/** * Types and Schema definitions for OIDC * * @link https://openid.net/specs/openid-4-verifiable-credential-issuance-1_0.html */ import * as TB from "@sinclair/typebox"; export declare namespace Protocols { const CredentialRequest = "OIDC_V1/CREDENTIAL_REQUEST"; } export type CredentialOffer = TB.Static; export declare const CredentialOffer: TB.TObject<{ /** * url of the Credential Issuer * from which the wallet is requested to obtain one or more Credentials * the Wallet uses it to obtain the Credential Issuer's Metadata */ credential_issuer: TB.TString; /** * array of unique strings that each identify one of the keys in name/value pairs * stored in the `credential_configurations_supported` Credential Issuer Metadata */ credential_configuration_ids: TB.TArray; /** * indicates the Grant Types the Authorization Server is prepared to process * if `grants` is nil the Wallet must determine the Grant Types using the Metadata * when multiple grants are present, it is at the Wallets discretion which to use */ grants: TB.TOptional; /** * can be used to identify the Authorization Server to use with this grant type * when `authorization_servers` in Issuer Metadata has multiple entries */ authorization_server: TB.TOptional; }>>; "urn:ietf:params:oauth:grant-type:pre-authorized_code": TB.TOptional; /** * can be used to identify the Authorization Server to use with this grant type * when `authorization_servers` in Issuer Metadata has multiple entries */ authorization_server: TB.TOptional; /** * specifies whether the Authorization Server expects a presentation of a Transaction Code * along with the Token Request */ tx_code: TB.TOptional; length: TB.TOptional; description: TB.TOptional; }>>; }>>; }>>; }>; export type IssuerMetadata = TB.Static; export declare const IssuerMetadata: TB.TObject<{ credential_issuer: TB.TString; authorization_servers: TB.TOptional>; credential_endpoint: TB.TString; batch_credential_endpoint: TB.TOptional; deferred_credential_endpoint: TB.TOptional; notification_endpoint: TB.TOptional; signed_metadata: TB.TOptional; credential_configurations_supported: TB.TRecord; credential_definition: TB.TObject<{ type: TB.TArray; credentialSubject: TB.TOptional>; }>; cryptographic_binding_methods_supported: TB.TOptional>; credential_signing_alg_values_supported: TB.TOptional>; proof_types_supported: TB.TOptional; }>>>; }>>; credential_response_encryption: TB.TOptional; enc_values_supported: TB.TArray; encryption_required: TB.TBoolean; }>>; credential_identifiers_supported: TB.TOptional; display: TB.TOptional>; }>; export type AuthServerMetadata = TB.Static; export declare const AuthServerMetadata: TB.TObject<{ /** * Authorization server's Issuer Identifier URL. */ issuer: TB.TString; /** * URL of the authorization server's authorization endpoint. */ authorization_endpoint: TB.TOptional; /** * URL of the authorization server's token endpoint. */ token_endpoint: TB.TOptional; /** * URL of the authorization server's JWK Set document. */ jwks_uri: TB.TOptional; /** * URL of the authorization server's Dynamic Client Registration Endpoint. */ registration_endpoint: TB.TOptional; /** * JSON array containing a list of the `scope` values that this authorization server supports. */ scopes_supported: TB.TOptional>; /** * JSON array containing a list of the `response_type` values that this authorization server * supports. */ response_types_supported: TB.TOptional>; /** * JSON array containing a list of the `response_mode` values that this authorization server * supports. */ response_modes_supported: TB.TOptional>; /** * JSON array containing a list of the `grant_type` values that this authorization server * supports. */ grant_types_supported: TB.TOptional>; /** * JSON array containing a list of client authentication methods supported by this token endpoint. */ token_endpoint_auth_methods_supported: TB.TOptional>; /** * JSON array containing a list of the JWS signing algorithms supported by the token endpoint for * the signature on the JWT used to authenticate the client at the token endpoint. */ token_endpoint_auth_signing_alg_values_supported: TB.TOptional>; /** * URL of a page containing human-readable information that developers might want or need to know * when using the authorization server. */ service_documentation: TB.TOptional; /** * Languages and scripts supported for the user interface, represented as a JSON array of language * tag values from RFC 5646. */ ui_locales_supported: TB.TOptional>; /** * URL that the authorization server provides to the person registering the client to read about * the authorization server's requirements on how the client can use the data provided by the * authorization server. */ op_policy_uri: TB.TOptional; /** * URL that the authorization server provides to the person registering the client to read about * the authorization server's terms of service. */ op_tos_uri: TB.TOptional; /** * URL of the authorization server's revocation endpoint. */ revocation_endpoint: TB.TOptional; /** * JSON array containing a list of client authentication methods supported by this revocation * endpoint. */ revocation_endpoint_auth_methods_supported: TB.TOptional>; /** * JSON array containing a list of the JWS signing algorithms supported by the revocation endpoint * for the signature on the JWT used to authenticate the client at the revocation endpoint. */ revocation_endpoint_auth_signing_alg_values_supported: TB.TOptional>; /** * URL of the authorization server's introspection endpoint. */ introspection_endpoint: TB.TOptional; /** * JSON array containing a list of client authentication methods supported by this introspection * endpoint. */ introspection_endpoint_auth_methods_supported: TB.TOptional>; /** * JSON array containing a list of the JWS signing algorithms supported by the introspection * endpoint for the signature on the JWT used to authenticate the client at the introspection * endpoint. */ introspection_endpoint_auth_signing_alg_values_supported: TB.TOptional>; /** * PKCE code challenge methods supported by this authorization server. */ code_challenge_methods_supported: TB.TOptional>; /** * Signed JWT containing metadata values about the authorization server as claims. */ signed_metadata: TB.TOptional; /** * URL of the authorization server's device authorization endpoint. */ device_authorization_endpoint: TB.TOptional; /** * Indicates authorization server support for mutual-TLS client certificate-bound access tokens. */ tls_client_certificate_bound_access_tokens: TB.TOptional; /** * JSON object containing alternative authorization server endpoints, which a client intending to * do mutual TLS will use in preference to the conventional endpoints. */ mtls_endpoint_aliases: TB.TOptional>; /** * URL of the authorization server's UserInfo Endpoint. */ userinfo_endpoint: TB.TOptional; /** * JSON array containing a list of the Authentication Context Class References that this * authorization server supports. */ acr_values_supported: TB.TOptional>; /** * JSON array containing a list of the Subject Identifier types that this authorization server * supports. */ subject_types_supported: TB.TOptional>; /** * JSON array containing a list of the JWS `alg` values supported by the authorization server for * the ID Token. */ id_token_signing_alg_values_supported: TB.TOptional>; /** * JSON array containing a list of the JWE `alg` values supported by the authorization server for * the ID Token. */ id_token_encryption_alg_values_supported: TB.TOptional>; /** * JSON array containing a list of the JWE `enc` values supported by the authorization server for * the ID Token. */ id_token_encryption_enc_values_supported: TB.TOptional>; /** * JSON array containing a list of the JWS `alg` values supported by the UserInfo Endpoint. */ userinfo_signing_alg_values_supported: TB.TOptional>; /** * JSON array containing a list of the JWE `alg` values supported by the UserInfo Endpoint. */ userinfo_encryption_alg_values_supported: TB.TOptional>; /** * JSON array containing a list of the JWE `enc` values supported by the UserInfo Endpoint. */ userinfo_encryption_enc_values_supported: TB.TOptional>; /** * JSON array containing a list of the JWS `alg` values supported by the authorization server for * Request Objects. */ request_object_signing_alg_values_supported: TB.TOptional>; /** * JSON array containing a list of the JWE `alg` values supported by the authorization server for * Request Objects. */ request_object_encryption_alg_values_supported: TB.TOptional>; /** * JSON array containing a list of the JWE `enc` values supported by the authorization server for * Request Objects. */ request_object_encryption_enc_values_supported: TB.TOptional>; /** * JSON array containing a list of the `display` parameter values that the authorization server * supports. */ display_values_supported: TB.TOptional>; /** * JSON array containing a list of the Claim Types that the authorization server supports. */ claim_types_supported: TB.TOptional>; /** * JSON array containing a list of the Claim Names of the Claims that the authorization server MAY * be able to supply values for. */ claims_supported: TB.TOptional>; /** * Languages and scripts supported for values in Claims being returned, represented as a JSON * array of RFC 5646 language tag values. */ claims_locales_supported: TB.TOptional>; /** * Boolean value specifying whether the authorization server supports use of the `claims` * parameter. */ claims_parameter_supported: TB.TOptional; /** * Boolean value specifying whether the authorization server supports use of the `request` * parameter. */ request_parameter_supported: TB.TOptional; /** * Boolean value specifying whether the authorization server supports use of the `request_uri` * parameter. */ request_uri_parameter_supported: TB.TOptional; /** * Boolean value specifying whether the authorization server requires any `request_uri` values * used to be pre-registered. */ require_request_uri_registration: TB.TOptional; /** * Indicates where authorization request needs to be protected as Request Object and provided * through either `request` or `request_uri` parameter. */ require_signed_request_object: TB.TOptional; /** * URL of the authorization server's pushed authorization request endpoint. */ pushed_authorization_request_endpoint: TB.TOptional; /** * Indicates whether the authorization server accepts authorization requests only via PAR. */ require_pushed_authorization_requests: TB.TOptional; /** * JSON array containing a list of algorithms supported by the authorization server for * introspection response signing. */ introspection_signing_alg_values_supported: TB.TOptional>; /** * JSON array containing a list of algorithms supported by the authorization server for * introspection response content key encryption (`alg` value). */ introspection_encryption_alg_values_supported: TB.TOptional>; /** * JSON array containing a list of algorithms supported by the authorization server for * introspection response content encryption (`enc` value). */ introspection_encryption_enc_values_supported: TB.TOptional>; /** * Boolean value indicating whether the authorization server provides the `iss` parameter in the * authorization response. */ authorization_response_iss_parameter_supported: TB.TOptional; /** * JSON array containing a list of algorithms supported by the authorization server for * introspection response signing. */ authorization_signing_alg_values_supported: TB.TOptional>; /** * JSON array containing a list of algorithms supported by the authorization server for * introspection response encryption (`alg` value). */ authorization_encryption_alg_values_supported: TB.TOptional>; /** * JSON array containing a list of algorithms supported by the authorization server for * introspection response encryption (`enc` value). */ authorization_encryption_enc_values_supported: TB.TOptional>; /** * CIBA Backchannel Authentication Endpoint. */ backchannel_authentication_endpoint: TB.TOptional; /** * JSON array containing a list of the JWS signing algorithms supported for validation of signed * CIBA authentication requests. */ backchannel_authentication_request_signing_alg_values_supported: TB.TOptional>; /** * Supported CIBA authentication result delivery modes. */ backchannel_token_delivery_modes_supported: TB.TOptional>; /** * Indicates whether the authorization server supports the use of the CIBA `user_code` parameter. */ backchannel_user_code_parameter_supported: TB.TOptional; /** * URL of an authorization server iframe that supports cross-origin communications for session * state information with the RP Client, using the HTML5 postMessage API. */ check_session_iframe: TB.TOptional; /** * JSON array containing a list of the JWS algorithms supported for DPoP proof JWTs. */ dpop_signing_alg_values_supported: TB.TOptional>; /** * URL at the authorization server to which an RP can perform a redirect to request that the * End-User be logged out at the authorization server. */ end_session_endpoint: TB.TOptional; /** * Boolean value specifying whether the authorization server can pass `iss` (issuer) and `sid` * (session ID) query parameters to identify the RP session with the authorization server when the * `frontchannel_logout_uri` is used. */ frontchannel_logout_session_supported: TB.TOptional; /** * Boolean value specifying whether the authorization server supports HTTP-based logout. */ frontchannel_logout_supported: TB.TOptional; /** * Boolean value specifying whether the authorization server can pass a `sid` (session ID) Claim * in the Logout Token to identify the RP session with the OP. */ backchannel_logout_session_supported: TB.TOptional; /** * Boolean value specifying whether the authorization server supports back-channel logout. */ backchannel_logout_supported: TB.TOptional; }>; export type TokenResponse = TB.Static; export declare const TokenResponse: TB.TObject<{ access_token: TB.TString; token_type: TB.TString; expires_in: TB.TOptional; c_nonce: TB.TOptional; c_nonce_expires_in: TB.TOptional; refresh_token: TB.TOptional; refresh_expires_in: TB.TOptional; id_token: TB.TOptional; scope: TB.TOptional; session_state: TB.TOptional; }>;