Ga naar inhoud

Get a Self-Issued ID token (STS)

POST
/dcp/sts/token
curl --request POST \
--url https://example.com/dcp/sts/token \
--header 'Content-Type: application/x-www-form-urlencoded' \
--data grant_type=example \
--data client_id=example \
--data client_secret=example \
--data audience=example \
--data bearer_access_scope=example \
--data token=example

The Secure Token Service of the participant: OAuth 2.0 client credentials give a Self-Issued ID token for an audience, with an access token for the scopes the audience may query. For the participant’s own components, authenticated by client id and secret.

  • None
Media typeapplication/x-www-form-urlencoded

An OAuth 2.0 token request with client credentials.

object
grant_type
required

client_credentials.

string
client_id
required
string
client_secret
required
string
audience
required

The DID of the verifier the token is for.

string
bearer_access_scope

Space-separated scopes the verifier may query, e.g. org.eclipse.dspace.dcp.vc.type:MembershipCredential:read.

string | null
token

An access token from another party to embed, instead of a new one.

string | null

Example generated

grant_type=example&client_id=example&client_secret=example&audience=example&bearer_access_scope=example&token=example

OK.

Media typeapplication/json
object
access_token
required

A Self-Issued ID token of this participant for the audience.

string
token_type
required

Bearer.

string
expires_in
required
integer format: int64

Example generated

{
"access_token": "example",
"token_type": "example",
"expires_in": 1
}

unsupported_grant_type or invalid_request.

invalid_client.

temporarily_unavailable: the signing key could not be reached.