Version: v0.25.0 (Latest)
Token exchange settings
Open a hosted authorization server and choose Settings, then Token exchange. Configure whether token exchange is available and which subject-token, actor-token, audience, and requested-token combinations the hosted resource accepts.
Token exchange is disabled unless the grant and feature policy both allow it. Treat accepted audiences and token types as an allowlist. The service validates the complete policy and commits it atomically with the resource revision.
Changing this section affects new exchanges. It does not mutate tokens already issued by this or another authorization server.
Token-exchange settings are fields of the aggregate hosted configuration below the selected UUID:
GET /api/platform/config/v1/tenants/{tenantId}/authorization-servers/{authorizationServerId}/configuration
PUT /api/platform/config/v1/tenants/{tenantId}/authorization-servers/{authorizationServerId}/configuration