Skip to main content
Version: v0.25.0 (Latest)

Authorization Server features

Open Protocols, select a tenant authorization server by its UUID-backed resource entry, and choose Features. This screen is tenant scoped; the platform authorization server is isolated and cannot be edited here.

Feature switches control hosted behavior such as OpenID Connect, introspection, revocation, logout, PAR, PKCE, DPoP, JAR, JARM, and signed metadata. Enable only capabilities supported by the selected grants, signing configuration, and client registrations.

Saving replaces the typed features section atomically. The console submits the section's current revision with the complete features policy. If another administrator changed it, the save fails with a revision conflict and the console reloads the current state instead of overwriting it.

The screen reads and replaces the aggregate hosted configuration. Features are fields of that revisioned resource, not a separately writable store:

GET /api/platform/config/v1/tenants/{tenantId}/authorization-servers/{authorizationServerId}/configuration
PUT /api/platform/config/v1/tenants/{tenantId}/authorization-servers/{authorizationServerId}/configuration

Runtime discovery metadata is projected from the committed resource. Deployment configuration is not a second feature store.