rafiki
rafiki copied to clipboard
Validate httpsig on RS requests
The backend should use the key returned in the token introspection response to validate the httpsig on the request from the client.
https://datatracker.ietf.org/doc/html/draft-ietf-gnap-resource-servers#section-3.3