Table of Contents

TOidcClient.TokenEndpointAuthMethod Property

Gets or sets how the client authenticates at the token endpoint when ClientSecret is set.

Remarks

The default, Auto, uses client_secret_post only when the provider discovery document advertises it and not client_secret_basic; otherwise it uses client_secret_basic, the OAuth 2.0 default. Most providers advertise both methods but may accept only the one configured for the client at the provider side. If the token endpoint rejects the request with an invalid_client error, set this property to the method registered for the client. When ClientSecret is empty, only client_id is sent in the request body, regardless of this setting.

Syntax

Unit: Sphinx.OidcClient

property TOidcClient.TokenEndpointAuthMethod: TTokenEndpointAuthMethod

See also