KEY-WP-0016 changed /token and /userinfo behaviour with no consumer-facing note; nothing in docs/ mentioned redirect_uri, so the change would have reached a deployment silently. States what an exchange must now send, who is affected and how to roll out. Every browser registration in dev-config is public with an authorization_code grant, so only the redirect_uri requirement can affect them; the realistic failure is a client that sends it to /authorize and omits it at /token, which has not been observed against a live consumer. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01NV9oijZukGyGbRQGGKnK4P Assistant: claude-code Assistant-Model: opus Assistant-Process: 713576@bnt-lap001 Assistant-Session: 384c511d-9bce-4cb8-a676-2aef6c0c8df6 |
||
|---|---|---|
| .. | ||
| adr | ||
| approval-engine-auth-contract.md | ||
| approval-engine-provisioning-request.yaml | ||
| authorization-code-bindings.md | ||
| native-authentication.md | ||
| openbao-service-auth-contract.md | ||
| qonto-runtime-identity-contract.md | ||
| tenant-claim-contract.md | ||