All Classes and Interfaces
Class
Description
One instance's clients, grants and consents, lost on restart.
A client of the authorization server, described by its RFC 7591 metadata exactly as it was registered
(defaults filled in).
An authorization code or a refresh token, stored under the hash of its value.
A caller holding an access token this application issued.
An OAuth 2.1 authorization server for the application's own users and resources.
A registered client, and its secret — shown this once, never stored.
Where the authorization server keeps its clients, grants and consents.
Whom an authorization is for, as the application names them:
id becomes the access token's
sub, claims travel in every token issued from it.