You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
<pclass="note" role="note"><spanclass="marker">NOTE:</span> This sections borrows concepts from OAuth 2.0 <adata-link-type="biblio" href="#biblio-rfc6749" title="The OAuth 2.0 Authorization Framework">[RFC6749]</a>, while the rest of Solid-OIDC builds on top of OpenID
1064
1095
Connect Core 1.0 <adata-link-type="biblio" href="#biblio-oidc-core" title="OpenID Connect Core 1.0">[OIDC-CORE]</a>. The section is likely to be extracted into a separate specification in the future.</p>
1065
-
<p>Authorization Servers MUST support the OAuth 2.0 Client Credentials Grant <adata-link-type="biblio" href="#biblio-rfc6749" title="The OAuth 2.0 Authorization Framework">[RFC6749]</a> (Section 4.4) to enable
1096
+
<p>Authorization Servers SHOULD support the OAuth 2.0 Client Credentials Grant <adata-link-type="biblio" href="#biblio-rfc6749" title="The OAuth 2.0 Authorization Framework">[RFC6749]</a> (Section 4.4) to enable
1066
1097
non-interactive authentication for scripts, automated agents, and server-to-server communication.</p>
1067
1098
<pclass="note" role="note"><spanclass="marker">NOTE:</span> Scripts and bots can also use Solid-OIDC without Client Credentials via the <ahref="https://www.rfc-editor.org/rfc/rfc6749#section-1.5">refresh token
<dd>Andrei Sambra; Henry Story; Tim Berners-Lee. <ahref="https://www.w3.org/2005/Incubator/webid/spec/identity/"><cite>WebID 1.0</cite></a>. URL: <ahref="https://www.w3.org/2005/Incubator/webid/spec/identity/">https://www.w3.org/2005/Incubator/webid/spec/identity/</a>
<dd><ahref="https://www.rfc-editor.org/info/bcp195"><cite>Best Current Practice 195</cite></a>. URL: <ahref="https://www.rfc-editor.org/info/bcp195">https://www.rfc-editor.org/info/bcp195</a>
<dd>N. Sakimura, Ed.; J. Bradley; N. Agarwal. <ahref="https://www.rfc-editor.org/rfc/rfc7636"><cite>Proof Key for Code Exchange by OAuth Public Clients</cite></a>. September 2015. Proposed Standard. URL: <ahref="https://www.rfc-editor.org/rfc/rfc7636">https://www.rfc-editor.org/rfc/rfc7636</a>
0 commit comments