Skip to main content
Version: v0.25.0 (Latest)

Create and activate a hosted server

Step 2 of 4 in Configure the authorization server.

Skip this step when the default server already fits. Otherwise create a hosted server:

{
"slug": "acme-login",
"displayName": "Acme login",
"issuer": "https://acme.example.com/as/acme-login",
"deployment": "HOSTED",
"authenticationMode": "HYBRID",
"purposes": ["GENERAL", "CREDENTIAL_ISSUANCE", "WALLET_LOGIN"],
"allowedGrantTypes": ["authorization_code", "refresh_token"]
}
Loading example...

slug becomes part of the authorization, discovery, JWKS and login URLs. issuer must be the public HTTPS origin wallets and browsers use, never an internal hostname. allowedGrantTypes must include every grant the issuer will offer, but enabling a grant here does not enable it on a client.

Correct the hosted configuration when needed, then activate. An external resource instead runs discovery validation before activation.

Loading example...
Loading example...

After activation, read discovery and JWKS through the tenant gateway. A 200 from the admin API does not prove the public protocol endpoints work.

Next​

Continue with step 3, Register clients.