Provides functionality to format and sign JSON Web Tokens (JWTs) specifically for use within the authentication service. This class processes tokens issued by the authentication service itself, including access tokens, refresh tokens and Registration Access Tokens generated during client registration via the dynamic registration API. It leverages signing and optional encryption to generate JWTs that authenticate and authorize internal service operations.
The encryption policy a caller hands to ClientJwtFormatter when formatting a client-addressed JWT. It makes explicit which registered client metadata governs encryption, so the formatter no longer has to infer it from the token type. Each client-JWT type (UserInfo, ID token, JARM authorization response, introspection) supplies its own policy via the static factories below.
Provides functionality to format JSON Web Tokens (JWTs) issued to clients by the authentication service. This class handles the signing of JWTs and, if configured, their encryption, based on the needs of each client.
The encryption policy a caller hands to AuthServiceJwtFormatter when formatting a JWT the server issues for itself. It is the service-side mirror of ClientJwtEncryption: it makes explicit whether the token is encrypted and, if so, to which of the server's own keys and with which algorithms, so the formatter no longer encrypts implicitly whenever any encryption key happens to exist. Each service-token type supplies its own policy via the static factories below, projected from ServiceTokens.
Serializes a JsonWebToken minted by the authorization server itself (access tokens, refresh tokens, registration access tokens, initial access tokens) into a compact JWS form (RFC 7515) using the server's signing keys, and - per an explicit ServiceJwtEncryption policy - optionally wraps the result in a JWE (RFC 7516) encrypted to the server's own encryption key.
Serializes a JWT addressed to a specific client (ID Token, Logout Token, etc.) into compact form: signed as a JWS (RFC 7515) with the server's signing key chosen by the JWT's header algorithm, then optionally wrapped in a JWE (RFC 7516) encrypted to the client's registered public key per the client's id_token_encrypted_response_alg/_enc metadata.