[Openid-specs-fapi] How best to combine PAR with Device Flow to help with x2Web flow to receive authorisation code

Nicholas Irving nirving at darkedges.com
Wed Dec 7 22:18:53 UTC 2022


Morning
We have a problem where we don't want to allow web access to our IDP,
instead push them to App via a QR Code. However it is not clear if a Pushed
Authorisation Request can participate in that flow so that we can get
claims for IDMVP.

Yes this is an Authorisation Server issue that I would like to solve via
specs as I don't want the relying party to have to choose which spec to
implement, as deep linking will solve the problem for x2App. CIBA is a pain
as once again the relying party had to collect and control information
prior to the request and again we don't want this to happen for the x2App
flow, as it is a bad CX.

Any plans to help solve this problem via specs?

Regards
Nicholas Irving
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.openid.net/pipermail/openid-specs-fapi/attachments/20221208/8147e1a0/attachment.html>


More information about the Openid-specs-fapi mailing list