Z
ZITADEL
Z
ZITADEL
Getting error with JWT Profile Grant
Original message was deleted
ZITADEL
Join
ZITADEL - Identity infrastructure, simplified for you.
4,316
Members
View on Discord
F
FFO
•
2/21/23, 4:52 PM
Hm is it not
urn:ietf:params:oauth:client-assertion-type:jwt-bearer
urn:ietf:params:oauth:client-assertion-type:jwt-bearer
in this case
?
F
FFO
•
2/21/23, 4:56 PM
Hm gime a sec
F
FFO
•
2/21/23, 4:59 PM
Ah now i see it
.
"
u
r
n
:
i
e
t
f
:
p
a
r
a
m
s
:
o
a
u
t
h
:client
-assertion
-
t
y
p
e
:jwt
-bearer
" is used to authenticate a client
/app directly against the
/introspect
F
FFO
•
2/21/23, 4:59 PM
no need to pass along the
/token
F
FFO
•
2/21/23, 4:59 PM
If you want to get a token to send to an API you need to use a service user instead
F
FFO
•
2/21/23, 5:14 PM
Yes
F
FFO
•
2/21/23, 9:08 PM
The client
/app credentials are not intended to get tokens
.
We use service accounts for this
, because they can receive access rights and generally are manageable like a user
.
urn:ietf:params:oauth:client-assertion-type:jwt-bearer
urn:ietf:params:oauth:client-assertion-type:jwt-bearer