uri` in

            [OpenID Connect Dynamic Client Registration 1.0, 2. Client
            Metadata](https://openid.net/specs/openid-connect-registration-1_0.html#ClientMetadata).
        tosUris:
          type: array
          items:
            $ref: '#/components/schemas/tagged_value'
          description: >
            URLs of "Terms Of Service" pages with language tags.


            If the client application has different "Terms Of Service" pages for
            different languages,

            this property can be used to register the URLs.
        policyUri:
          type: string
          description: >
            The URL pointing to the page which describes the policy as to how
            end-user's profile data is used.


            This property corresponds to `policy_uri` in

            [OpenID Connect Dynamic Client Registration 1.0, 2. Client
            Metadata](https://openid.net/specs/openid-connect-registration-1_0.html#ClientMetadata).
        policyUris:
          type: array
          items:
            $ref: '#/components/schemas/tagged_value'
          description: >
            URLs of policy pages with language tags.

            If the client application has different policy pages for different
            languages, this property can be used to register the URLs.
        clientUri:
          type: string
          description: >
            The URL pointing to the home page of the client application.


            This property corresponds to `client_uri` in

            [OpenID Connect Dynamic Client Registration 1.0, 2. Client
            Metadata](https://openid.net/specs/openid-connect-registration-1_0.html#ClientMetadata).
        clientUris:
          type: array
          items:
            $ref: '#/components/schemas/tagged_value'
          description: >
            Home page URLs with language tags.

            If the client application has different home pages for different
            languages, this property can

            be used to register the URLs.
        bcDeliveryMode:
          type: string
          description: >
            The backchannel token delivery mode.


            This property corresponds to the `backchannel_token_delivery_mode`
            metadata.

            The backchannel token delivery mode is defined in the specification
            of "CIBA (Client Initiated

            Backchannel Authentication)".
        bcNotificationEndpoint:
          type: string
          description: >
            The backchannel client notification endpoint.


            This property corresponds to the
            `backchannel_client_notification_endpoint` metadata.

            The backchannel token delivery mode is defined in the specification
            of "CIBA (Client Initiated

            Backchannel Authentication)".
        bcRequestSignAlg:
          $ref: '#/components/schemas/jws_alg'
        bcUserCodeRequired:
          type: boolean
          description: >
            The boolean flag to indicate whether a user code is required when
            this client makes a backchannel

            authentication request.


            This property corresponds to the `backchannel_user_code_parameter`
            metadata.
        attributes:
          type: array
          items:
            $ref: '#/components/schemas/pair'
          description: |
            The attributes of this client.
        extension:
          $ref: '#/components/schemas/client_extension'
        authorizationDetailsTypes:
          type: array
          items:
            type: string
          description: >
            The authorization details types that this client may use as values
            of the `type` field in

            `authorization_details`.


            This property corresponds to the `authorization_details_types`
            metadata. See [OAuth 2.0 Rich

            Authorization Requests
            (RAR)](https://datatracker.ietf.org/doc/draft-ietf-oauth-rar/) for
            details.


            Note that the property name was renamed from authorizationDataTypes
            to authorizationDetailsTypes

            to align with the change made by the 5th draft of the RAR
            specification.
        customMetadata:
          type: string
          description: |
            The custom client metadata in JSON format.
          x-mint:
            metadata:
              description: The custom client metadata in JSON format.
            content: >
              <Accordion title="Full description" defaultOpen={false}>

              Standard specifications define client metadata as necessary. The
              following are such examples.


              * [OpenID Connect Dynamic Client Registration
              1.0](https://openid.net/specs/openid-connect-registration-1_0.html)

              * [RFC 7591 OAuth 2.0 Dynamic Client Registration
              Protocol](https://www.rfc-editor.org/rfc/rfc7591.html)

              * [RFC 8705 OAuth 2.0 Mutual-TLS Client Authentication and
              Certificate-Bound Access
              Tokens](https://www.rfc-editor.org/rfc/rfc8705.html)

              * [OpenID Connect Client-Initiated Backchannel Authentication Flow
              - Core
              1.0](https://openid.net/specs/openid-client-initiated-backchannel-authentication-core-1_0.html)

              * [The OAuth 2.0 Authorization Framework: JWT Secured
              Authorization Request
              (JAR)](https://datatracker.ietf.org/doc/draft-ietf-oauth-jwsreq/)

              * [Financial-grade API: JWT Secured Authorization Response Mode
              for OAuth 2.0
              (JARM)](https://openid.net/specs/openid-financial-api-jarm.html)

              * [OAuth 2.0 Pushed Authorization Requests
              (PAR)](https://datatracker.ietf.org/doc/rfc9126/)

              * [OAuth 2.0 Rich Authorization Requests
              (RAR)](https://datatracker.ietf.org/doc/draft-ietf-oauth-rar/)


              Standard client metadata included in Client Registration Request
              and Client Update Request (cf.

              [OIDC
              DynReg](https://openid.net/specs/openid-connect-registration-1_0.html),
              [RFC 7591](https://www.rfc-editor.org/rfc/rfc7591.html)

              and [RFC 7592](https://www.rfc-editor.org/rfc/rfc7592.html)) are,
              if supported by Authlete, set

              to corresponding properties of the client application. For
              example, the value of the `client_name`

              client metadata in Client Registration/Update Request is set to
              the clientName property. On the

              other hand, unrecognized client metadata are discarded.


              By listing up custom client metadata in advance by using the
              `supportedCustomClientMetadata` property

              of Service, Authlete can recognize them and stores their values
              into the database. The stored

              custom client metadata values can be referenced by this property.

              </Accordion>
        frontChannelRequestObjectEncryptionRequired:
          type: boolean
          description: >
            The flag indicating whether encryption of request object is required
            when the request object

            is passed through the front channel.
          x-mint:
            metadata:
              description: >-
                The flag indicating whether encryption of request object is
                required when the request object is passed through the front
                channel.
            content: >
              <Accordion title="Full description" defaultOpen={false}>

              This flag does not affect the processing of request objects at the
              Pushed Authorization Request

              Endpoint, which is defined in [OAuth 2.0 Pushed Authorization
              Requests](https://datatracker.ietf.org/doc/rfc9126/).

              Unecrypted request objects are accepted at the endpoint even if
              this flag is `true`.


              This flag does not indicate whether a request object is always
              required. There is a different

              flag, `requestObjectRequired`, for the purpose.


              Even if this flag is `false`, encryption of request object is
              required if the `frontChannelRequestObjectEncryptionRequired`

              flag of the service is `true`.

              </Accordion>
        requestObjectEncryptionAlgMatchRequired:
          type: boolean
          description: >
            The flag indicating whether the JWE alg of encrypted request object
            must match the `request_object_encryption_alg`

            client metadata.
          x-mint:
            metadata:
              description: >-
                The flag indicating whether the JWE alg of encrypted request
                object must match the `request_object_encryption_alg` client
                metadata.
            content: >
              <Accordion title="Full description" defaultOpen={false}>

              The `request_object_encryption_alg` client metadata itself is
              defined in [OpenID Connect Dynamic

              Client Registration
              1.0](https://openid.net/specs/openid-connect-registration-1_0.html)
              as follows.


              > request_object_encryption_alg

              >

              > OPTIONAL. JWE [JWE] alg algorithm [JWA] the RP is declaring that
              it may use for encrypting Request
                Objects sent to the OP. This parameter SHOULD be included when symmetric encryption will be used,
                since this signals to the OP that a client_secret value needs to be returned from which the
                symmetric key will be derived, that might not otherwise be returned. The RP MAY still use other
                supported encryption algorithms or send unencrypted Request Objects, even when this parameter
                is present. If both signing and encryption are requested, the Request Object will be signed
                then encrypted, with the result being a Nested JWT, as defined in [JWT]. The default, if omitted,
                is that the RP is not declaring whether it might encrypt any Request Objects.

              The point here is "The RP MAY still use other supported encryption
              algorithms or send unencrypted

              Request Objects, even when this parameter is present."


              The property that represents the client metadata is
              `requestEncryptionAlg`. See the description

              of `requestEncryptionAlg` for details.


              Even if this flag is `false`, the match is required if the
              `requestObjectEncryptionAlgMatchRequired`

              flag of the service is `true`.

              </Accordion>
        requestObjectEncryptionEncMatchRequired:
          type: boolean
          description: >
            The flag indicating whether the JWE enc of encrypted request object
            must match the `request_object_encryption_enc`

            client metadata.
          x-mint:
            metadata:
              description: >-
                The flag indicating whether the JWE enc of encrypted request
                object must match the `request_object_encryption_enc` client
                metadata.
            content: >
              <Accordion title="Full description" defaultOpen={false}>

              The `request_object_encryption_enc` client metadata itself is
              defined in [OpenID Connect Dynamic

              Client Registration
              1.0](https://openid.net/specs/openid-connect-registration-1_0.html)
              as follows.


              > request_object_encryption_enc

              >

              > OPTIONAL. JWE enc algorithm [JWA] the RP is declaring that it
              may use for encrypting Request
                Objects sent to the OP. If request_object_encryption_alg is specified, the default for this
                value is A128CBC-HS256. When request_object_encryption_enc is included, request_object_encryption_alg
                MUST also be provided.

              The property that represents the client metadata is
              `requestEncryptionEnc`. See the description

              of `requestEncryptionEnc`  for details.


              Even if this flag is `false`, the match is required if the
              `requestObjectEncryptionEncMatchRequired`

              flag of the service is `true`.

              </Accordion>
        digestAlgorithm:
          type: string
          description: >
            The digest algorithm that this client requests the server to use

            when it computes digest values of [external
            attachments](https://openid.net/specs/openid-connect-4-identity-assurance-1_0.html#name-external-attachments),
            which may be referenced from within ID tokens

            or userinfo responses (or any place that can have the
            `verified_claims` claim).

            Possible values are listed in the [Hash Algorithm
            Registry](https://www.iana.org/assignments/named-information/named-information.xhtml#hash-alg)
            of IANA (Internet Assigned Numbers Authority),

            but the server does not necessarily support all the values there.
            When

            this property is omitted, `sha-256` is used as the default
            algorithm.

            This property corresponds to the `digest_algorithm` client metadata

            which was defined by the third implementer's draft of

            [OpenID Connect for Identity Assurance
            1.0](https://openid.net/specs/openid-connect-4-identity-assurance-1_0.html).
        singleAccessTokenPerSubject:
          type: boolean
          description: >
            If `Enabled` is selected, an attempt to issue a new access token
            invalidates existing access tokens that are associated with the same
            combination of subject and client.


            Note that, however, attempts by Client Credentials Flow do not
            invalidate existing access tokens because access tokens issued by
            Client Credentials Flow are not associated with any end-user's
            subject.


            Even if `Disabled` is selected here, single access token per subject
            is effective if `singleAccessTokenPerSubject` of the `Service` this
            client belongs to is Enabled.
        pkceRequired:
          type: boolean
          description: >
            The flag to indicate whether the use of Proof Key for Code Exchange
            (PKCE) is always required for authorization requests by
            Authorization Code Flow.


            If `true`, `code_challenge` request parameter is always required for
            authorization requests using Authorization Code Flow.


            See [RFC 7636](https://tools.ietf.org/html/rfc7636) (Proof Key for
            Code Exchange by OAuth Public Clients) for details about
            `code_challenge` request parameter.
        pkceS256Required:
          type: boolean
          description: >
            The flag to indicate whether `S256` is always required as the code
            challenge method whenever [PKCE (RFC
            7636)](https://tools.ietf.org/html/rfc7636) is used.


            If this flag is set to `true`, `code_challenge_method=S256` must be
            included in the authorization request

            whenever it includes the `code_challenge` request parameter.

            Neither omission of the `code_challenge_method` request parameter
            nor use of plain (`code_challenge_method=plain`) is allowed.
        dpopRequired:
          type: boolean
          description: |
            If the DPoP is required for this client
        automaticallyRegistered:
          type: boolean
          description: |
            The flag indicating whether this client was registered by the
            "automatic" client registration of OIDC Federation.
        explicitlyRegistered:
          type: boolean
          description: |
            The flag indicating whether this client was registered by the
            "explicit" client registration of OIDC Federation.
        rsRequestSigned:
          type: boolean
          description: >
            The flag indicating whether this service signs responses from the
            resource server.
        rsSignedRequestKeyId:
          type: string
          description: >
            The key ID of a JWK containing the public key used by this client to
            sign requests to the resource server.
        clientRegistrationTypes:
          type: array
          items:
            $ref: '#/components/schemas/client_registration_type'
          description: >
            The client registration types that the client has declared it may
            use.
        organizationName:
          type: string
          description: >
            The human-readable name representing the organization that manages
            this client. This property corresponds

            to the organization_name client metadata that is defined in OpenID
            Connect Federation 1.0.
        signedJwksUri:
          type: string
          description: >
            The URI of the endpoint that returns this client's JWK Set document
            in the JWT format. This property

            corresponds to the `signed_jwks_uri` client metadata defined in
            OpenID Connect Federation 1.0.
        entityId:
          type: string
          description: |
            the entity ID of this client.
        trustAnchorId:
          type: string
          description: >
            The entity ID of the trust anchor of the trust chain that was used
            when this client was registered or updated by

            the mechanism defined in OpenID Connect Federation 1.0
        trustChain:
          type: array
          items:
            type: string
          description: >
            The trust chain that was used when this client was registered or
            updated by the mechanism defined in

            OpenID Connect Federation 1.0
        trustChainExpiresAt:
          type: integer
          format: int64
          description: >
            the expiration time of the trust chain that was used when this
            client was registered or updated by the mechanism

            defined in OpenID Connect Federation 1.0. The value is represented
            as milliseconds elapsed since the Unix epoch (1970-01-01).
        trustChainUpdatedAt:
          type: integer
          format: int64
          description: >
            the time at which the trust chain was updated by the mechanism
            defined in OpenID Connect Federation 1.0
        locked:
          type: boolean
          description: |
            The flag which indicates whether this client is locked.
        credentialOfferEndpoint:
          type: string
          description: |
            The URL of the credential offer endpoint at which this client
            (wallet) receives a credential offer from the credential issuer.
        fapiModes:
          type: array
          items:
            $ref: '#/components/schemas/fapi_mode'
          description: |
            The FAPI modes for this client.
          x-mint:
            metadata:
              description: The FAPI modes for this client.
            content: >
              <Accordion title="Full description" defaultOpen={false}>

              When the value of this property is not `null`, Authlete always
              processes requests from this client

              based on the specified FAPI modes if the FAPI feature is enabled
              in Authlete, the FAPI profile

              is supported by the service, and the FAPI modes for the service
              are set to `null`.


              For instance, when this property is set to an array containing
              `FAPI1_ADVANCED` only, Authlete

              always processes requests from this client based on
              "Financial-grade API Security Profile 1.0 -

              Part 2: Advanced" if the FAPI feature is enabled in Authlete, the
              FAPI profile is supported by

              the service, and the FAPI modes for the service are set to `null`.

              </Accordion>
        responseModes:
          type: array
          items:
            type: string
            enum:
              - QUERY
              - FRAGMENT
              - FORM_POST
              - JWT
              - QUERY_JWT
              - FRAGMENT_JWT
              - FORM_POST_JWT
          description: The response modes that this client may use.
        credentialResponseEncryptionRequired:
          type: boolean
          description: >-
            True if credential responses to this client must be always
            encrypted.
        mtlsEndpointAliasesUsed:
          type: boolean
          description: >
            The flag indicating whether the client intends to prefer mutual TLS
            endpoints over non-MTLS endpoints.


            This property corresponds to the `use_mtls_endpoint_aliases` client
            metadata that is defined in

            [FAPI 2.0 Security Profile, 8.1.1.
            use_mtls_endpoint_aliases](https://openid.bitbucket.io/fapi/fapi-2_0-security-profile.html#section-8.1.1).
        inScopeForTokenMigration:
          type: boolean
          description: >
            The flag indicating whether this client is in scope for token
            migration 

            operations.
        metadataDocumentLocation:
          type: string
          format: uri
          description: >
            Location of the Client ID Metadata Document that was used for this
            client.
        metadataDocumentExpiresAt:
          type: integer
          format: int64
          description: >
            Expiration time of the metadata document (UNIX time in
            milliseconds).
        metadataDocumentUpdatedAt:
          type: integer
          format: int64
          description: >
            Last-updated time of the metadata document (UNIX time in
            milliseconds).
        discoveredByMetadataDocument:
          type: boolean
          description: >
            Indicates whether this client was discovered via a Client ID
            Metadata Document.
        clientSource:
          type: string
          description: |
            Source of this client record.
          enum:
            - DYNAMIC_REGISTRATION
            - AUTOMATIC_REGISTRATION
            - EXPLICIT_REGISTRATION
            - METADATA_DOCUMENT
            - STATIC_REGISTRATION
    result:
      type: object
      properties:
        resultCode:
          type: string
          description: The code which represents the result of the API call.
        resultMessage:
          type: string
          description: A short message which explains the result of the API call.
    tagged_value:
      type: object
      properties:
        tag:
          type: string
          description: The language tag part.
        value:
          type: string
          description: The value part.
    client_type:
      type: string
      description: >
        The client type, either `CONFIDENTIAL` or `PUBLIC`. See [RFC 6749, 2.1.
        Client Types](https://datatracker.ietf.org/doc/html/rfc6749#section-2.1)

        for details.
      enum:
        - PUBLIC
        - CONFIDENTIAL
    application_type:
      type: string
      description: >
        The application type. The value of this property affects the validation
        steps for a redirect URI.

        See the description about `redirectUris` property for more details.
      enum:
        - WEB
        - NATIVE
    grant_type:
      type: string
      description: |
        The grant type of the access token when the access token was created.
      enum:
        - AUTHORIZATION_CODE
        - IMPLICIT
        - PASSWORD
        - CLIENT_CREDENTIALS
        - REFRESH_TOKEN
        - CIBA
        - DEVICE_CODE
        - TOKEN_EXCHANGE
        - JWT_BEARER
        - PRE_AUTHORIZED_CODE
    response_type:
      type: string
      enum:
        - NONE
        - CODE
        - TOKEN
        - ID_TOKEN
        - CODE_TOKEN
        - CODE_ID_TOKEN
        - ID_TOKEN_TOKEN
        - CODE_ID_TOKEN_TOKEN
    jws_alg:
      type: string
      nullable: true
      description: >
        The signature algorithm for JWT. This value is represented on 'alg'
        attribute

        of the header of JWT.


        it's semantics depends upon where is this defined, for instance:
          - as service accessTokenSignAlg value, it defines that access token are JWT and the algorithm used to sign it. Check your [KB article](https://kb.authlete.com/en/s/oauth-and-openid-connect/a/jwt-based-access-token).
          - as client authorizationSignAlg value, it represents the signature algorithm used when [creating a JARM response](https://kb.authlete.com/en/s/oauth-and-openid-connect/a/enabling-jarm).
          - or as client requestSignAlg value, it specifies which is the expected signature used by [client on a Request Object](https://kb.authlete.com/en/s/oauth-and-openid-connect/a/request-objects).
      enum:
        - NONE
        - HS256
        - HS384
        - HS512
        - RS256
        - RS384
        - RS512
        - ES256
        - ES384
        - ES512
        - PS256
        - PS384
        - PS512
        - ES256K
        - EdDSA
    jwe_alg:
      type: string
      nullable: true
      description: >
        this is the 'alg' header value for encrypted JWT tokens.

        Depending upon the context, this refers to key transport scheme to be
        used by the client and by the server. For instance:

        - as `authorizationEncryptionAlg` value, it refers to the encoding
        algorithm used by server for transporting they keys on JARM objects

        - as `requestEncryptionAlg` value, it refers to the expected key
        transport encoding algorithm that server expect from client when
        encrypting a Request Object

        - as `idTokenEncryptionAlg` value, it refers to the algorithm used by
        the server to key transport of id_tokens


        **Please note that some of the algorithms are more secure than others,
        some are not supported very well cross platforms and some (like RSA1_5)
        is known to be weak**.
      enum:
        - RSA1_5
        - RSA_OAEP
        - RSA_OAEP_256
        - A128KW
        - A192KW
        - A256KW
        - DIR
        - ECDH_ES
        - ECDH_ES_A128KW
        - ECDH_ES_A192KW
        - ECDH_ES_A256KW
        - A128GCMKW
        - A192GCMKW
        - A256GCMKW
        - PBES2_HS256_A128KW
        - PBES2_HS384_A192KW
        - PBES2_HS512_A256KW
    jwe_enc:
      type: string
      nullable: true
      description: >
        This is the encryption algorithm to be used when encrypting a JWT on
        client or server side.

        Depending upon the context, this refers to encryption done by the client
        or by the server. For instance:
          - as `authorizationEncryptionEnc` value, it refers to the encryption algorithm used by server when creating a JARM response
          - as `requestEncryptionEnc` value, it refers to the expected encryption algorithm used by the client when encrypting a Request Object
          - as `idTokenEncryptionEnc` value, it refers to the algorithm used by the server to encrypt id_tokens
      enum:
        - A128CBC_HS256
        - A192CBC_HS384
        - A256CBC_HS512
        - A128GCM
        - A192GCM
        - A256GCM
    client_auth_method:
      type: string
      description: >
        The client authentication method that the client application declares
        that it uses at the token

        endpoint. This property corresponds to `token_endpoint_auth_method` in
        [OpenID Connect Dynamic

        Client Registration 1.0, 2. Client
        Metadata](https://openid.net/specs/openid-connect-registration-1_0.html#ClientMetadata).
      enum:
        - NONE
        - CLIENT_SECRET_BASIC
        - CLIENT_SECRET_POST
        - CLIENT_SECRET_JWT
        - PRIVATE_KEY_JWT
        - TLS_CLIENT_AUTH
        - SELF_SIGNED_TLS_CLIENT_AUTH
        - ATTEST_JWT_CLIENT_AUTH
    subject_type:
      type: string
      description: >
        The subject type that the client application requests. Details about the
        subject type are described in

        [OpenID Connect Core 1.0, 8. Subjct Identifier
        Types](https://openid.net/specs/openid-connect-core-1_0.html#SubjectIDTypes).


        This property corresponds to `subject_type` in

        [OpenID Connect Dynamic Client Registration 1.0, 2. Client
        Metadata](https://openid.net/specs/openid-connect-registration-1_0.html#ClientMetadata).
      enum:
        - PUBLIC
        - PAIRWISE
    pair:
      type: object
      properties:
        key:
          type: string
          description: The key part.
        value:
          type: string
          description: The value part.
    client_extension:
      type: object
      properties:
        requestableScopes:
          type: array
          items:
            type: string
          description: >
            The set of scopes that the client application is allowed to request.
            This paramter will be one

            of the following.
          x-mint:
            metadata:
              description: >-
                The set of scopes that the client application is allowed to
                request. This paramter will be one of the following.
            content: >
              <Accordion title="Full description" defaultOpen={false}>
                - `null`
                - an empty set
                - a set with at least one element

              When the value of this parameter is `null`, it means that the set
              of scopes that the client

              application is allowed to request is the set of the scopes that
              the service supports. When the

              value of this parameter is an empty set, it means that the client
              application is not allowed to

              request any scopes. When the value of this parameter is a set with
              at least one element, it means

              that the set is the set of scopes that the client application is
              allowed to request.

              </Accordion>
        requestableScopesEnabled:
          type: boolean
          description: >
            The flag to indicate whether "Requestable Scopes per Client" is
            enabled or not. If `true`, you

            can define the set of scopes which this client application can
            request. If `false`, this client

            application can request any scope which is supported by the
            authorization server.
        accessTokenDuration:
          type: integer
          format: int64
          description: >
            The value of the duration of access tokens per client in seconds. In
            normal cases, the value of

            the service's `accessTokenDuration` property is used as the duration
            of access tokens issued by

            the service. However, if this `accessTokenDuration` property holds a
            non-zero positive number

            and its value is less than the duration configured by the service,
            the value is used as the duration

            of access tokens issued to the client application.


            Note that the duration of access tokens can be controlled by the
            scope attribute `access_token.duration`,

            too. Authlete chooses the minimum value among the candidates.
        refreshTokenDuration:
          type: integer
          format: int64
          description: >
            The value of the duration of refresh tokens per client in seconds.
            In normal cases, the value

            of the service's `refreshTokenDuration` property is used as the
            duration of refresh tokens issued

            by the service. However, if this `refreshTokenDuration` property
            holds a non-zero positive number

            and its value is less than the duration configured by the service,
            the value is used as the duration

            of refresh tokens issued to the client application.


            Note that the duration of refresh tokens can be controlled by the
            scope attribute `refresh_token.duration`,

            too. Authlete chooses the minimum value among the candidates.
        idTokenDuration:
          type: integer
          format: int64
          description: >
            The value of the duration of ID tokens per client in seconds. In
            normal cases, the value

            of the service's `idTokenDuration` property is used as the duration
            of ID tokens issued

            by the service. However, if this `idTokenDuration` property holds a
            non-zero positive number

            and its value is less than the duration configured by the service,
            the value is used as the duration

            of ID tokens issued to the client application.


            Note that the duration of refresh tokens can be controlled by the
            scope attribute `id_token.duration`,

            too. Authlete chooses the minimum value among the candidates.
        tokenExchangePermitted:
          type: boolean
          description: >
            Get the flag indicating whether the client is explicitly given a

            permission to make token exchange requests ([RFC
            8693][https://www.rfc-editor.org/rfc/rfc8693.html])
    client_registration_type:
      type: string
      description: |
        Values for the `client_registration_types` RP metadata and the
         `client_registration_types_supported` OP metadata that are defined in
         [OpenID Connect Federation 1.0](https://openid.net/specs/openid-connect-federation-1_0.html).
      enum:
        - AUTOMATIC
        - EXPLICIT
    fapi_mode:
      type: string
      enum:
        - FAPI1_ADVANCED
        - FAPI1_BASELINE
        - FAPI2_MESSAGE_SIGNING_AUTH_REQ
        - FAPI2_MESSAGE_SIGNING_AUTH_RES
        - FAPI2_MESSAGE_SIGNING_INTROSPECTION_RES
        - FAPI2_SECURITY
  responses:
    '400':
      description: ''
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/result'
          example:
            resultCode: A001201
            resultMessage: '[A001201] /auth/authorization, TLS must be used.'
    '401':
      description: ''
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/result'
          example:
            resultCode: A001202
            resultMessage: '[A001202] /auth/authorization, Authorization header is missing.'
    '403':
      description: ''
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/result'
          example:
            resultCode: A001215
            resultMessage: >-
              [A001215] /auth/authorization, The client (ID = 26837717140341) is
              locked.
    '500':
      description: ''
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/result'
          example:
            resultCode: A001101
            resultMessage: '[A001101] /auth/authorization, Authlete Server error.'
  securitySchemes:
    bearer:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: >
        Authenticate every request with a **Service Access Token** or
        **Organization Token**.

        Set the token value in the `Authorization: Bearer <token>` header.


        **Service Access Token**: Scoped to a single service. Use when
        automating service-level configuration or runtime flows.


        **Organization Token**: Scoped to the organization; inherits permissions
        across services. Use for org-wide automation or when managing multiple
        services programmatically.


        Both token types are issued by the Authlete console or provisioning
        APIs.

````