Client
1. Identity assertion (ID-JAG)
Pre-minted stand-in for what Token Exchange against the user's IdP would produce — not part of DTR itself. Edit and re-mint to try different subjects or resources.
2. Token request
grant_type=urn:ietf:params:oauth:grant-type:jwt-bearer,
completion_mode=deferred
3. Status
idle
Authorization Server — idp.deferred-token-response.dev
Deferred request state
- status
- —
Policy (fixed for this scenario)
This resource server always requires human interaction before granting access via an ID-JAG — the client cannot know this in advance, and discovers it through the deferred response.