authzen icon indicating copy to clipboard operation
authzen copied to clipboard

Proposed standard for an Authorization API

Results 61 authzen issues
Sort by recently updated
recently updated
newest added

Output of running the test script on the Axiomatics PDP hosted at https://alfa.pdp.guide

This merge seems to have broken the automatic building of the GitHub pages: https://github.com/openid/authzen/actions/runs/7891433299

In the spec the error status reponses are specified: > 401 | Unauthorized | An error message string > 403 | Forbidden | An error message string Suggest clarifying that...

Should the access decision be signed by the PDP private key to ensure that the payload has not been tampered with?

PDP may want to keep a stateful session between the PEP and PDP. Rationale: you could provide further input that would be used for the PDP to make a decision;...

"Common Actions" currently defines 4 CRUD and one generice "access" action. are those normative and mandatory for PDP/PEP spec compliance? How should a PDP response, in cases a common action...

A PDP may involve third party components into policy evaluation as a sub-query, i.e. a Policy Information Point (PIP) which holds additional information about the resource/subjects relationships or other metadata...