Confirm public endpoints and runtime discovery
Step 3 of 3 in Onboard a tenant.
Provisioning binds the protocol surfaces you enabled to the tenant host: authorization server, issuer,
verifier and DID resolution. Listing the bindings confirms the tenant is reachable at the addresses
its credentials and metadata will advertise. Each entry also carries the wellKnownPath a wallet
uses, which is the nearest the API comes to returning published issuer metadata; see
Set up the credential issuer.
Runtime discovery returns the browser-safe base URLs for KMS, DID, design and other calls. Take those values from discovery rather than assembling them from the slug and base domain, because a deployment can publish a surface on a host you would not guess.
When the tenant reads ACTIVE and its endpoints resolve, the tenant owner can activate their account
and register the confidential tenant application described in
Configure the authorization server.
Next
This completes the journey. Continue with Connect Azure KMS with BYOK and BYOC.