The (authentication-session, authorization-context) pair from which the token endpoint mints access, refresh and ID tokens. Produced by an IAuthorizationGrantHandler and carried through token issuance.
Represents an authorized grant result for a refresh token request. Contains the authenticated session, authorization context, and the associated refresh token.
Identity of an issued token, recorded against an authorization grant so that the token can be revoked by JTI if the grant is later invalidated (for example when an authorization code is reused).
Processes incoming token requests from clients, ensuring they are valid and authorized before issuing the appropriate token response. Depending on the request type and granted permissions, the response can include various types of tokens such as Access Tokens, Refresh Tokens and ID Tokens.
Validates an incoming OAuth 2.0 token request (RFC 6749 §3.2) against the rules required by the requested grant_type: client authentication, grant ownership (e.g. an authorization code MUST have been issued to the authenticated client per OIDC Core 1.0 §3.1.3.2), redirect URI equivalence for code exchange, scope and resource (RFC 8707) consistency, and PKCE verifier matching (RFC 7636 §4.5) where applicable.