Interface ResourceServerCreate

Hierarchy

  • ResourceServerCreate

Properties

allow_offline_access?: boolean

Whether refresh tokens can be issued for this API (true) or not (false).

authorization_details?: any[]
client?: object
enforce_policies?: boolean

Whether to enforce authorization policies (true) or to ignore them (false).

identifier: string

Unique identifier for the API used as the audience parameter on authorization calls. Can not be changed once set.

name?: string

Friendly name for this resource server. Can not contain < or > characters.

proof_of_possession?: null | ResourceServerProofOfPossession
scopes?: Scope[]

List of permissions (scopes) that this API uses.

Algorithm used to sign JWTs. Can be HS256 or RS256. PS256 available via addon.

signing_secret?: string

Secret used to sign tokens when using symmetric algorithms (HS256).

skip_consent_for_verifiable_first_party_clients?: boolean

Whether to skip user consent for applications flagged as first party (true) or not (false).

Dialect of issued access token. access_token is a JWT containing standard Auth0 claims; rfc9068_profile is a JWT conforming to the IETF JWT Access Token Profile. access_token_authz and rfc9068_profile_authz additionally include RBAC permissions claims.

token_encryption?: null | ResourceServerTokenEncryption
token_lifetime?: number

Expiration value (in seconds) for access tokens issued for this API from the token endpoint.