key-cape/docs
tegwick 0d7e2f6b41 Document the authorization-code bindings for relying parties
KEY-WP-0016 changed /token and /userinfo behaviour with no consumer-facing note;
nothing in docs/ mentioned redirect_uri, so the change would have reached a
deployment silently.

States what an exchange must now send, who is affected and how to roll out.
Every browser registration in dev-config is public with an authorization_code
grant, so only the redirect_uri requirement can affect them; the realistic
failure is a client that sends it to /authorize and omits it at /token, which
has not been observed against a live consumer.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01NV9oijZukGyGbRQGGKnK4P

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 713576@bnt-lap001
Assistant-Session: 384c511d-9bce-4cb8-a676-2aef6c0c8df6
2026-09-07 00:17:56 +02:00
..
adr feat: implement T01-T04 — Go module, canonical model, LDAP validator, error taxonomy 2026-03-13 01:27:54 +01:00
approval-engine-auth-contract.md Add bounded resource audiences and enforce browser scope grants 2026-09-05 00:41:17 +02:00
approval-engine-provisioning-request.yaml Align approval registrations to the tenant:platform decision 2026-09-06 22:30:32 +02:00
authorization-code-bindings.md Document the authorization-code bindings for relying parties 2026-09-07 00:17:56 +02:00
native-authentication.md Add native verified login and service-token commands 2026-09-05 01:08:58 +02:00
openbao-service-auth-contract.md Implement KeyCape provider and service identity contracts 2026-08-23 13:10:13 +02:00
qonto-runtime-identity-contract.md Define Qonto runtime identity contract 2026-07-26 13:34:56 +02:00
tenant-claim-contract.md Align approval registrations to the tenant:platform decision 2026-09-06 22:30:32 +02:00