Skip to content

Pushed authorization requests

The client pushes its authorization request to the provider, authenticating itself, and receives a request_uri the browser then carries. Nothing of the request travels in a URL, and the provider knows the request was not tampered with on the way.

This page will describe the endpoint, the lifetime of a request_uri, and what a tenant may require.