JwtTypes Class
The typ values this server mints for its own token kinds, and the refusal decision that
sees them. The specification-fixed vocabulary lives in the JWT core's
JsonWebTokenTypes, shared by every package on the core; what stays here is what
only this product can own - its vendor-tree values - plus the combined known set the two
vocabularies form together.
public static class JwtTypesInheritance System.Object → JwtTypes
Remarks
RFC 6838 Section 3.2 is where the prefix comes from: the vendor tree "is used for media types associated with publicly available products", and its registrations "will be distinguished by the leading facet vnd.". Names without it belong to the standards tree, where a future registration of the same word would collide with ours - and, worse for a reader, a name sitting there looks exactly as authoritative as one that was actually standardised.
Changing a prefixed value is possible but not free: it changes what an already-issued token looks like, so tokens minted before the change stop being recognised.
Fields
JwtTypes.AccessToken Field
The "AccessToken" JWT type per RFC 9068, fixed by the specification.
public const string AccessToken = "at+jwt";Field Value
JwtTypes.DPoPProof Field
The "DPoP proof" JWT type per RFC 9449 §4.2, fixed by the specification.
public const string DPoPProof = "dpop+jwt";Field Value
JwtTypes.InitialAccessToken Field
The "InitialAccessToken" JWT type is used to authorize calls to the client registration endpoint per RFC 7591 Section 3.
public const string InitialAccessToken = "vnd.abblix.iat+jwt";Field Value
Remarks
Not replaceable by AccessToken, and here the type is load-bearing on its own. Beyond it, the validator asks only for a non-empty subject that has not been revoked, so sharing a type with the access token would let any access token this server issued register clients.
JwtTypes.Jwt Field
Standard JSON Web Token type. Per RFC 7519 Section 5.1, this is the recommended value for the 'typ' header parameter.
public const string Jwt = "JWT";Field Value
JwtTypes.LogoutToken Field
The "LogoutToken" JWT type per OpenID Connect Back-Channel Logout, fixed by the specification.
public const string LogoutToken = "logout+jwt";Field Value
JwtTypes.RefreshToken Field
The "RefreshToken" JWT type is used to represent refresh tokens, which allow obtaining new access tokens without reauthentication.
public const string RefreshToken = "vnd.abblix.rt+jwt";Field Value
Remarks
Not replaceable by AccessToken, and the reason is a protection rather than a preference. A refresh token carries the resources of its grant in the audience claim, exactly as the access token of that grant does, so with a shared type nothing would separate the two and a resource server presented with a refresh token would have no ground to refuse it. There is also nowhere standard to move to: the IANA media types registry holds no entry for a refresh token, which follows from RFC 6749 Section 1.5 making it a value "intended for use only with authorization servers".
JwtTypes.RegistrationAccessToken Field
The "RegistrationAccessToken" JWT type is used in OAuth 2.0 Dynamic Client Registration for securely registering clients.
public const string RegistrationAccessToken = "vnd.abblix.dcr+jwt";Field Value
Remarks
Not replaceable by AccessToken. Its validator does ask for more - the subject must name the client being managed, and the identifier must match the one that client records - but the second of those is enforced only where a record exists, which leaves a statically configured client defended by the subject alone. An access token issued for the client itself carries that same subject, so the type is what keeps the two apart. See also InitialAccessToken, which has nothing else at all.
JwtTypes.TokenIntrospection Field
The "token introspection response" JWT type per RFC 9701 §5, fixed by the specification.
public const string TokenIntrospection = "token-introspection+jwt";Field Value
Methods
JwtTypes.IsPermitted(string, string[]) Method
Reports whether a typ is one this position permits, over the combined vocabulary of the core
registry and this server's vendor values. The decision itself - refusal by kind, with an absent,
generic or unfamiliar value passing untouched - is
IsPermitted(string, IReadOnlyList<string>, string[]); see its
remarks for why the refused side is enumerated rather than the accepted one.
public static bool IsPermitted(string? tokenType, params string[] permittedTypes);Parameters
tokenType System.String
The typ header parameter of the incoming JWT, which may be absent.
permittedTypes System.String[]
The types this position permits. Pass none where the JWT that belongs there carries no typ at
all, as an ID token does - then every known type is out of place.
Returns
System.Boolean
true for an absent, generic or unfamiliar value and for any of permittedTypes;
false only for a known type that is not among them.