Get a Self-Issued ID token (STS)
POST
/dcp/sts/token
const url = 'https://example.com/dcp/sts/token';const options = { method: 'POST', headers: {'Content-Type': 'application/x-www-form-urlencoded'}, body: new URLSearchParams({ grant_type: 'example', client_id: 'example', client_secret: 'example', audience: 'example', bearer_access_scope: 'example', token: 'example' })};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request POST \ --url https://example.com/dcp/sts/token \ --header 'Content-Type: application/x-www-form-urlencoded' \ --data grant_type=example \ --data client_id=example \ --data client_secret=example \ --data audience=example \ --data bearer_access_scope=example \ --data token=exampleThe Secure Token Service of the participant: OAuth 2.0 client credentials give a Self-Issued ID token for an audience, with an access token for the scopes the audience may query. For the participant’s own components, authenticated by client id and secret.
Authorizations
Section titled “Authorizations”- None
Request Bodyrequired
Section titled “Request Bodyrequired”Media typeapplication/x-www-form-urlencoded
An OAuth 2.0 token request with client credentials.
object
grant_type
required
client_credentials.
string
client_id
required
string
client_secret
required
string
audience
required
The DID of the verifier the token is for.
string
bearer_access_scope
Space-separated scopes the verifier may query, e.g.
org.eclipse.dspace.dcp.vc.type:MembershipCredential:read.
string | null
token
An access token from another party to embed, instead of a new one.
string | null
Example generated
grant_type=example&client_id=example&client_secret=example&audience=example&bearer_access_scope=example&token=exampleResponses
Section titled “Responses”OK.
Media typeapplication/json
object
access_token
required
A Self-Issued ID token of this participant for the audience.
string
token_type
required
Bearer.
string
expires_in
required
integer format: int64
Example generated
{ "access_token": "example", "token_type": "example", "expires_in": 1}unsupported_grant_type or invalid_request.
invalid_client.
temporarily_unavailable: the signing key could not be reached.