Skip to content

[API Design Guideline] Does an API not implementing OIDC Discovery make it non-CAMARA compliant #43

@rkandoi

Description

@rkandoi

The current CAMARA guidelines make the use of three-legged auth flow mandatory. This is okay for B2C and B2B2C cases.

However, in the current versions of the API, Dedicated Networks will ONLY support the B2B case using Client Credentials and there is no real need to implement or design the three-legged flow in to the implementation or even in the info.description.

There does not seem to be a precedent for how to handle such a case in CAMARA. Creating this placeholder to discuss the topic.

Note that the r1.1 adopts CAMARA guidelines, but adopting the guideline is potentially misleading at this point.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions