Skip to main content
Version: v0.25.0 (Latest)

Review the tenant authorization servers

Step 1 of 4 in Configure the authorization server.

Start with the authorization servers your tenant can use. This list comes from the authorization server service itself and is tenant-scoped: the tenant is taken from your access token, so you only ever see your own servers.

Loading example...
Loading example...

Each item carries the server id, its display name and lifecycle status, and the public issuer a wallet or client sees, with links to its administration record. Results are paged with cursor and limit. Nothing secret is returned: client secrets, signing keys and upstream credentials never appear.

The administration record holds the full configuration. Read it through the platform configuration API with the same id:

Loading example...
Loading example...

A newly provisioned tenant has one hosted default server, normally in LOCAL_ONLY authentication mode. Each entry carries the administration UUID, slug, public issuer, deployment (HOSTED or EXTERNAL), purposes, lifecycle status and a revision. Use the UUID in every later path; never reconstruct it from the slug or the issuer URL.

purposes decide which platform resources may select the server: GENERAL, CREDENTIAL_ISSUANCE and WALLET_LOGIN. A server without CREDENTIAL_ISSUANCE cannot be bound to an issuer later.

Next​

Continue with step 2, Create and activate a hosted server.