oauth-wg/oauth-transaction-tokens

Need to describe how claims are transcribed

Closed this issue · 3 comments

Describe how to show that claims are transcribed (namespaced) both withing and across trust domains.

tulshi commented

Would this be more of a concern for the identity chaining draft rather than the transaction tokens draft?

I was expecting to see it in the transaction token draft because I think this will be the more common use case - most workloads will operate within a trust boundary, and crossing it will be less frequent. We can the reference it in the Identity Chaing draft and make any tweaks we need to make there (hopefully we can just inherit it all from the transaction token draft).

The azc claim in the latest draft describes how to represent transcribed claims.