News

Authlete 2.1 conforms Dynamic and Form Post OP profiles of OpenID Connect protocol

August 5, 2019 - Authlete, Inc has certified that Authlete 2.1 conforms to the Dynamic and Form Post OpenID Provider (OP) Profiles of the OpenID Connect protocol. So far, our solution, Authlete, has received the following certifications.

  • Basic OP Profile
  • Implicit OP Profile
  • Hybrid OP Profile
  • Config OP Profile
  • Dynamic OP Profile
  • Form Post OP Profile
  • FAPI (Financial-grade API) R/W OP w/ MTLS
  • FAPI (Financial-grade API) R/W OP w/ Private Key

The Dynamic OP Profile is for an OP that conforms the specification of Section 15.2. Mandatory to Implement Features for Dynamic OpenID Provides in OpenID Connect Core 1.0. The OP with the profile can register OpenID Relying Party (RP) dynamically based on the specification of OpenID Connect Dynamic Client Registration 1.0. This feature enables OPs to issue different client ID to each resource owner, for example.

The Form Post OP Profile is for an OP that conforms the specification of OAuth 2.0 Form Post Response Mode. The OP with the profile can send an authorization response to a user agent with HTTP POST method, on top of HTTP GET method. This features can veil the parameters in the authorization response and improve the security in some cases.

Please contact us for more details.