Claims reviews
Not served by the id service: sent by it, to a service that
owns a scope, at <URL>/api/v1alpha1/claimsreviews or
FG_ID_SERVICE_<NAME>_CLAIMS_ENDPOINT.
The OpenAPI document describes it
under webhooks.
POST /api/v1alpha1/claimsreviews
Authorization: Bearer <JWT, typ fg-claims-review+jwt>
Content-Type: application/json
request | |
|---|---|
uid | echo it in the response |
purpose | Preview while the person decides, Release when the claims go out |
subject | the person, as sub |
client | the service the claims are for, { id, name } |
scopes, claims | what is asked for |
response | |
|---|---|
uid | the request's |
claims | the claims; anything the scopes do not carry is dropped |
reasons | optional: what was withheld and why, shown to the person |
Answer within three seconds, or the claims are left out.