-
Notifications
You must be signed in to change notification settings - Fork 1.6k
Description
Is your feature request related to a problem? Please describe.
I have a variety of internal applications which have various metadata they require when a token shows up. Specifically this is problematic for "bot" users. I have bot or service-accounts that are created by my oauth clients on behalf of a user. These "bot" tokens need to have some metadata (who created it, when it was created, etc.). Today this would require me to maintain a map of token -> metadata which means (1) I have duplication of the token and (2) I'm having to store it in a few places.
Describe the solution you'd like
Simply I'd like to be able to define claims for an access token minted through the clientcredential flow. This would enable my use-case as well as others (e.g. #1221).
Describe alternatives you've considered
As it stands today I don't use hydra/oauth for this, as it would require me to effectively duplicate al the token data.