Test Summary

Test Results

Expand All Collapse All
All times are UTC
2022-12-13 15:34:22 INFO
TEST-RUNNER
Test instance uXqmOQoi1qW9UG5 created
baseUrl
https://www.certification.openid.net/test/a/fapipoc_fapi_jarm
variant
{
  "client_auth_type": "mtls",
  "fapi_auth_request_method": "by_value",
  "fapi_profile": "plain_fapi",
  "fapi_response_mode": "jarm"
}
alias
fapipoc_fapi_jarm
description
planId
BjLqJvsjmQJpP
config
{
  "alias": "fapipoc_fapi_jarm",
  "server": {
    "discoveryUrl": "https://fapipoc.rel.vanitytst.cloudidentity.ibm.com/oauth2/.well-known/openid-configuration"
  },
  "client": {
    "client_id": "d74dcd6c-cfa7-41b5-ad33-837ca6013a9c",
    "client_secret": "ZbBKKNhJPo",
    "scope": "openid email",
    "jwks": {
      "keys": [
        {
          "p": "-JkZq0-X1RAO2UtEohS_gpRIW6vXFq8f_4eldFP7qXQcHzsSfFrul14pXG7grNokcA5S3w7HSBXQXQ7WdVeN-nZSI_232NSyF3GRkiINenSUMoz8_7zKy2MUvo9gW8WkaOlMOv5l8H781ZDfQvMCNjmwb2zE4q8qNbv2ZnA_gfc",
          "kty": "RSA",
          "q": "tj8Ug4uHQnfJEXdNKCPPbUD4kPMNu4T0pAf7lUkZ4Aa56CxKds063qUvdtyPYSiTKlpdAVYibqSyLBauG_RjPDcD6zrziKO93o42mX2Fr4fZJaWFKqlAqA3fZycWyu-VDrjF14QmDUS4NPnnQ7_UuiKYr5o3hO8-iJrW8z4VQJc",
          "d": "j_TQo4CwQ9GHOy2hCJJJfV1rUVxQpWmljB4SNBcJ4cZWbMVc0qRTL9awlgIvFCYmO2H97q3CLJAjigPGNta-TCI1eEbuaTsGrLwsjUrycQz7EIZf_i9rdj3lRhJ-gLpgO2Fj6_hfQLMHQ0yhiHi09FPLpJfPpicqEHwwmwNLQGIwN88c-TDDX2D4Iw3geygigqRnWviDVMejuRL2Luordiw7XOJHzY2BGwqOZdgqYfVS6Dr6PjOaOwWDJ7w9pHT19zz3UEXiarzA-AZKSZtxOoNVSliltj0nIzhVN0fd7g0Ljt13LjrGuyLSrAoTCZdQpCZ0uX02leqFkCAOkCzWlQ",
          "e": "AQAB",
          "use": "sig",
          "kid": "fapips1",
          "qi": "sNIuSo-uVI0TrtcR_6ZdGkps2MIWmVRhqBCKDxJAm21RkW7Sv0buRD8KPSP7WA20KTgs3O9i1Hz6bD8U2Hkjt3rk6MP59JvQev1DxFD8yA_A6aaIHk6Z7BryX5QOJzj0tzIB1tVzrSViVdDg0LUOO5yZdm_IQSU4AN-aaxjrpvA",
          "dp": "NnHJVmRzGz2OEvbSDDFBFAcHpdQHojcuadc6XDS8bAs60Xgtf0Cm-k2r_0tlN1X7HvN0INfquxXT8V17iG1pcc4SBUHezsUeT9YWjIuaqhP4FO4dxqCBRXPoqidach7h9_wILu9iQf59vwQgcVgpRtjxlCWdJQw50VTeDOdOcVc",
          "alg": "PS256",
          "dq": "qwl0dShDnuvQdmXisaM6Dq0FGvQglTZoanFbeXWLpSZq3yyCDhD6CO46J3FD1sk_pGX-Fz0BP5mt5Za7fFzVrTNsqB1BZaFWlkIdl9un1V7HOn-nBKynk5DBc4vJ5lcHKzPZ6TOKirVNs9o9YuXr_Wxuo482P7pQk9_Nj6daRq0",
          "n": "sPoZ2M-WhvDJchlxahAPDtkSaRlXWIK17NF2qHn3RgWUw0Z4XyptMWi-HMwxwwwApCi_g7ytaJ4DBDo5DY-pumFZHdj4mcD8Nb2XhV5smMO3-XABBVAuNH6VW4sFeb6bvlVBNyoHpAA_4VyMCYTjZffxGIqXpyxIND1M5zwP8RaZc1_Yo4yakZa15wXirbwZkCArJaIROpKy5xXFPA_2p4w7PnTQshAqjJx2Jz8N5CKsEvUvHNEg7pfeL1hTqLk1KRpLRh8QZKwfEjuxg0KFIGmi45gAX8SCjjX-BBffN6C7VELESRzILSlCEbTL_hslQkSQNbmyqI--kWCgkTZosQ"
        }
      ]
    }
  },
  "client_secret_post": {
    "client_id": "3fec31b2-9e2a-4e2b-a72a-228a06e06729",
    "client_secret": "ZbBKKNhJPo"
  },
  "mtls": {
    "cert": "-----BEGIN CERTIFICATE-----\nMIID2TCCA36gAwIBAgIULVRuRCMrxxQ2YhrJ+h9vwtSuO/QwCgYIKoZIzj0EAwIw\ngYExCzAJBgNVBAYTAlVTMREwDwYDVQQIDAhOZXcgWW9yazE0MDIGA1UECgwrSW50\nZXJuYXRpb25hbCBCdXNpbmVzcyBNYWNoaW5lcyBDb3Jwb3JhdGlvbjEpMCcGA1UE\nAwwgSUJNIFNlY3VyaXR5IFZlcmlmeSBSZWwtSVRFIENBLTEwHhcNMjIxMjEyMDMx\nNjAwWhcNMjUxMjExMDMxNjAwWjB0MQswCQYDVQQGEwJTRzETMBEGA1UECBMKa2Nh\nMmNzci1TVDESMBAGA1UEBxMJa2NhMmNzci1MMRIwEAYDVQQKEwlrY2EyY3NyLU8x\nEzARBgNVBAsTCmtjYTJjc3ItT1UxEzARBgNVBAMTCmtjYTJjc3ItQ04wggEiMA0G\nCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDA8kHL4ANRJU2aW+r4S/5KCmYXgK5O\nBvvWlgxxwQAVvU/gn/0SoB05rdMRdf/RTQXq3LnvFu/7bA3RkjoKfti6HcD5RxFM\nm4Lo3jQ4ZtTxrNLIh609ilhkXL3SmkxNuqF0S2WX8FZ62bhxBCS7HAjVbv32ROk9\n2ARPtS5I/mTyo6W2WLmdtpC5J3W6MwMsLpgqPvYB/qo+TEhKiWb2N6XIm+a96CvR\nuhzH717U97gbR6EhkToNdsh65dZ+0TAIo58Q2ykA8tBhx/T1qk8HKr4jDRbOu/AG\n6HbsvMuKQrhOdlfc+2AnLnmmxGnLzmmIq9YlCVKO3oJZsiWfiZ+9kflLAgMBAAGj\nggETMIIBDzAOBgNVHQ8BAf8EBAMCBaAwEwYDVR0lBAwwCgYIKwYBBQUHAwIwDAYD\nVR0TAQH/BAIwADAdBgNVHQ4EFgQUar6U6YaPLwKeCPOwxzzbNeoTSpUwHwYDVR0j\nBBgwFoAUy63c0QU2r5F/Z4cdgCgXKPJk+KMwgZkGA1UdEQSBkTCBjoIPd3d3LmV4\nYW1wbGUuY29tghB0ZXN0LmV4YW1wbGUuY29tghBtYWlsLmV4YW1wbGUuY29tgg93\nd3cuZXhhbXBsZS5uZXSBE3NoYW5rYXJ2QHNnLmlibS5jb22HBMAAAgGHBMYzZP6H\nECABDbgAAAAAAAAAAAAAAAGGE2h0dHBzOi8vamtlLmNvbS9mb28wCgYIKoZIzj0E\nAwIDSQAwRgIhAKD9ml0OBpiloVebUI66xdTxEFwNMgC3BlF3RkTlDG9tAiEAgJVO\nZFa6grAMPA+yskk267DSu3cx0LBNrGlBncdDoZk\u003d\n-----END CERTIFICATE-----",
    "key": "-----BEGIN RSA PRIVATE KEY-----\nMIIEogIBAAKCAQEAwPJBy+ADUSVNmlvq+Ev+SgpmF4CuTgb71pYMccEAFb1P4J/9\nEqAdOa3TEXX/0U0F6ty57xbv+2wN0ZI6Cn7Yuh3A+UcRTJuC6N40OGbU8azSyIet\nPYpYZFy90ppMTbqhdEtll/BWetm4cQQkuxwI1W799kTpPdgET7UuSP5k8qOltli5\nnbaQuSd1ujMDLC6YKj72Af6qPkxISolm9jelyJvmvegr0bocx+9e1Pe4G0ehIZE6\nDXbIeuXWftEwCKOfENspAPLQYcf09apPByq+Iw0WzrvwBuh27LzLikK4TnZX3Ptg\nJy55psRpy85piKvWJQlSjt6CWbIln4mfvZH5SwIDAQABAoIBAGfIJtH1nXMhQHud\no2aI4a+LplxP7/GyWfWTYgAx0szetj9ZbvN8whuLPvOuZ7p51ov8y9opmU3AUjJ+\nl8+baRG6/VhX/JsbLq/5DVelIDcaQYpxSCLI7kCVjdjg+9f3Ye6+u1edg7aysz2+\n/87RBoNfHyU+7cJBFhiVmN7UTxIfONaVt+gTlW3IPb9xBCLwahIa12w+kSFk9RQZ\ngzi/kUaH20BFZDSzmJsxZSTIG0IL3KwJFM0JFBAHzc14RvAbwGozfoT494qQBVdo\nhaTiid+x7iUrDXgvU95chciL9b7262F3a6wlWO3/a6AVVckzqdgQ27YnIiEcy0s2\nsukTBTECgYEA/WJiKxvyGXYPsMu/eC5sLM5MGwDMcheru3OV1inB8yIofzviud3n\n6UXA5sS7qeDEy/sPB9yu8sWDC9+73UXwKYq3+SuEx291koFE0J3PO4sM7UdNRq5N\n1p3nKzklICbgtumZhtX9aG5wjXu6yXhFIezvnNeHJjcjipsf6iGN0fMCgYEAwvAn\nkq8lOUxcoCpLKwsWv37M9RyW2zPDixTv9Ddj1wTDnBXYlxzJ5BkL65UAGxTgoESN\n2mO/ZTk0AnOGJVyYvrDnvY88sRld2jDYK8ALilzUYSoAqAA5dR8y5qS/wAC9yyB1\nze7j65lrtIT/I7d442HCM63WDeXATEBVXByWOUkCgYAzVx7q+zOXwxs0yGPYVxem\nEHrNMeE68N7kEWx3w2g/+ljYRusOnA7kbjTCzXP03M0jQ5BtGGL+X9TIsCGhmQ0r\nbacPPqkdu9DHyZeG6aLWvrr0zPC0dJbi+IWhdWe3VwlLJpPsBSneYho+IKbdMZhY\nYmi+j9EbhiqWaA4UY44XzwKBgFFoi441eJ0iJ7h3kSarnddg8+UVCGcIigwGNWNO\n0nIUOkBv2yDYU/PfBdxfQEkPAfPMTVU7vM1gAzlW11m4/sz8Aftm2xi2mDwrk8tJ\ni0hAFi1xpg6C8XvZCJ/Lg4yCgsBWkPvsXOCiFJmxxP88es6yn7CHU1JAdXsijsNF\n6PKJAoGAZn9jiGdKVkgtnzHpArY+xxgDvV4p3PRqz5GOopcLLbvS5z1CfHRc/2Hb\n0ivNf5GlTFuHttZGIadyEqm0FVCoXlfPRq8k5SLYe120+866zZ7eQ7rb4SLm2603\nF3+Wv1gT5WD2B/9PSD/0ORo5rL4cb4qu4MBm/n0n1PHteZZaGHk\u003d\n-----END RSA PRIVATE KEY-----"
  },
  "client2": {
    "client_id": "079330e3-ac73-4a20-89e9-6af7aaeacb7b",
    "scope": "openid email",
    "jwks": {
      "keys": [
        {
          "p": "_V4SSh_YdQH3_c3zAUQ4RgxImgnYHPRZuVcfRuVztq6fHs1xI5Qcri4wSyfmcQgu-Caos_5Htu6iOrrMnA0Si8s6rsU8lzGCgBF0clQeEdUGX1YKqsTw2OrdcFhjwZWO59uBcmUXw8xw-EMlA_9x82HVKwZcPW94fRJJeUC80Pk",
          "kty": "RSA",
          "q": "jt6KCTdVQV6MLruoTlKPN9MtlLZ16TR-5GUareWhr8GGn81mto_Ua0eCZHGCnleAYzI3il66PvF4ribDXXOHhn6iBiIHph2Oge1Q73gSjdClHGrTq7EHi_yEeoPxXXD8siEplKcREsWtby8XTUktG0GaIg2XgocVpj7AEn_QewM",
          "d": "JhMR3QAhmiyBWEFvYJF7t5ohNOrRa5DWJi1sBmq_baADjt_DuEGBX3mQ2ZCHdWGjIznlqg9NuewHu1RykRujwFImBJaK5XMIdQoDDHlja3jBg-cp6swoQUBrOv0Amq-Co-qmtn5D7gaEkO4cJD1AM_ZJSKYus9k1ra3mEGPPUKiSknjICvZ4zEd28mJG_ZTMa5y_G3NrqkkjeLoej86Ru0yHLjYo3ZpXvbRspnlmAqganHVo7CjeBqW8ov2fS6hyRxPRDHfyw-fKHBcLFVqGNTw9-vfqXWfTBB4kwHmSwfJ5jF19UBenKk77eyzOcdwQeSDUKUeS5Ni6_cpvDe9HEQ",
          "e": "AQAB",
          "use": "sig",
          "kid": "fapips2",
          "qi": "jRUHNAE9Rq9slhKVJaHTDc56L040JIlc92nS1lW5tXxwT1032yjOHqvxkUafFsRl2Y_HJhNMXiZH89zk8QIGgO_-o2sOhlVYReE9HZpXaZQegicuG8Oc7AuH78EbPjeBml2ph1B4UV1r1L9EDg6C5otTMvi7AxIG5SH1nDsB8LA",
          "dp": "7hq6y2g0DnnkKWOjS_xlegbPL9uyejt0GoZygTjezr46EUN2YL4vWc1UWzzLBkxvf4stHcIIeTS3xsOHx9tNI4zAwD_hWiEQB_TfXxYIEDAGxg9hBO0Bfojxw0N9tA4t91zEwNGaTMpTHCxVm_UyjEvTfZSDmMSqEbfezpF1IFk",
          "alg": "PS256",
          "dq": "XPniZyEFcKcxH3CslVwRLElYToF3tq6dLdHGTQk18gVFsVWg1IpBuRcuemOMl7NmMCgMERaYqkHHQb6kQXrf5d0fYFJhG-_8P_3LQCyqFnSEHzw-SGvK94T8Sib3utG_AcWnI8Cd0dOnjMXeqkNHAYft4N9rjFyQ8EHCCcf4SzU",
          "n": "jWZuVs7f3z7SVFMH9tggC-wbx_JIEy59aScoFGhb64IoKt886ftpFht6_WTwJJKkMxQiPDeHUmi7xAC5TWV1OmrGOv4QKQ2P-u3wvvkFTrOUFGCVRgZl8dJ8I85StneVZXbVaQ6sJBH3x_wgtAT_KWUOrgs4Asi1QoHU1Qs1m-_lf0nkL7aYJDOBYpY9LYtj8NuNLaKSJSTjkZIabDJzTboNvDarS3YLQiS-LVJSD9svfK3HwAq9XV3-LEpNkqT6xCe1TJiOT-4taXwRTjyoZ9z_ejgjnpPL1AD7TkXgxTIpCQ6vGgq9j4YyUy5QIf9QZnA71L4Xj41WddUdy-4V6w"
        }
      ]
    }
  },
  "mtls2": {
    "cert": "-----BEGIN CERTIFICATE-----\nMIID1zCCA36gAwIBAgIUDBFNPnYtCIbXSSNasLveG4juOdEwCgYIKoZIzj0EAwIw\ngYExCzAJBgNVBAYTAlVTMREwDwYDVQQIDAhOZXcgWW9yazE0MDIGA1UECgwrSW50\nZXJuYXRpb25hbCBCdXNpbmVzcyBNYWNoaW5lcyBDb3Jwb3JhdGlvbjEpMCcGA1UE\nAwwgSUJNIFNlY3VyaXR5IFZlcmlmeSBSZWwtSVRFIENBLTEwHhcNMjIxMjEyMDMx\nODAwWhcNMjUxMjExMDMxODAwWjB0MQswCQYDVQQGEwJTRzETMBEGA1UECBMKa2Nh\nMmNzci1TVDESMBAGA1UEBxMJa2NhMmNzci1MMRIwEAYDVQQKEwlrY2EyY3NyLU8x\nEzARBgNVBAsTCmtjYTJjc3ItT1UxEzARBgNVBAMTCmtjYTJjc3ItQ04wggEiMA0G\nCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCkEkkODVEXXwznpi+9CcgwW6JY6N9d\nje83Qq0NvPOA92+cG9xg5hVy21buTD6qRMpx/nOlv0pm8VatNgGYAb/v7E9UIfC+\nUEpFSI0u1g733UUiDxXjkhSkosJc/QMYvXJYIVUnywZ0sukxvaJjs2bROPTXZy0A\nZQPxQNG4T1I16L5608ReL+xSQaA5S7UiE4wh4kXPPd4jc/QmWQ58yBa5o/ZUV6YU\nNI0IbsqSLMRl1dsk8rK5qSOTds6OZUNigoxTOz5+Q2vvhzhJxyWNlqxvxp8h4Ae3\ngrj09TKi7a7qCm0Kk4SruiXiaLcB7nzGWFcFMwGjYuBD7J00moLqHMnZAgMBAAGj\nggETMIIBDzAOBgNVHQ8BAf8EBAMCBaAwEwYDVR0lBAwwCgYIKwYBBQUHAwIwDAYD\nVR0TAQH/BAIwADAdBgNVHQ4EFgQU60qqehCXUuXd2Pn7pKWlox+HsBUwHwYDVR0j\nBBgwFoAUy63c0QU2r5F/Z4cdgCgXKPJk+KMwgZkGA1UdEQSBkTCBjoIPd3d3LmV4\nYW1wbGUuY29tghB0ZXN0LmV4YW1wbGUuY29tghBtYWlsLmV4YW1wbGUuY29tgg93\nd3cuZXhhbXBsZS5uZXSBE3NoYW5rYXJ2QHNnLmlibS5jb22HBMAAAgGHBMYzZP6H\nECABDbgAAAAAAAAAAAAAAAGGE2h0dHBzOi8vamtlLmNvbS9mb28wCgYIKoZIzj0E\nAwIDRwAwRAIgbZTf0ORGNxyWFyMT0tgE0Sx01MgcIJnP9OOJ9UxMad0CIGQB7Nrv\nrE34v62B5Wjwi8qj9Ca/taOvgQaNNLGRLcIQ\n-----END CERTIFICATE-----",
    "key": "-----BEGIN RSA PRIVATE KEY-----\nMIIEpAIBAAKCAQEApBJJDg1RF18M56YvvQnIMFuiWOjfXY3vN0KtDbzzgPdvnBvc\nYOYVcttW7kw+qkTKcf5zpb9KZvFWrTYBmAG/7+xPVCHwvlBKRUiNLtYO991FIg8V\n45IUpKLCXP0DGL1yWCFVJ8sGdLLpMb2iY7Nm0Tj012ctAGUD8UDRuE9SNei+etPE\nXi/sUkGgOUu1IhOMIeJFzz3eI3P0JlkOfMgWuaP2VFemFDSNCG7KkizEZdXbJPKy\nuakjk3bOjmVDYoKMUzs+fkNr74c4SccljZasb8afIeAHt4K49PUyou2u6gptCpOE\nq7ol4mi3Ae58xlhXBTMBo2LgQ+ydNJqC6hzJ2QIDAQABAoIBAQCH3VR9vG1QSzem\nhCm4Auexk9AmjACbujNDsYUYgUWroDreLPwbiaxtRlEAWEb0PK7gIvOlZ3i3Mlay\nbKx5Mcm9ZhRy+QAguOAn62JuTHhsrODYyWE45/kMNHN7CVGNJSQQ8tlPcIJSFO2i\ncQSORzt3OhEWZqwPTZcsKp8AXz8Wv+c7lThb/kn5x0KrghOSoD752D6snDRFIy6D\n1NziziT1ozZJc3zUnKKq/qBCV3/1/iJ8y98CgwVwxD/HvIbf7vD4nZeo+KDjhxgm\nhWq4Yd0ZpWgRII6pKitHSl45hrG8BCC3s4kSqwiJvPIz8CGUJPd0sctUnlWlVFPV\n3wnnyUeZAoGBANiIA89BZjd57tAg9Z+8COVUbAGOzglmnZ+LTonGd1BFyP3PI+us\nKo9O/JY5gMokjn+MehoaeG8ChyhQjMJFuyfAgo6V45v8RP2cgPAJXUwU8p+nSmdR\nbiU9z68NJSpxmnjMTYr92WD01Y41IZNpYF6hYtGtCsA8eVrxcj0312jPAoGBAMH6\nVroThTamv/JlA8rdPrZD1oNTUfeekKtPxIWZvlsXVQ9/ya9n0KvwqyAMcZZR2rgt\n9L5A5OkKcSuiI/KYdqssEs/SQkYuJdLyzDeyX7+HyiZfva0bqwYb5a8KPtiXxPG+\ndMQNuudXO2uqjWSEcHBZR1VIT6R1yNw6taCoePzXAoGBAICiBMlaC7RHPoTsH57e\nINbEGUmvoVzaVidSpbyZZ4YLfwSwyqEV7U6nWMyRqp3rq6/AL0VUllk0QkDD4WsD\n69QIvEaias3exsl28O4oUgGBrEUGJ+BK8sky+C8A+yREysSacjJw7XN432kUzTZ6\ncmKlM0RmrS1Yf6t0Ji6R/ujnAoGAFFlJnc2MbPZDLo9wPWjGOmKVb0NfVuWYcZA1\nonpFYNLqxmx2YOM4HcFqgjsr80P0+NtBUHAIU3YX9ybUNI/P6xb9hjWdZDVVHHMB\n/1nD95isGSh0AmPjpglpJ9qgSyJos59yKlryX3BkOGA04vWNwgtrk0O5rxv4DTpP\ncWIbBxMCgYBX7uCWmJmgB/a/CRzZsE5dwVIM15MjIM7MOAu/+OTPzVq7Gqc7Rgyy\nLItin3QjnuomAmtJ2TKilGzQj09z6hNNfijUfzY0jzgyWIlhbiVcYxlZ+956+Xyt\ncAe0FUI+7vadJNsprdASSAUvq9A2zrYyfGUkM5OfeEW9H0eWrjnCQw\u003d\u003d\n-----END RSA PRIVATE KEY-----"
  },
  "resource": {
    "resourceUrl": "https://fapipoc.rel.vanitytst.cloudidentity.ibm.com/oauth2/open-banking/v3.1/aisp/accounts"
  },
  "consent": {}
}
testName
fapi1-advanced-final-attempt-reuse-authorisation-code-after-one-second
2022-12-13 15:34:22 SUCCESS
CreateRedirectUri
Created redirect URI
redirect_uri
https://www.certification.openid.net/test/a/fapipoc_fapi_jarm/callback
2022-12-13 15:34:22
GetDynamicServerConfiguration
HTTP request
request_uri
https://fapipoc.rel.vanitytst.cloudidentity.ibm.com/oauth2/.well-known/openid-configuration
request_method
GET
request_headers
{
  "accept": "text/plain, application/json, application/*+json, */*",
  "content-length": "0"
}
request_body

                                
2022-12-13 15:34:22 RESPONSE
GetDynamicServerConfiguration
HTTP response
response_status_code
200 OK
response_status_text
OK
response_headers
{
  "x-backside-transport": "OK OK",
  "content-type": "application/json",
  "p3p": "CP\u003d\"NON CUR OTPi OUR NOR UNI\"",
  "x-frame-options": "SAMEORIGIN",
  "x-content-type-options": "nosniff",
  "cache-control": "no-cache, no-store, max-age\u003d0, must-revalidate",
  "expires": "0",
  "x-xss-protection": "1; mode\u003dblock",
  "x-correlation-id": "CORR_ID-AKc89a51bc-1633-4043-9e28-7239625f3881",
  "content-security-policy": "frame-ancestors \u0027self\u0027",
  "x-ua-compatible": "IE\u003dedge",
  "x-global-transaction-id": "efc5c28163989b7e53f7c431",
  "vary": "Accept-Encoding",
  "date": "Tue, 13 Dec 2022 15:34:22 GMT",
  "connection": "keep-alive",
  "set-cookie": [
    "CIPD-S-SESSION-ID\u003d0:1:rediscol:bWZrwKRb0osi1/6XI0SYhnsBfSjvBQTZQx5pQ1gD6UE\u003d; Path\u003d/; SameSite\u003dNone; Secure; HttpOnly",
    "CISESSIONIDREL02A\u003dPBC5YS:57871319; Path\u003d/; Domain\u003drel.vanitytst.cloudidentity.ibm.com; Secure; HttpOnly",
    "_abck\u003dB22340E2B6F0480DA7E37B1FE5B0FF3C~-1~YAAQT05OaAKwoAiFAQAAZ2cfDAkN3NZ0J3nOx6GeOj+JsHXPXIcxe5Yylbnqe0g8YxeY3kwoVBXfj+//SIAKs/ewvmVQe3vti642ebIxQKgpIKisPfBL9xhf0T/p5N3H0c+k8bV7HbsUt5g4rS5eQgg0AiIvf/FaKsoi0s0GRDQ6kDhY2uZ+bLQ7tuXn78NzmdZLrPcdMpPDE90pxbP0sCBaOulW+fRqe53zLlrbJUzvEzwjjy6CvD7bfM6eszCmB0eKfIOzOUdKCE+5BQsTNk+dN+O9xhWxTQs3hKBlnWc4UrMecKo5xCLsCwv8xwJ2EPlAbUg2ov0jUKrX7jgs6S0TPZdmwxUB2g9cYuIeWlxu4X+6mDYd1Q\u003d\u003d~-1~-1~-1; Domain\u003d.ibm.com; Path\u003d/; Expires\u003dWed, 13 Dec 2023 15:34:22 GMT; Max-Age\u003d31536000; Secure",
    "bm_sz\u003d3602660A626EB3AF0E013A9AAF0382BA~YAAQT05OaAOwoAiFAQAAZ2cfDBIWYMiF/BL09xmujHH8+JPe/ZTXrx4UBw5h3Buj2xAqC/B2RoQCNCTaNWAz0j6VAl5Xe1YfQOqXipAerxfmiAyzqUsVHtuRvyK/EjVoSj+PFpmTNDNskwdnkOHscbOT9fgdF+/oHeZyX92sU/vK3trFAZ/YerfRqYuzQa1UPDw6wK8r/egUxsF5OZlASb6C1vKzlQhB2WTe0zCZp0XCwonh6pO53nw1oPga2XBOh79fbrBIi9RkwIJxhlml6doMUPOMtoEKWPuIKWA2Wio\u003d~3355202~4277572; Domain\u003d.ibm.com; Path\u003d/; Expires\u003dTue, 13 Dec 2022 19:34:22 GMT; Max-Age\u003d14400; Secure"
  ],
  "server-timing": [
    "cdn-cache; desc\u003dMISS",
    "edge; dur\u003d231",
    "origin; dur\u003d129"
  ],
  "strict-transport-security": "max-age\u003d31536000 ; includeSubDomains"
}
response_body
{"authorization_encryption_alg_values_supported":["none","RSA-OAEP","RSA-OAEP-256"],"authorization_encryption_enc_values_supported":["none","A128GCM","A192GCM","A256GCM"],"authorization_endpoint":"https://fapipoc.rel.vanitytst.cloudidentity.ibm.com/oauth2/authorize","authorization_signing_alg_values_supported":["RS256","RS384","RS512","PS256","PS384","PS512","ES256","ES384","ES512"],"claim_types_supported":["normal"],"claims_parameter_supported":true,"claims_supported":["email","groupIds","family_name","employee_id","mobile_number","job_title","uid","given_name","name","tenantId","department","upn","preferred_username","realmName","iss","acr","sharing_duration","openbanking_intent_id"],"dpop_signing_alg_values_supported":["RS256","RS384","RS512","PS256","PS384","PS512","ES256","ES384","ES512"],"grant_types_supported":["authorization_code","implicit","password","refresh_token","client_credentials"],"id_token_encryption_alg_values_supported":["none","RSA-OAEP","RSA-OAEP-256"],"id_token_encryption_enc_values_supported":["none","A128GCM","A192GCM","A256GCM"],"id_token_signing_alg_values_supported":["RS256","RS384","RS512","PS256","PS384","PS512","ES256","ES384","ES512"],"introspection_endpoint":"https://fapipoc.rel.vanitytst.cloudidentity.ibm.com/oauth2/introspect","issuer":"https://fapipoc.rel.vanitytst.cloudidentity.ibm.com/oauth2","jwks_uri":"https://fapipoc.rel.vanitytst.cloudidentity.ibm.com/oauth2/jwks","mtls_endpoint_aliases":{"introspection_endpoint":"https://fapipoc.rel.vanitytst.cloudidentity.ibm.com/oauth2/introspect","pushed_authorization_request_endpoint":"https://fapipoc.rel.vanitytst.cloudidentity.ibm.com/oauth2/par","revocation_endpoint":"https://fapipoc.rel.vanitytst.cloudidentity.ibm.com/oauth2/revoke","token_endpoint":"https://fapipoc.rel.vanitytst.cloudidentity.ibm.com/oauth2/token"},"pushed_authorization_request_endpoint":"https://fapipoc.rel.vanitytst.cloudidentity.ibm.com/oauth2/par","registration_endpoint":"https://fapipoc.rel.vanitytst.cloudidentity.ibm.com/oauth2/register","request_object_encryption_alg_values_supported":["none","RSA-OAEP","RSA-OAEP-256"],"request_object_encryption_enc_values_supported":["none","A128GCM","A192GCM","A256GCM"],"request_object_signing_alg_values_supported":["RS256","RS384","RS512","PS256","PS384","PS512","ES256","ES384","ES512"],"request_parameter_supported":true,"request_uri_parameter_supported":true,"require_request_uri_registration":true,"response_modes_supported":["query","fragment","form_post","jwt","query.jwt","fragment.jwt","form_post.jwt"],"response_types_supported":["none","code","token","id_token","code token","code id_token","token id_token","code token id_token"],"revocation_endpoint":"https://fapipoc.rel.vanitytst.cloudidentity.ibm.com/oauth2/revoke","scopes_supported":["openid","profile","email","phone","address","accounts"],"subject_types_supported":["public"],"tls_client_certificate_bound_access_tokens":true,"token_endpoint":"https://fapipoc.rel.vanitytst.cloudidentity.ibm.com/oauth2/token","token_endpoint_auth_methods_supported":["client_secret_basic","client_secret_post","private_key_jwt","tls_client_auth"],"token_endpoint_auth_signing_alg_values_supported":["RS256","RS384","RS512","PS256","PS384","PS512","ES256","ES384","ES512"],"userinfo_encryption_alg_values_supported":["none","RSA-OAEP","RSA-OAEP-256"],"userinfo_encryption_enc_values_supported":["none","A128GCM","A192GCM","A256GCM"],"userinfo_endpoint":"https://fapipoc.rel.vanitytst.cloudidentity.ibm.com/oauth2/userinfo","userinfo_signing_alg_values_supported":["RS256","RS384","RS512","PS256","PS384","PS512","ES256","ES384","ES512"]}
2022-12-13 15:34:22 SUCCESS
GetDynamicServerConfiguration
Successfully parsed server configuration
authorization_encryption_alg_values_supported
[
  "none",
  "RSA-OAEP",
  "RSA-OAEP-256"
]
authorization_encryption_enc_values_supported
[
  "none",
  "A128GCM",
  "A192GCM",
  "A256GCM"
]
authorization_endpoint
https://fapipoc.rel.vanitytst.cloudidentity.ibm.com/oauth2/authorize
authorization_signing_alg_values_supported
[
  "RS256",
  "RS384",
  "RS512",
  "PS256",
  "PS384",
  "PS512",
  "ES256",
  "ES384",
  "ES512"
]
claim_types_supported
[
  "normal"
]
claims_parameter_supported
true
claims_supported
[
  "email",
  "groupIds",
  "family_name",
  "employee_id",
  "mobile_number",
  "job_title",
  "uid",
  "given_name",
  "name",
  "tenantId",
  "department",
  "upn",
  "preferred_username",
  "realmName",
  "iss",
  "acr",
  "sharing_duration",
  "openbanking_intent_id"
]
dpop_signing_alg_values_supported
[
  "RS256",
  "RS384",
  "RS512",
  "PS256",
  "PS384",
  "PS512",
  "ES256",
  "ES384",
  "ES512"
]
grant_types_supported
[
  "authorization_code",
  "implicit",
  "password",
  "refresh_token",
  "client_credentials"
]
id_token_encryption_alg_values_supported
[
  "none",
  "RSA-OAEP",
  "RSA-OAEP-256"
]
id_token_encryption_enc_values_supported
[
  "none",
  "A128GCM",
  "A192GCM",
  "A256GCM"
]
id_token_signing_alg_values_supported
[
  "RS256",
  "RS384",
  "RS512",
  "PS256",
  "PS384",
  "PS512",
  "ES256",
  "ES384",
  "ES512"
]
introspection_endpoint
https://fapipoc.rel.vanitytst.cloudidentity.ibm.com/oauth2/introspect
issuer
https://fapipoc.rel.vanitytst.cloudidentity.ibm.com/oauth2
jwks_uri
https://fapipoc.rel.vanitytst.cloudidentity.ibm.com/oauth2/jwks
mtls_endpoint_aliases
{
  "introspection_endpoint": "https://fapipoc.rel.vanitytst.cloudidentity.ibm.com/oauth2/introspect",
  "pushed_authorization_request_endpoint": "https://fapipoc.rel.vanitytst.cloudidentity.ibm.com/oauth2/par",
  "revocation_endpoint": "https://fapipoc.rel.vanitytst.cloudidentity.ibm.com/oauth2/revoke",
  "token_endpoint": "https://fapipoc.rel.vanitytst.cloudidentity.ibm.com/oauth2/token"
}
pushed_authorization_request_endpoint
https://fapipoc.rel.vanitytst.cloudidentity.ibm.com/oauth2/par
registration_endpoint
https://fapipoc.rel.vanitytst.cloudidentity.ibm.com/oauth2/register
request_object_encryption_alg_values_supported
[
  "none",
  "RSA-OAEP",
  "RSA-OAEP-256"
]
request_object_encryption_enc_values_supported
[
  "none",
  "A128GCM",
  "A192GCM",
  "A256GCM"
]
request_object_signing_alg_values_supported
[
  "RS256",
  "RS384",
  "RS512",
  "PS256",
  "PS384",
  "PS512",
  "ES256",
  "ES384",
  "ES512"
]
request_parameter_supported
true
request_uri_parameter_supported
true
require_request_uri_registration
true
response_modes_supported
[
  "query",
  "fragment",
  "form_post",
  "jwt",
  "query.jwt",
  "fragment.jwt",
  "form_post.jwt"
]
response_types_supported
[
  "none",
  "code",
  "token",
  "id_token",
  "code token",
  "code id_token",
  "token id_token",
  "code token id_token"
]
revocation_endpoint
https://fapipoc.rel.vanitytst.cloudidentity.ibm.com/oauth2/revoke
scopes_supported
[
  "openid",
  "profile",
  "email",
  "phone",
  "address",
  "accounts"
]
subject_types_supported
[
  "public"
]
tls_client_certificate_bound_access_tokens
true
token_endpoint
https://fapipoc.rel.vanitytst.cloudidentity.ibm.com/oauth2/token
token_endpoint_auth_methods_supported
[
  "client_secret_basic",
  "client_secret_post",
  "private_key_jwt",
  "tls_client_auth"
]
token_endpoint_auth_signing_alg_values_supported
[
  "RS256",
  "RS384",
  "RS512",
  "PS256",
  "PS384",
  "PS512",
  "ES256",
  "ES384",
  "ES512"
]
userinfo_encryption_alg_values_supported
[
  "none",
  "RSA-OAEP",
  "RSA-OAEP-256"
]
userinfo_encryption_enc_values_supported
[
  "none",
  "A128GCM",
  "A192GCM",
  "A256GCM"
]
userinfo_endpoint
https://fapipoc.rel.vanitytst.cloudidentity.ibm.com/oauth2/userinfo
userinfo_signing_alg_values_supported
[
  "RS256",
  "RS384",
  "RS512",
  "PS256",
  "PS384",
  "PS512",
  "ES256",
  "ES384",
  "ES512"
]
2022-12-13 15:34:22 SUCCESS
AddMTLSEndpointAliasesToEnvironment
Added mtls_endpoint_aliases to environment
2022-12-13 15:34:22 SUCCESS
CheckServerConfiguration
Found required server configuration keys
required
[
  "authorization_endpoint",
  "token_endpoint",
  "issuer"
]
2022-12-13 15:34:22
FetchServerKeys
Fetching server key
jwks_uri
https://fapipoc.rel.vanitytst.cloudidentity.ibm.com/oauth2/jwks
2022-12-13 15:34:22
FetchServerKeys
HTTP request
request_uri
https://fapipoc.rel.vanitytst.cloudidentity.ibm.com/oauth2/jwks
request_method
GET
request_headers
{
  "accept": "text/plain, application/json, application/*+json, */*",
  "content-length": "0"
}
request_body

                                
2022-12-13 15:34:23 RESPONSE
FetchServerKeys
HTTP response
response_status_code
200 OK
response_status_text
OK
response_headers
{
  "x-backside-transport": "OK OK",
  "content-type": "application/json",
  "p3p": "CP\u003d\"NON CUR OTPi OUR NOR UNI\"",
  "x-frame-options": "SAMEORIGIN",
  "x-content-type-options": "nosniff",
  "cache-control": "no-cache, no-store, max-age\u003d0, must-revalidate",
  "expires": "0",
  "x-xss-protection": "1; mode\u003dblock",
  "x-correlation-id": "CORR_ID-AK6a310a4f-7748-4e25-adc9-8c8fefe3480e",
  "content-security-policy": "frame-ancestors \u0027self\u0027",
  "x-ua-compatible": "IE\u003dedge",
  "x-global-transaction-id": "efc5c28163989b7f53f7c461",
  "vary": "Accept-Encoding",
  "date": "Tue, 13 Dec 2022 15:34:23 GMT",
  "connection": "keep-alive",
  "set-cookie": [
    "CIPD-S-SESSION-ID\u003d0:1:rediscol:CC/UG8s/JrnjGhezwPZrLycesc7O45clMNhj8M3ihD8\u003d; Path\u003d/; SameSite\u003dNone; Secure; HttpOnly",
    "CISESSIONIDREL02A\u003dPBC5YS:61017047; Path\u003d/; Domain\u003drel.vanitytst.cloudidentity.ibm.com; Secure; HttpOnly",
    "_abck\u003d6D6A5BD654669AAAB0493191DA1B074F~-1~YAAQT05OaFawoAiFAQAAkGgfDAkNIAQEdceK8/Davk8jbF1CBsNmwNUulAINN0kMfRK7eP9TQLZ7e1gFxYKYR6iBsZ2ODhCnVJAhhSvlj5+UfJvcsWeRhPvLj+iuByz9XA4bqaa2vY9eP92hdOo7AFM1zKTVQtubzqOdFRPAPaaMwFYJ0ufUeISYj56uNLhq803KdqCiGaS31A/r+6yY4w1uEuSVN9NxR884XqaiAo3KRznCx52j/DC3Wve05+gqM5hpwi+sszGQjDBt3JH02fZlN0mgitWdMqLxBREoVxX2uO2/rX9bbwKCB9ly1A52t7wyn3Gx/j735gLJ+i5Yws1hCiVZJwSApTTn0qlOrG+zQZCvZEv/YA\u003d\u003d~-1~-1~-1; Domain\u003d.ibm.com; Path\u003d/; Expires\u003dWed, 13 Dec 2023 15:34:23 GMT; Max-Age\u003d31536000; Secure",
    "bm_sz\u003dEFBE76CFDAB849D74F521F0C0F9B9098~YAAQT05OaFewoAiFAQAAkGgfDBJwceoeTbpt7yUgXz8BiSiHmZRk+4XvhuZNSzX5/l9BwkHMV3hLbEwGIvf/n8VAH1S12dIw/AN1TQjjE8HiiVoAua/x8BMPQg42sdIWmn2/bpbVXbeosmm20ogwdnIBwPi5XtatZpLyMZhSC5UoSfDn8OrcPoCcsJVrs3GnK81xyu8hBmHAEtJ8F7tpDOz9fWBy+qzcOK1+6GxP0uf4HVkyirwkivbsx/LWHodNVlsgfQXpzEyvkIZ53YyMbPu4C6jNagbfDM2WJE2HccI\u003d~3355202~4277572; Domain\u003d.ibm.com; Path\u003d/; Expires\u003dTue, 13 Dec 2022 19:34:22 GMT; Max-Age\u003d14399; Secure"
  ],
  "server-timing": [
    "cdn-cache; desc\u003dMISS",
    "edge; dur\u003d81",
    "origin; dur\u003d114"
  ],
  "strict-transport-security": "max-age\u003d31536000 ; includeSubDomains"
}
response_body
{"keys":[{"kid":"server","kty":"RSA","use":"sig","x5c":["MIIDYDCCAkigAwIBAgIEIFW8uDANBgkqhkiG9w0BAQsFADByMQkwBwYDVQQGEwAxCTAHBgNVBAgTADEJMAcGA1UEBxMAMQkwBwYDVQQKEwAxCTAHBgNVBAsTADE5MDcGA1UEAxMwb2lkYy1jb25mb3JtYW5jZS5yZWwudmVyaWZ5LmlibWNsb3Vkc2VjdXJpdHkuY29tMB4XDTIyMTExNDA0NDI0MFoXDTMyMTExMTA0NDI0MFowcjEJMAcGA1UEBhMAMQkwBwYDVQQIEwAxCTAHBgNVBAcTADEJMAcGA1UEChMAMQkwBwYDVQQLEwAxOTA3BgNVBAMTMG9pZGMtY29uZm9ybWFuY2UucmVsLnZlcmlmeS5pYm1jbG91ZHNlY3VyaXR5LmNvbTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBALBtmxl55OH/ceueSG0bRucWkdCLybhWwz+x9J6IOb8Q89d4lcd7xhdkN+9nYEjqQMDrUEFDj2ajikKlxrJk7tZSkbu5skFuxHUETDhjHBqnNQb1jwhAdYzBPFTyQ9Ii7lm0uYTthnBJKvpvjKPoz7H9Vuu15RNDujq7RF6sDGSIJUTaxbx7EM2Xv37iqfSAjaMCvfLelacNHUfCAoyGeJYXCIOnlg2/KdfoN4QHKw9Dwq12Br2vau/TcvbD8Na4b+Mm/NEf00wFjt+MtbMCDyUFMQbsAuAk2eFS3eABb1VOQ9ZZOOcsXwB4nRewWIVVhJyMEixDXxm73G9oJBUpI6sCAwEAATANBgkqhkiG9w0BAQsFAAOCAQEAhvvrczfcb1xsYJeEiVtctWlLfHXyKkfyJpIU1nTGdKpd18tPv4OeLMyuJsOFenhJD95UauFwz3AT1zdHShp04JHWTtkb7aezFN4C9fpb97BUR0BheoYzkC6pgZ7M4QkkKE/AKYZfWLahqcbZ6ICmUfXyDJ2mWpXLpLm+l6jh32NF74ho8h4b65cMpDk5mFEp9vf1WgnmaWGtFjVuhAgaS8IrYcDy3DzVrZX/0kCPa0EXng7Xx1IkhUaKz0ajx3ZCmC6HmNa6U+oDKboGq7w1ZfscjOr8nB9M0f5BUAQN1m0nGAR1Ac96BMjfwwS/05lpPLF3Dv5CzOGLuIi0Cws7xA=="],"x5t#S256":"PVCDmVgwC-YE7Q8Bfe_9jJ8izpYjwStjUEYZEe-58Y4","n":"sG2bGXnk4f9x655IbRtG5xaR0IvJuFbDP7H0nog5vxDz13iVx3vGF2Q372dgSOpAwOtQQUOPZqOKQqXGsmTu1lKRu7myQW7EdQRMOGMcGqc1BvWPCEB1jME8VPJD0iLuWbS5hO2GcEkq-m-Mo-jPsf1W67XlE0O6OrtEXqwMZIglRNrFvHsQzZe_fuKp9ICNowK98t6Vpw0dR8ICjIZ4lhcIg6eWDb8p1-g3hAcrD0PCrXYGva9q79Ny9sPw1rhv4yb80R_TTAWO34y1swIPJQUxBuwC4CTZ4VLd4AFvVU5D1lk45yxfAHidF7BYhVWEnIwSLENfGbvcb2gkFSkjqw","e":"AQAB"}]}
2022-12-13 15:34:23
FetchServerKeys
Found JWK set string
jwk_string
{"keys":[{"kid":"server","kty":"RSA","use":"sig","x5c":["MIIDYDCCAkigAwIBAgIEIFW8uDANBgkqhkiG9w0BAQsFADByMQkwBwYDVQQGEwAxCTAHBgNVBAgTADEJMAcGA1UEBxMAMQkwBwYDVQQKEwAxCTAHBgNVBAsTADE5MDcGA1UEAxMwb2lkYy1jb25mb3JtYW5jZS5yZWwudmVyaWZ5LmlibWNsb3Vkc2VjdXJpdHkuY29tMB4XDTIyMTExNDA0NDI0MFoXDTMyMTExMTA0NDI0MFowcjEJMAcGA1UEBhMAMQkwBwYDVQQIEwAxCTAHBgNVBAcTADEJMAcGA1UEChMAMQkwBwYDVQQLEwAxOTA3BgNVBAMTMG9pZGMtY29uZm9ybWFuY2UucmVsLnZlcmlmeS5pYm1jbG91ZHNlY3VyaXR5LmNvbTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBALBtmxl55OH/ceueSG0bRucWkdCLybhWwz+x9J6IOb8Q89d4lcd7xhdkN+9nYEjqQMDrUEFDj2ajikKlxrJk7tZSkbu5skFuxHUETDhjHBqnNQb1jwhAdYzBPFTyQ9Ii7lm0uYTthnBJKvpvjKPoz7H9Vuu15RNDujq7RF6sDGSIJUTaxbx7EM2Xv37iqfSAjaMCvfLelacNHUfCAoyGeJYXCIOnlg2/KdfoN4QHKw9Dwq12Br2vau/TcvbD8Na4b+Mm/NEf00wFjt+MtbMCDyUFMQbsAuAk2eFS3eABb1VOQ9ZZOOcsXwB4nRewWIVVhJyMEixDXxm73G9oJBUpI6sCAwEAATANBgkqhkiG9w0BAQsFAAOCAQEAhvvrczfcb1xsYJeEiVtctWlLfHXyKkfyJpIU1nTGdKpd18tPv4OeLMyuJsOFenhJD95UauFwz3AT1zdHShp04JHWTtkb7aezFN4C9fpb97BUR0BheoYzkC6pgZ7M4QkkKE/AKYZfWLahqcbZ6ICmUfXyDJ2mWpXLpLm+l6jh32NF74ho8h4b65cMpDk5mFEp9vf1WgnmaWGtFjVuhAgaS8IrYcDy3DzVrZX/0kCPa0EXng7Xx1IkhUaKz0ajx3ZCmC6HmNa6U+oDKboGq7w1ZfscjOr8nB9M0f5BUAQN1m0nGAR1Ac96BMjfwwS/05lpPLF3Dv5CzOGLuIi0Cws7xA=="],"x5t#S256":"PVCDmVgwC-YE7Q8Bfe_9jJ8izpYjwStjUEYZEe-58Y4","n":"sG2bGXnk4f9x655IbRtG5xaR0IvJuFbDP7H0nog5vxDz13iVx3vGF2Q372dgSOpAwOtQQUOPZqOKQqXGsmTu1lKRu7myQW7EdQRMOGMcGqc1BvWPCEB1jME8VPJD0iLuWbS5hO2GcEkq-m-Mo-jPsf1W67XlE0O6OrtEXqwMZIglRNrFvHsQzZe_fuKp9ICNowK98t6Vpw0dR8ICjIZ4lhcIg6eWDb8p1-g3hAcrD0PCrXYGva9q79Ny9sPw1rhv4yb80R_TTAWO34y1swIPJQUxBuwC4CTZ4VLd4AFvVU5D1lk45yxfAHidF7BYhVWEnIwSLENfGbvcb2gkFSkjqw","e":"AQAB"}]}
2022-12-13 15:34:23 SUCCESS
FetchServerKeys
Found server JWK set
server_jwks
{
  "keys": [
    {
      "kid": "server",
      "kty": "RSA",
      "use": "sig",
      "x5c": [
        "MIIDYDCCAkigAwIBAgIEIFW8uDANBgkqhkiG9w0BAQsFADByMQkwBwYDVQQGEwAxCTAHBgNVBAgTADEJMAcGA1UEBxMAMQkwBwYDVQQKEwAxCTAHBgNVBAsTADE5MDcGA1UEAxMwb2lkYy1jb25mb3JtYW5jZS5yZWwudmVyaWZ5LmlibWNsb3Vkc2VjdXJpdHkuY29tMB4XDTIyMTExNDA0NDI0MFoXDTMyMTExMTA0NDI0MFowcjEJMAcGA1UEBhMAMQkwBwYDVQQIEwAxCTAHBgNVBAcTADEJMAcGA1UEChMAMQkwBwYDVQQLEwAxOTA3BgNVBAMTMG9pZGMtY29uZm9ybWFuY2UucmVsLnZlcmlmeS5pYm1jbG91ZHNlY3VyaXR5LmNvbTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBALBtmxl55OH/ceueSG0bRucWkdCLybhWwz+x9J6IOb8Q89d4lcd7xhdkN+9nYEjqQMDrUEFDj2ajikKlxrJk7tZSkbu5skFuxHUETDhjHBqnNQb1jwhAdYzBPFTyQ9Ii7lm0uYTthnBJKvpvjKPoz7H9Vuu15RNDujq7RF6sDGSIJUTaxbx7EM2Xv37iqfSAjaMCvfLelacNHUfCAoyGeJYXCIOnlg2/KdfoN4QHKw9Dwq12Br2vau/TcvbD8Na4b+Mm/NEf00wFjt+MtbMCDyUFMQbsAuAk2eFS3eABb1VOQ9ZZOOcsXwB4nRewWIVVhJyMEixDXxm73G9oJBUpI6sCAwEAATANBgkqhkiG9w0BAQsFAAOCAQEAhvvrczfcb1xsYJeEiVtctWlLfHXyKkfyJpIU1nTGdKpd18tPv4OeLMyuJsOFenhJD95UauFwz3AT1zdHShp04JHWTtkb7aezFN4C9fpb97BUR0BheoYzkC6pgZ7M4QkkKE/AKYZfWLahqcbZ6ICmUfXyDJ2mWpXLpLm+l6jh32NF74ho8h4b65cMpDk5mFEp9vf1WgnmaWGtFjVuhAgaS8IrYcDy3DzVrZX/0kCPa0EXng7Xx1IkhUaKz0ajx3ZCmC6HmNa6U+oDKboGq7w1ZfscjOr8nB9M0f5BUAQN1m0nGAR1Ac96BMjfwwS/05lpPLF3Dv5CzOGLuIi0Cws7xA\u003d\u003d"
      ],
      "x5t#S256": "PVCDmVgwC-YE7Q8Bfe_9jJ8izpYjwStjUEYZEe-58Y4",
      "n": "sG2bGXnk4f9x655IbRtG5xaR0IvJuFbDP7H0nog5vxDz13iVx3vGF2Q372dgSOpAwOtQQUOPZqOKQqXGsmTu1lKRu7myQW7EdQRMOGMcGqc1BvWPCEB1jME8VPJD0iLuWbS5hO2GcEkq-m-Mo-jPsf1W67XlE0O6OrtEXqwMZIglRNrFvHsQzZe_fuKp9ICNowK98t6Vpw0dR8ICjIZ4lhcIg6eWDb8p1-g3hAcrD0PCrXYGva9q79Ny9sPw1rhv4yb80R_TTAWO34y1swIPJQUxBuwC4CTZ4VLd4AFvVU5D1lk45yxfAHidF7BYhVWEnIwSLENfGbvcb2gkFSkjqw",
      "e": "AQAB"
    }
  ]
}
2022-12-13 15:34:23 SUCCESS
CheckServerKeysIsValid
Server JWKs is valid
server_jwks
{
  "keys": [
    {
      "kid": "server",
      "kty": "RSA",
      "use": "sig",
      "x5c": [
        "MIIDYDCCAkigAwIBAgIEIFW8uDANBgkqhkiG9w0BAQsFADByMQkwBwYDVQQGEwAxCTAHBgNVBAgTADEJMAcGA1UEBxMAMQkwBwYDVQQKEwAxCTAHBgNVBAsTADE5MDcGA1UEAxMwb2lkYy1jb25mb3JtYW5jZS5yZWwudmVyaWZ5LmlibWNsb3Vkc2VjdXJpdHkuY29tMB4XDTIyMTExNDA0NDI0MFoXDTMyMTExMTA0NDI0MFowcjEJMAcGA1UEBhMAMQkwBwYDVQQIEwAxCTAHBgNVBAcTADEJMAcGA1UEChMAMQkwBwYDVQQLEwAxOTA3BgNVBAMTMG9pZGMtY29uZm9ybWFuY2UucmVsLnZlcmlmeS5pYm1jbG91ZHNlY3VyaXR5LmNvbTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBALBtmxl55OH/ceueSG0bRucWkdCLybhWwz+x9J6IOb8Q89d4lcd7xhdkN+9nYEjqQMDrUEFDj2ajikKlxrJk7tZSkbu5skFuxHUETDhjHBqnNQb1jwhAdYzBPFTyQ9Ii7lm0uYTthnBJKvpvjKPoz7H9Vuu15RNDujq7RF6sDGSIJUTaxbx7EM2Xv37iqfSAjaMCvfLelacNHUfCAoyGeJYXCIOnlg2/KdfoN4QHKw9Dwq12Br2vau/TcvbD8Na4b+Mm/NEf00wFjt+MtbMCDyUFMQbsAuAk2eFS3eABb1VOQ9ZZOOcsXwB4nRewWIVVhJyMEixDXxm73G9oJBUpI6sCAwEAATANBgkqhkiG9w0BAQsFAAOCAQEAhvvrczfcb1xsYJeEiVtctWlLfHXyKkfyJpIU1nTGdKpd18tPv4OeLMyuJsOFenhJD95UauFwz3AT1zdHShp04JHWTtkb7aezFN4C9fpb97BUR0BheoYzkC6pgZ7M4QkkKE/AKYZfWLahqcbZ6ICmUfXyDJ2mWpXLpLm+l6jh32NF74ho8h4b65cMpDk5mFEp9vf1WgnmaWGtFjVuhAgaS8IrYcDy3DzVrZX/0kCPa0EXng7Xx1IkhUaKz0ajx3ZCmC6HmNa6U+oDKboGq7w1ZfscjOr8nB9M0f5BUAQN1m0nGAR1Ac96BMjfwwS/05lpPLF3Dv5CzOGLuIi0Cws7xA\u003d\u003d"
      ],
      "x5t#S256": "PVCDmVgwC-YE7Q8Bfe_9jJ8izpYjwStjUEYZEe-58Y4",
      "n": "sG2bGXnk4f9x655IbRtG5xaR0IvJuFbDP7H0nog5vxDz13iVx3vGF2Q372dgSOpAwOtQQUOPZqOKQqXGsmTu1lKRu7myQW7EdQRMOGMcGqc1BvWPCEB1jME8VPJD0iLuWbS5hO2GcEkq-m-Mo-jPsf1W67XlE0O6OrtEXqwMZIglRNrFvHsQzZe_fuKp9ICNowK98t6Vpw0dR8ICjIZ4lhcIg6eWDb8p1-g3hAcrD0PCrXYGva9q79Ny9sPw1rhv4yb80R_TTAWO34y1swIPJQUxBuwC4CTZ4VLd4AFvVU5D1lk45yxfAHidF7BYhVWEnIwSLENfGbvcb2gkFSkjqw",
      "e": "AQAB"
    }
  ]
}
2022-12-13 15:34:23 SUCCESS
ValidateServerJWKs
Valid server JWKs: keys are valid JSON, contain the required fields and are correctly encoded using unpadded base64url
2022-12-13 15:34:23 SUCCESS
CheckForKeyIdInServerJWKs
All keys contain kids
2022-12-13 15:34:23 SUCCESS
EnsureServerJwksDoesNotContainPrivateOrSymmetricKeys
Jwks does not contain any private or symmetric keys
2022-12-13 15:34:23 SUCCESS
FAPIEnsureMinimumServerKeyLength
Validated minimum key lengths for server_jwks
server_jwks
{
  "keys": [
    {
      "kid": "server",
      "kty": "RSA",
      "use": "sig",
      "x5c": [
        "MIIDYDCCAkigAwIBAgIEIFW8uDANBgkqhkiG9w0BAQsFADByMQkwBwYDVQQGEwAxCTAHBgNVBAgTADEJMAcGA1UEBxMAMQkwBwYDVQQKEwAxCTAHBgNVBAsTADE5MDcGA1UEAxMwb2lkYy1jb25mb3JtYW5jZS5yZWwudmVyaWZ5LmlibWNsb3Vkc2VjdXJpdHkuY29tMB4XDTIyMTExNDA0NDI0MFoXDTMyMTExMTA0NDI0MFowcjEJMAcGA1UEBhMAMQkwBwYDVQQIEwAxCTAHBgNVBAcTADEJMAcGA1UEChMAMQkwBwYDVQQLEwAxOTA3BgNVBAMTMG9pZGMtY29uZm9ybWFuY2UucmVsLnZlcmlmeS5pYm1jbG91ZHNlY3VyaXR5LmNvbTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBALBtmxl55OH/ceueSG0bRucWkdCLybhWwz+x9J6IOb8Q89d4lcd7xhdkN+9nYEjqQMDrUEFDj2ajikKlxrJk7tZSkbu5skFuxHUETDhjHBqnNQb1jwhAdYzBPFTyQ9Ii7lm0uYTthnBJKvpvjKPoz7H9Vuu15RNDujq7RF6sDGSIJUTaxbx7EM2Xv37iqfSAjaMCvfLelacNHUfCAoyGeJYXCIOnlg2/KdfoN4QHKw9Dwq12Br2vau/TcvbD8Na4b+Mm/NEf00wFjt+MtbMCDyUFMQbsAuAk2eFS3eABb1VOQ9ZZOOcsXwB4nRewWIVVhJyMEixDXxm73G9oJBUpI6sCAwEAATANBgkqhkiG9w0BAQsFAAOCAQEAhvvrczfcb1xsYJeEiVtctWlLfHXyKkfyJpIU1nTGdKpd18tPv4OeLMyuJsOFenhJD95UauFwz3AT1zdHShp04JHWTtkb7aezFN4C9fpb97BUR0BheoYzkC6pgZ7M4QkkKE/AKYZfWLahqcbZ6ICmUfXyDJ2mWpXLpLm+l6jh32NF74ho8h4b65cMpDk5mFEp9vf1WgnmaWGtFjVuhAgaS8IrYcDy3DzVrZX/0kCPa0EXng7Xx1IkhUaKz0ajx3ZCmC6HmNa6U+oDKboGq7w1ZfscjOr8nB9M0f5BUAQN1m0nGAR1Ac96BMjfwwS/05lpPLF3Dv5CzOGLuIi0Cws7xA\u003d\u003d"
      ],
      "x5t#S256": "PVCDmVgwC-YE7Q8Bfe_9jJ8izpYjwStjUEYZEe-58Y4",
      "n": "sG2bGXnk4f9x655IbRtG5xaR0IvJuFbDP7H0nog5vxDz13iVx3vGF2Q372dgSOpAwOtQQUOPZqOKQqXGsmTu1lKRu7myQW7EdQRMOGMcGqc1BvWPCEB1jME8VPJD0iLuWbS5hO2GcEkq-m-Mo-jPsf1W67XlE0O6OrtEXqwMZIglRNrFvHsQzZe_fuKp9ICNowK98t6Vpw0dR8ICjIZ4lhcIg6eWDb8p1-g3hAcrD0PCrXYGva9q79Ny9sPw1rhv4yb80R_TTAWO34y1swIPJQUxBuwC4CTZ4VLd4AFvVU5D1lk45yxfAHidF7BYhVWEnIwSLENfGbvcb2gkFSkjqw",
      "e": "AQAB"
    }
  ]
}
2022-12-13 15:34:23 SUCCESS
GetStaticClientConfiguration
Found a static client object
client_id
d74dcd6c-cfa7-41b5-ad33-837ca6013a9c
client_secret
ZbBKKNhJPo
scope
openid email
jwks
{
  "keys": [
    {
      "p": "-JkZq0-X1RAO2UtEohS_gpRIW6vXFq8f_4eldFP7qXQcHzsSfFrul14pXG7grNokcA5S3w7HSBXQXQ7WdVeN-nZSI_232NSyF3GRkiINenSUMoz8_7zKy2MUvo9gW8WkaOlMOv5l8H781ZDfQvMCNjmwb2zE4q8qNbv2ZnA_gfc",
      "kty": "RSA",
      "q": "tj8Ug4uHQnfJEXdNKCPPbUD4kPMNu4T0pAf7lUkZ4Aa56CxKds063qUvdtyPYSiTKlpdAVYibqSyLBauG_RjPDcD6zrziKO93o42mX2Fr4fZJaWFKqlAqA3fZycWyu-VDrjF14QmDUS4NPnnQ7_UuiKYr5o3hO8-iJrW8z4VQJc",
      "d": "j_TQo4CwQ9GHOy2hCJJJfV1rUVxQpWmljB4SNBcJ4cZWbMVc0qRTL9awlgIvFCYmO2H97q3CLJAjigPGNta-TCI1eEbuaTsGrLwsjUrycQz7EIZf_i9rdj3lRhJ-gLpgO2Fj6_hfQLMHQ0yhiHi09FPLpJfPpicqEHwwmwNLQGIwN88c-TDDX2D4Iw3geygigqRnWviDVMejuRL2Luordiw7XOJHzY2BGwqOZdgqYfVS6Dr6PjOaOwWDJ7w9pHT19zz3UEXiarzA-AZKSZtxOoNVSliltj0nIzhVN0fd7g0Ljt13LjrGuyLSrAoTCZdQpCZ0uX02leqFkCAOkCzWlQ",
      "e": "AQAB",
      "use": "sig",
      "kid": "fapips1",
      "qi": "sNIuSo-uVI0TrtcR_6ZdGkps2MIWmVRhqBCKDxJAm21RkW7Sv0buRD8KPSP7WA20KTgs3O9i1Hz6bD8U2Hkjt3rk6MP59JvQev1DxFD8yA_A6aaIHk6Z7BryX5QOJzj0tzIB1tVzrSViVdDg0LUOO5yZdm_IQSU4AN-aaxjrpvA",
      "dp": "NnHJVmRzGz2OEvbSDDFBFAcHpdQHojcuadc6XDS8bAs60Xgtf0Cm-k2r_0tlN1X7HvN0INfquxXT8V17iG1pcc4SBUHezsUeT9YWjIuaqhP4FO4dxqCBRXPoqidach7h9_wILu9iQf59vwQgcVgpRtjxlCWdJQw50VTeDOdOcVc",
      "alg": "PS256",
      "dq": "qwl0dShDnuvQdmXisaM6Dq0FGvQglTZoanFbeXWLpSZq3yyCDhD6CO46J3FD1sk_pGX-Fz0BP5mt5Za7fFzVrTNsqB1BZaFWlkIdl9un1V7HOn-nBKynk5DBc4vJ5lcHKzPZ6TOKirVNs9o9YuXr_Wxuo482P7pQk9_Nj6daRq0",
      "n": "sPoZ2M-WhvDJchlxahAPDtkSaRlXWIK17NF2qHn3RgWUw0Z4XyptMWi-HMwxwwwApCi_g7ytaJ4DBDo5DY-pumFZHdj4mcD8Nb2XhV5smMO3-XABBVAuNH6VW4sFeb6bvlVBNyoHpAA_4VyMCYTjZffxGIqXpyxIND1M5zwP8RaZc1_Yo4yakZa15wXirbwZkCArJaIROpKy5xXFPA_2p4w7PnTQshAqjJx2Jz8N5CKsEvUvHNEg7pfeL1hTqLk1KRpLRh8QZKwfEjuxg0KFIGmi45gAX8SCjjX-BBffN6C7VELESRzILSlCEbTL_hslQkSQNbmyqI--kWCgkTZosQ"
    }
  ]
}
2022-12-13 15:34:23
ValidateMTLSCertificatesHeader
No certificate authority found for MTLS
2022-12-13 15:34:23 SUCCESS
ValidateMTLSCertificatesHeader
MTLS certificates header is valid
2022-12-13 15:34:23
ExtractMTLSCertificatesFromConfiguration
No certificate authority found for MTLS
2022-12-13 15:34:23 SUCCESS
ExtractMTLSCertificatesFromConfiguration
Mutual TLS authentication credentials loaded
cert
MIID2TCCA36gAwIBAgIULVRuRCMrxxQ2YhrJ+h9vwtSuO/QwCgYIKoZIzj0EAwIwgYExCzAJBgNVBAYTAlVTMREwDwYDVQQIDAhOZXcgWW9yazE0MDIGA1UECgwrSW50ZXJuYXRpb25hbCBCdXNpbmVzcyBNYWNoaW5lcyBDb3Jwb3JhdGlvbjEpMCcGA1UEAwwgSUJNIFNlY3VyaXR5IFZlcmlmeSBSZWwtSVRFIENBLTEwHhcNMjIxMjEyMDMxNjAwWhcNMjUxMjExMDMxNjAwWjB0MQswCQYDVQQGEwJTRzETMBEGA1UECBMKa2NhMmNzci1TVDESMBAGA1UEBxMJa2NhMmNzci1MMRIwEAYDVQQKEwlrY2EyY3NyLU8xEzARBgNVBAsTCmtjYTJjc3ItT1UxEzARBgNVBAMTCmtjYTJjc3ItQ04wggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDA8kHL4ANRJU2aW+r4S/5KCmYXgK5OBvvWlgxxwQAVvU/gn/0SoB05rdMRdf/RTQXq3LnvFu/7bA3RkjoKfti6HcD5RxFMm4Lo3jQ4ZtTxrNLIh609ilhkXL3SmkxNuqF0S2WX8FZ62bhxBCS7HAjVbv32ROk92ARPtS5I/mTyo6W2WLmdtpC5J3W6MwMsLpgqPvYB/qo+TEhKiWb2N6XIm+a96CvRuhzH717U97gbR6EhkToNdsh65dZ+0TAIo58Q2ykA8tBhx/T1qk8HKr4jDRbOu/AG6HbsvMuKQrhOdlfc+2AnLnmmxGnLzmmIq9YlCVKO3oJZsiWfiZ+9kflLAgMBAAGjggETMIIBDzAOBgNVHQ8BAf8EBAMCBaAwEwYDVR0lBAwwCgYIKwYBBQUHAwIwDAYDVR0TAQH/BAIwADAdBgNVHQ4EFgQUar6U6YaPLwKeCPOwxzzbNeoTSpUwHwYDVR0jBBgwFoAUy63c0QU2r5F/Z4cdgCgXKPJk+KMwgZkGA1UdEQSBkTCBjoIPd3d3LmV4YW1wbGUuY29tghB0ZXN0LmV4YW1wbGUuY29tghBtYWlsLmV4YW1wbGUuY29tgg93d3cuZXhhbXBsZS5uZXSBE3NoYW5rYXJ2QHNnLmlibS5jb22HBMAAAgGHBMYzZP6HECABDbgAAAAAAAAAAAAAAAGGE2h0dHBzOi8vamtlLmNvbS9mb28wCgYIKoZIzj0EAwIDSQAwRgIhAKD9ml0OBpiloVebUI66xdTxEFwNMgC3BlF3RkTlDG9tAiEAgJVOZFa6grAMPA+yskk267DSu3cx0LBNrGlBncdDoZk=
key
MIIEogIBAAKCAQEAwPJBy+ADUSVNmlvq+Ev+SgpmF4CuTgb71pYMccEAFb1P4J/9EqAdOa3TEXX/0U0F6ty57xbv+2wN0ZI6Cn7Yuh3A+UcRTJuC6N40OGbU8azSyIetPYpYZFy90ppMTbqhdEtll/BWetm4cQQkuxwI1W799kTpPdgET7UuSP5k8qOltli5nbaQuSd1ujMDLC6YKj72Af6qPkxISolm9jelyJvmvegr0bocx+9e1Pe4G0ehIZE6DXbIeuXWftEwCKOfENspAPLQYcf09apPByq+Iw0WzrvwBuh27LzLikK4TnZX3PtgJy55psRpy85piKvWJQlSjt6CWbIln4mfvZH5SwIDAQABAoIBAGfIJtH1nXMhQHudo2aI4a+LplxP7/GyWfWTYgAx0szetj9ZbvN8whuLPvOuZ7p51ov8y9opmU3AUjJ+l8+baRG6/VhX/JsbLq/5DVelIDcaQYpxSCLI7kCVjdjg+9f3Ye6+u1edg7aysz2+/87RBoNfHyU+7cJBFhiVmN7UTxIfONaVt+gTlW3IPb9xBCLwahIa12w+kSFk9RQZgzi/kUaH20BFZDSzmJsxZSTIG0IL3KwJFM0JFBAHzc14RvAbwGozfoT494qQBVdohaTiid+x7iUrDXgvU95chciL9b7262F3a6wlWO3/a6AVVckzqdgQ27YnIiEcy0s2sukTBTECgYEA/WJiKxvyGXYPsMu/eC5sLM5MGwDMcheru3OV1inB8yIofzviud3n6UXA5sS7qeDEy/sPB9yu8sWDC9+73UXwKYq3+SuEx291koFE0J3PO4sM7UdNRq5N1p3nKzklICbgtumZhtX9aG5wjXu6yXhFIezvnNeHJjcjipsf6iGN0fMCgYEAwvAnkq8lOUxcoCpLKwsWv37M9RyW2zPDixTv9Ddj1wTDnBXYlxzJ5BkL65UAGxTgoESN2mO/ZTk0AnOGJVyYvrDnvY88sRld2jDYK8ALilzUYSoAqAA5dR8y5qS/wAC9yyB1ze7j65lrtIT/I7d442HCM63WDeXATEBVXByWOUkCgYAzVx7q+zOXwxs0yGPYVxemEHrNMeE68N7kEWx3w2g/+ljYRusOnA7kbjTCzXP03M0jQ5BtGGL+X9TIsCGhmQ0rbacPPqkdu9DHyZeG6aLWvrr0zPC0dJbi+IWhdWe3VwlLJpPsBSneYho+IKbdMZhYYmi+j9EbhiqWaA4UY44XzwKBgFFoi441eJ0iJ7h3kSarnddg8+UVCGcIigwGNWNO0nIUOkBv2yDYU/PfBdxfQEkPAfPMTVU7vM1gAzlW11m4/sz8Aftm2xi2mDwrk8tJi0hAFi1xpg6C8XvZCJ/Lg4yCgsBWkPvsXOCiFJmxxP88es6yn7CHU1JAdXsijsNF6PKJAoGAZn9jiGdKVkgtnzHpArY+xxgDvV4p3PRqz5GOopcLLbvS5z1CfHRc/2Hb0ivNf5GlTFuHttZGIadyEqm0FVCoXlfPRq8k5SLYe120+866zZ7eQ7rb4SLm2603F3+Wv1gT5WD2B/9PSD/0ORo5rL4cb4qu4MBm/n0n1PHteZZaGHk=
2022-12-13 15:34:23 SUCCESS
ValidateClientJWKsPrivatePart
Valid client JWKs: keys are valid JSON, contain the required fields, the private/public exponents match and are correctly encoded using unpadded base64url
2022-12-13 15:34:23 SUCCESS
ExtractJWKsFromStaticClientConfiguration
Extracted client JWK
client_jwks
{
  "keys": [
    {
      "p": "-JkZq0-X1RAO2UtEohS_gpRIW6vXFq8f_4eldFP7qXQcHzsSfFrul14pXG7grNokcA5S3w7HSBXQXQ7WdVeN-nZSI_232NSyF3GRkiINenSUMoz8_7zKy2MUvo9gW8WkaOlMOv5l8H781ZDfQvMCNjmwb2zE4q8qNbv2ZnA_gfc",
      "kty": "RSA",
      "q": "tj8Ug4uHQnfJEXdNKCPPbUD4kPMNu4T0pAf7lUkZ4Aa56CxKds063qUvdtyPYSiTKlpdAVYibqSyLBauG_RjPDcD6zrziKO93o42mX2Fr4fZJaWFKqlAqA3fZycWyu-VDrjF14QmDUS4NPnnQ7_UuiKYr5o3hO8-iJrW8z4VQJc",
      "d": "j_TQo4CwQ9GHOy2hCJJJfV1rUVxQpWmljB4SNBcJ4cZWbMVc0qRTL9awlgIvFCYmO2H97q3CLJAjigPGNta-TCI1eEbuaTsGrLwsjUrycQz7EIZf_i9rdj3lRhJ-gLpgO2Fj6_hfQLMHQ0yhiHi09FPLpJfPpicqEHwwmwNLQGIwN88c-TDDX2D4Iw3geygigqRnWviDVMejuRL2Luordiw7XOJHzY2BGwqOZdgqYfVS6Dr6PjOaOwWDJ7w9pHT19zz3UEXiarzA-AZKSZtxOoNVSliltj0nIzhVN0fd7g0Ljt13LjrGuyLSrAoTCZdQpCZ0uX02leqFkCAOkCzWlQ",
      "e": "AQAB",
      "use": "sig",
      "kid": "fapips1",
      "qi": "sNIuSo-uVI0TrtcR_6ZdGkps2MIWmVRhqBCKDxJAm21RkW7Sv0buRD8KPSP7WA20KTgs3O9i1Hz6bD8U2Hkjt3rk6MP59JvQev1DxFD8yA_A6aaIHk6Z7BryX5QOJzj0tzIB1tVzrSViVdDg0LUOO5yZdm_IQSU4AN-aaxjrpvA",
      "dp": "NnHJVmRzGz2OEvbSDDFBFAcHpdQHojcuadc6XDS8bAs60Xgtf0Cm-k2r_0tlN1X7HvN0INfquxXT8V17iG1pcc4SBUHezsUeT9YWjIuaqhP4FO4dxqCBRXPoqidach7h9_wILu9iQf59vwQgcVgpRtjxlCWdJQw50VTeDOdOcVc",
      "alg": "PS256",
      "dq": "qwl0dShDnuvQdmXisaM6Dq0FGvQglTZoanFbeXWLpSZq3yyCDhD6CO46J3FD1sk_pGX-Fz0BP5mt5Za7fFzVrTNsqB1BZaFWlkIdl9un1V7HOn-nBKynk5DBc4vJ5lcHKzPZ6TOKirVNs9o9YuXr_Wxuo482P7pQk9_Nj6daRq0",
      "n": "sPoZ2M-WhvDJchlxahAPDtkSaRlXWIK17NF2qHn3RgWUw0Z4XyptMWi-HMwxwwwApCi_g7ytaJ4DBDo5DY-pumFZHdj4mcD8Nb2XhV5smMO3-XABBVAuNH6VW4sFeb6bvlVBNyoHpAA_4VyMCYTjZffxGIqXpyxIND1M5zwP8RaZc1_Yo4yakZa15wXirbwZkCArJaIROpKy5xXFPA_2p4w7PnTQshAqjJx2Jz8N5CKsEvUvHNEg7pfeL1hTqLk1KRpLRh8QZKwfEjuxg0KFIGmi45gAX8SCjjX-BBffN6C7VELESRzILSlCEbTL_hslQkSQNbmyqI--kWCgkTZosQ"
    }
  ]
}
public_client_jwks
{
  "keys": [
    {
      "kty": "RSA",
      "e": "AQAB",
      "use": "sig",
      "kid": "fapips1",
      "alg": "PS256",
      "n": "sPoZ2M-WhvDJchlxahAPDtkSaRlXWIK17NF2qHn3RgWUw0Z4XyptMWi-HMwxwwwApCi_g7ytaJ4DBDo5DY-pumFZHdj4mcD8Nb2XhV5smMO3-XABBVAuNH6VW4sFeb6bvlVBNyoHpAA_4VyMCYTjZffxGIqXpyxIND1M5zwP8RaZc1_Yo4yakZa15wXirbwZkCArJaIROpKy5xXFPA_2p4w7PnTQshAqjJx2Jz8N5CKsEvUvHNEg7pfeL1hTqLk1KRpLRh8QZKwfEjuxg0KFIGmi45gAX8SCjjX-BBffN6C7VELESRzILSlCEbTL_hslQkSQNbmyqI--kWCgkTZosQ"
    }
  ]
}
2022-12-13 15:34:23 SUCCESS
CheckForKeyIdInClientJWKs
All keys contain kids
2022-12-13 15:34:23 SUCCESS
CheckDistinctKeyIdValueInClientJWKs
Distinct 'kid' value in all keys of client_jwks
see
https://bitbucket.org/openid/connect/issues/1127
2022-12-13 15:34:23 SUCCESS
FAPICheckKeyAlgInClientJWKs
Keys in client JWKS all have permitted 'alg'
permitted
[
  "ES256",
  "PS256"
]
2022-12-13 15:34:23 SUCCESS
FAPIEnsureMinimumClientKeyLength
Validated minimum key lengths for client_jwks
client_jwks
{
  "keys": [
    {
      "p": "-JkZq0-X1RAO2UtEohS_gpRIW6vXFq8f_4eldFP7qXQcHzsSfFrul14pXG7grNokcA5S3w7HSBXQXQ7WdVeN-nZSI_232NSyF3GRkiINenSUMoz8_7zKy2MUvo9gW8WkaOlMOv5l8H781ZDfQvMCNjmwb2zE4q8qNbv2ZnA_gfc",
      "kty": "RSA",
      "q": "tj8Ug4uHQnfJEXdNKCPPbUD4kPMNu4T0pAf7lUkZ4Aa56CxKds063qUvdtyPYSiTKlpdAVYibqSyLBauG_RjPDcD6zrziKO93o42mX2Fr4fZJaWFKqlAqA3fZycWyu-VDrjF14QmDUS4NPnnQ7_UuiKYr5o3hO8-iJrW8z4VQJc",
      "d": "j_TQo4CwQ9GHOy2hCJJJfV1rUVxQpWmljB4SNBcJ4cZWbMVc0qRTL9awlgIvFCYmO2H97q3CLJAjigPGNta-TCI1eEbuaTsGrLwsjUrycQz7EIZf_i9rdj3lRhJ-gLpgO2Fj6_hfQLMHQ0yhiHi09FPLpJfPpicqEHwwmwNLQGIwN88c-TDDX2D4Iw3geygigqRnWviDVMejuRL2Luordiw7XOJHzY2BGwqOZdgqYfVS6Dr6PjOaOwWDJ7w9pHT19zz3UEXiarzA-AZKSZtxOoNVSliltj0nIzhVN0fd7g0Ljt13LjrGuyLSrAoTCZdQpCZ0uX02leqFkCAOkCzWlQ",
      "e": "AQAB",
      "use": "sig",
      "kid": "fapips1",
      "qi": "sNIuSo-uVI0TrtcR_6ZdGkps2MIWmVRhqBCKDxJAm21RkW7Sv0buRD8KPSP7WA20KTgs3O9i1Hz6bD8U2Hkjt3rk6MP59JvQev1DxFD8yA_A6aaIHk6Z7BryX5QOJzj0tzIB1tVzrSViVdDg0LUOO5yZdm_IQSU4AN-aaxjrpvA",
      "dp": "NnHJVmRzGz2OEvbSDDFBFAcHpdQHojcuadc6XDS8bAs60Xgtf0Cm-k2r_0tlN1X7HvN0INfquxXT8V17iG1pcc4SBUHezsUeT9YWjIuaqhP4FO4dxqCBRXPoqidach7h9_wILu9iQf59vwQgcVgpRtjxlCWdJQw50VTeDOdOcVc",
      "alg": "PS256",
      "dq": "qwl0dShDnuvQdmXisaM6Dq0FGvQglTZoanFbeXWLpSZq3yyCDhD6CO46J3FD1sk_pGX-Fz0BP5mt5Za7fFzVrTNsqB1BZaFWlkIdl9un1V7HOn-nBKynk5DBc4vJ5lcHKzPZ6TOKirVNs9o9YuXr_Wxuo482P7pQk9_Nj6daRq0",
      "n": "sPoZ2M-WhvDJchlxahAPDtkSaRlXWIK17NF2qHn3RgWUw0Z4XyptMWi-HMwxwwwApCi_g7ytaJ4DBDo5DY-pumFZHdj4mcD8Nb2XhV5smMO3-XABBVAuNH6VW4sFeb6bvlVBNyoHpAA_4VyMCYTjZffxGIqXpyxIND1M5zwP8RaZc1_Yo4yakZa15wXirbwZkCArJaIROpKy5xXFPA_2p4w7PnTQshAqjJx2Jz8N5CKsEvUvHNEg7pfeL1hTqLk1KRpLRh8QZKwfEjuxg0KFIGmi45gAX8SCjjX-BBffN6C7VELESRzILSlCEbTL_hslQkSQNbmyqI--kWCgkTZosQ"
    }
  ]
}
2022-12-13 15:34:23 SUCCESS
ValidateMTLSCertificatesAsX509
Mutual TLS authentication cert validated as X.509
Verify configuration of second client
2022-12-13 15:34:23 SUCCESS
GetStaticClient2Configuration
Found a static second client object
client_id
079330e3-ac73-4a20-89e9-6af7aaeacb7b
scope
openid email
jwks
{
  "keys": [
    {
      "p": "_V4SSh_YdQH3_c3zAUQ4RgxImgnYHPRZuVcfRuVztq6fHs1xI5Qcri4wSyfmcQgu-Caos_5Htu6iOrrMnA0Si8s6rsU8lzGCgBF0clQeEdUGX1YKqsTw2OrdcFhjwZWO59uBcmUXw8xw-EMlA_9x82HVKwZcPW94fRJJeUC80Pk",
      "kty": "RSA",
      "q": "jt6KCTdVQV6MLruoTlKPN9MtlLZ16TR-5GUareWhr8GGn81mto_Ua0eCZHGCnleAYzI3il66PvF4ribDXXOHhn6iBiIHph2Oge1Q73gSjdClHGrTq7EHi_yEeoPxXXD8siEplKcREsWtby8XTUktG0GaIg2XgocVpj7AEn_QewM",
      "d": "JhMR3QAhmiyBWEFvYJF7t5ohNOrRa5DWJi1sBmq_baADjt_DuEGBX3mQ2ZCHdWGjIznlqg9NuewHu1RykRujwFImBJaK5XMIdQoDDHlja3jBg-cp6swoQUBrOv0Amq-Co-qmtn5D7gaEkO4cJD1AM_ZJSKYus9k1ra3mEGPPUKiSknjICvZ4zEd28mJG_ZTMa5y_G3NrqkkjeLoej86Ru0yHLjYo3ZpXvbRspnlmAqganHVo7CjeBqW8ov2fS6hyRxPRDHfyw-fKHBcLFVqGNTw9-vfqXWfTBB4kwHmSwfJ5jF19UBenKk77eyzOcdwQeSDUKUeS5Ni6_cpvDe9HEQ",
      "e": "AQAB",
      "use": "sig",
      "kid": "fapips2",
      "qi": "jRUHNAE9Rq9slhKVJaHTDc56L040JIlc92nS1lW5tXxwT1032yjOHqvxkUafFsRl2Y_HJhNMXiZH89zk8QIGgO_-o2sOhlVYReE9HZpXaZQegicuG8Oc7AuH78EbPjeBml2ph1B4UV1r1L9EDg6C5otTMvi7AxIG5SH1nDsB8LA",
      "dp": "7hq6y2g0DnnkKWOjS_xlegbPL9uyejt0GoZygTjezr46EUN2YL4vWc1UWzzLBkxvf4stHcIIeTS3xsOHx9tNI4zAwD_hWiEQB_TfXxYIEDAGxg9hBO0Bfojxw0N9tA4t91zEwNGaTMpTHCxVm_UyjEvTfZSDmMSqEbfezpF1IFk",
      "alg": "PS256",
      "dq": "XPniZyEFcKcxH3CslVwRLElYToF3tq6dLdHGTQk18gVFsVWg1IpBuRcuemOMl7NmMCgMERaYqkHHQb6kQXrf5d0fYFJhG-_8P_3LQCyqFnSEHzw-SGvK94T8Sib3utG_AcWnI8Cd0dOnjMXeqkNHAYft4N9rjFyQ8EHCCcf4SzU",
      "n": "jWZuVs7f3z7SVFMH9tggC-wbx_JIEy59aScoFGhb64IoKt886ftpFht6_WTwJJKkMxQiPDeHUmi7xAC5TWV1OmrGOv4QKQ2P-u3wvvkFTrOUFGCVRgZl8dJ8I85StneVZXbVaQ6sJBH3x_wgtAT_KWUOrgs4Asi1QoHU1Qs1m-_lf0nkL7aYJDOBYpY9LYtj8NuNLaKSJSTjkZIabDJzTboNvDarS3YLQiS-LVJSD9svfK3HwAq9XV3-LEpNkqT6xCe1TJiOT-4taXwRTjyoZ9z_ejgjnpPL1AD7TkXgxTIpCQ6vGgq9j4YyUy5QIf9QZnA71L4Xj41WddUdy-4V6w"
    }
  ]
}
2022-12-13 15:34:23
ValidateMTLSCertificates2Header
No certificate authority found for MTLS
2022-12-13 15:34:23 SUCCESS
ValidateMTLSCertificates2Header
MTLS certificates header is valid
2022-12-13 15:34:23
ExtractMTLSCertificates2FromConfiguration
No certificate authority found for MTLS
2022-12-13 15:34:23 SUCCESS
ExtractMTLSCertificates2FromConfiguration
Mutual TLS authentication credentials loaded
cert
MIID1zCCA36gAwIBAgIUDBFNPnYtCIbXSSNasLveG4juOdEwCgYIKoZIzj0EAwIwgYExCzAJBgNVBAYTAlVTMREwDwYDVQQIDAhOZXcgWW9yazE0MDIGA1UECgwrSW50ZXJuYXRpb25hbCBCdXNpbmVzcyBNYWNoaW5lcyBDb3Jwb3JhdGlvbjEpMCcGA1UEAwwgSUJNIFNlY3VyaXR5IFZlcmlmeSBSZWwtSVRFIENBLTEwHhcNMjIxMjEyMDMxODAwWhcNMjUxMjExMDMxODAwWjB0MQswCQYDVQQGEwJTRzETMBEGA1UECBMKa2NhMmNzci1TVDESMBAGA1UEBxMJa2NhMmNzci1MMRIwEAYDVQQKEwlrY2EyY3NyLU8xEzARBgNVBAsTCmtjYTJjc3ItT1UxEzARBgNVBAMTCmtjYTJjc3ItQ04wggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCkEkkODVEXXwznpi+9CcgwW6JY6N9dje83Qq0NvPOA92+cG9xg5hVy21buTD6qRMpx/nOlv0pm8VatNgGYAb/v7E9UIfC+UEpFSI0u1g733UUiDxXjkhSkosJc/QMYvXJYIVUnywZ0sukxvaJjs2bROPTXZy0AZQPxQNG4T1I16L5608ReL+xSQaA5S7UiE4wh4kXPPd4jc/QmWQ58yBa5o/ZUV6YUNI0IbsqSLMRl1dsk8rK5qSOTds6OZUNigoxTOz5+Q2vvhzhJxyWNlqxvxp8h4Ae3grj09TKi7a7qCm0Kk4SruiXiaLcB7nzGWFcFMwGjYuBD7J00moLqHMnZAgMBAAGjggETMIIBDzAOBgNVHQ8BAf8EBAMCBaAwEwYDVR0lBAwwCgYIKwYBBQUHAwIwDAYDVR0TAQH/BAIwADAdBgNVHQ4EFgQU60qqehCXUuXd2Pn7pKWlox+HsBUwHwYDVR0jBBgwFoAUy63c0QU2r5F/Z4cdgCgXKPJk+KMwgZkGA1UdEQSBkTCBjoIPd3d3LmV4YW1wbGUuY29tghB0ZXN0LmV4YW1wbGUuY29tghBtYWlsLmV4YW1wbGUuY29tgg93d3cuZXhhbXBsZS5uZXSBE3NoYW5rYXJ2QHNnLmlibS5jb22HBMAAAgGHBMYzZP6HECABDbgAAAAAAAAAAAAAAAGGE2h0dHBzOi8vamtlLmNvbS9mb28wCgYIKoZIzj0EAwIDRwAwRAIgbZTf0ORGNxyWFyMT0tgE0Sx01MgcIJnP9OOJ9UxMad0CIGQB7NrvrE34v62B5Wjwi8qj9Ca/taOvgQaNNLGRLcIQ
key
MIIEpAIBAAKCAQEApBJJDg1RF18M56YvvQnIMFuiWOjfXY3vN0KtDbzzgPdvnBvcYOYVcttW7kw+qkTKcf5zpb9KZvFWrTYBmAG/7+xPVCHwvlBKRUiNLtYO991FIg8V45IUpKLCXP0DGL1yWCFVJ8sGdLLpMb2iY7Nm0Tj012ctAGUD8UDRuE9SNei+etPEXi/sUkGgOUu1IhOMIeJFzz3eI3P0JlkOfMgWuaP2VFemFDSNCG7KkizEZdXbJPKyuakjk3bOjmVDYoKMUzs+fkNr74c4SccljZasb8afIeAHt4K49PUyou2u6gptCpOEq7ol4mi3Ae58xlhXBTMBo2LgQ+ydNJqC6hzJ2QIDAQABAoIBAQCH3VR9vG1QSzemhCm4Auexk9AmjACbujNDsYUYgUWroDreLPwbiaxtRlEAWEb0PK7gIvOlZ3i3MlaybKx5Mcm9ZhRy+QAguOAn62JuTHhsrODYyWE45/kMNHN7CVGNJSQQ8tlPcIJSFO2icQSORzt3OhEWZqwPTZcsKp8AXz8Wv+c7lThb/kn5x0KrghOSoD752D6snDRFIy6D1NziziT1ozZJc3zUnKKq/qBCV3/1/iJ8y98CgwVwxD/HvIbf7vD4nZeo+KDjhxgmhWq4Yd0ZpWgRII6pKitHSl45hrG8BCC3s4kSqwiJvPIz8CGUJPd0sctUnlWlVFPV3wnnyUeZAoGBANiIA89BZjd57tAg9Z+8COVUbAGOzglmnZ+LTonGd1BFyP3PI+usKo9O/JY5gMokjn+MehoaeG8ChyhQjMJFuyfAgo6V45v8RP2cgPAJXUwU8p+nSmdRbiU9z68NJSpxmnjMTYr92WD01Y41IZNpYF6hYtGtCsA8eVrxcj0312jPAoGBAMH6VroThTamv/JlA8rdPrZD1oNTUfeekKtPxIWZvlsXVQ9/ya9n0KvwqyAMcZZR2rgt9L5A5OkKcSuiI/KYdqssEs/SQkYuJdLyzDeyX7+HyiZfva0bqwYb5a8KPtiXxPG+dMQNuudXO2uqjWSEcHBZR1VIT6R1yNw6taCoePzXAoGBAICiBMlaC7RHPoTsH57eINbEGUmvoVzaVidSpbyZZ4YLfwSwyqEV7U6nWMyRqp3rq6/AL0VUllk0QkDD4WsD69QIvEaias3exsl28O4oUgGBrEUGJ+BK8sky+C8A+yREysSacjJw7XN432kUzTZ6cmKlM0RmrS1Yf6t0Ji6R/ujnAoGAFFlJnc2MbPZDLo9wPWjGOmKVb0NfVuWYcZA1onpFYNLqxmx2YOM4HcFqgjsr80P0+NtBUHAIU3YX9ybUNI/P6xb9hjWdZDVVHHMB/1nD95isGSh0AmPjpglpJ9qgSyJos59yKlryX3BkOGA04vWNwgtrk0O5rxv4DTpPcWIbBxMCgYBX7uCWmJmgB/a/CRzZsE5dwVIM15MjIM7MOAu/+OTPzVq7Gqc7RgyyLItin3QjnuomAmtJ2TKilGzQj09z6hNNfijUfzY0jzgyWIlhbiVcYxlZ+956+XytcAe0FUI+7vadJNsprdASSAUvq9A2zrYyfGUkM5OfeEW9H0eWrjnCQw==
2022-12-13 15:34:23 SUCCESS
ValidateClientJWKsPrivatePart
Valid client JWKs: keys are valid JSON, contain the required fields, the private/public exponents match and are correctly encoded using unpadded base64url
2022-12-13 15:34:23 SUCCESS
ExtractJWKsFromStaticClientConfiguration
Extracted client JWK
client_jwks
{
  "keys": [
    {
      "p": "_V4SSh_YdQH3_c3zAUQ4RgxImgnYHPRZuVcfRuVztq6fHs1xI5Qcri4wSyfmcQgu-Caos_5Htu6iOrrMnA0Si8s6rsU8lzGCgBF0clQeEdUGX1YKqsTw2OrdcFhjwZWO59uBcmUXw8xw-EMlA_9x82HVKwZcPW94fRJJeUC80Pk",
      "kty": "RSA",
      "q": "jt6KCTdVQV6MLruoTlKPN9MtlLZ16TR-5GUareWhr8GGn81mto_Ua0eCZHGCnleAYzI3il66PvF4ribDXXOHhn6iBiIHph2Oge1Q73gSjdClHGrTq7EHi_yEeoPxXXD8siEplKcREsWtby8XTUktG0GaIg2XgocVpj7AEn_QewM",
      "d": "JhMR3QAhmiyBWEFvYJF7t5ohNOrRa5DWJi1sBmq_baADjt_DuEGBX3mQ2ZCHdWGjIznlqg9NuewHu1RykRujwFImBJaK5XMIdQoDDHlja3jBg-cp6swoQUBrOv0Amq-Co-qmtn5D7gaEkO4cJD1AM_ZJSKYus9k1ra3mEGPPUKiSknjICvZ4zEd28mJG_ZTMa5y_G3NrqkkjeLoej86Ru0yHLjYo3ZpXvbRspnlmAqganHVo7CjeBqW8ov2fS6hyRxPRDHfyw-fKHBcLFVqGNTw9-vfqXWfTBB4kwHmSwfJ5jF19UBenKk77eyzOcdwQeSDUKUeS5Ni6_cpvDe9HEQ",
      "e": "AQAB",
      "use": "sig",
      "kid": "fapips2",
      "qi": "jRUHNAE9Rq9slhKVJaHTDc56L040JIlc92nS1lW5tXxwT1032yjOHqvxkUafFsRl2Y_HJhNMXiZH89zk8QIGgO_-o2sOhlVYReE9HZpXaZQegicuG8Oc7AuH78EbPjeBml2ph1B4UV1r1L9EDg6C5otTMvi7AxIG5SH1nDsB8LA",
      "dp": "7hq6y2g0DnnkKWOjS_xlegbPL9uyejt0GoZygTjezr46EUN2YL4vWc1UWzzLBkxvf4stHcIIeTS3xsOHx9tNI4zAwD_hWiEQB_TfXxYIEDAGxg9hBO0Bfojxw0N9tA4t91zEwNGaTMpTHCxVm_UyjEvTfZSDmMSqEbfezpF1IFk",
      "alg": "PS256",
      "dq": "XPniZyEFcKcxH3CslVwRLElYToF3tq6dLdHGTQk18gVFsVWg1IpBuRcuemOMl7NmMCgMERaYqkHHQb6kQXrf5d0fYFJhG-_8P_3LQCyqFnSEHzw-SGvK94T8Sib3utG_AcWnI8Cd0dOnjMXeqkNHAYft4N9rjFyQ8EHCCcf4SzU",
      "n": "jWZuVs7f3z7SVFMH9tggC-wbx_JIEy59aScoFGhb64IoKt886ftpFht6_WTwJJKkMxQiPDeHUmi7xAC5TWV1OmrGOv4QKQ2P-u3wvvkFTrOUFGCVRgZl8dJ8I85StneVZXbVaQ6sJBH3x_wgtAT_KWUOrgs4Asi1QoHU1Qs1m-_lf0nkL7aYJDOBYpY9LYtj8NuNLaKSJSTjkZIabDJzTboNvDarS3YLQiS-LVJSD9svfK3HwAq9XV3-LEpNkqT6xCe1TJiOT-4taXwRTjyoZ9z_ejgjnpPL1AD7TkXgxTIpCQ6vGgq9j4YyUy5QIf9QZnA71L4Xj41WddUdy-4V6w"
    }
  ]
}
public_client_jwks
{
  "keys": [
    {
      "kty": "RSA",
      "e": "AQAB",
      "use": "sig",
      "kid": "fapips2",
      "alg": "PS256",
      "n": "jWZuVs7f3z7SVFMH9tggC-wbx_JIEy59aScoFGhb64IoKt886ftpFht6_WTwJJKkMxQiPDeHUmi7xAC5TWV1OmrGOv4QKQ2P-u3wvvkFTrOUFGCVRgZl8dJ8I85StneVZXbVaQ6sJBH3x_wgtAT_KWUOrgs4Asi1QoHU1Qs1m-_lf0nkL7aYJDOBYpY9LYtj8NuNLaKSJSTjkZIabDJzTboNvDarS3YLQiS-LVJSD9svfK3HwAq9XV3-LEpNkqT6xCe1TJiOT-4taXwRTjyoZ9z_ejgjnpPL1AD7TkXgxTIpCQ6vGgq9j4YyUy5QIf9QZnA71L4Xj41WddUdy-4V6w"
    }
  ]
}
2022-12-13 15:34:23 SUCCESS
CheckForKeyIdInClientJWKs
All keys contain kids
2022-12-13 15:34:23 SUCCESS
CheckDistinctKeyIdValueInClientJWKs
Distinct 'kid' value in all keys of client_jwks
see
https://bitbucket.org/openid/connect/issues/1127
2022-12-13 15:34:23 SUCCESS
FAPICheckKeyAlgInClientJWKs
Keys in client JWKS all have permitted 'alg'
permitted
[
  "ES256",
  "PS256"
]
2022-12-13 15:34:23 SUCCESS
FAPIEnsureMinimumClientKeyLength
Validated minimum key lengths for client_jwks
client_jwks
{
  "keys": [
    {
      "p": "_V4SSh_YdQH3_c3zAUQ4RgxImgnYHPRZuVcfRuVztq6fHs1xI5Qcri4wSyfmcQgu-Caos_5Htu6iOrrMnA0Si8s6rsU8lzGCgBF0clQeEdUGX1YKqsTw2OrdcFhjwZWO59uBcmUXw8xw-EMlA_9x82HVKwZcPW94fRJJeUC80Pk",
      "kty": "RSA",
      "q": "jt6KCTdVQV6MLruoTlKPN9MtlLZ16TR-5GUareWhr8GGn81mto_Ua0eCZHGCnleAYzI3il66PvF4ribDXXOHhn6iBiIHph2Oge1Q73gSjdClHGrTq7EHi_yEeoPxXXD8siEplKcREsWtby8XTUktG0GaIg2XgocVpj7AEn_QewM",
      "d": "JhMR3QAhmiyBWEFvYJF7t5ohNOrRa5DWJi1sBmq_baADjt_DuEGBX3mQ2ZCHdWGjIznlqg9NuewHu1RykRujwFImBJaK5XMIdQoDDHlja3jBg-cp6swoQUBrOv0Amq-Co-qmtn5D7gaEkO4cJD1AM_ZJSKYus9k1ra3mEGPPUKiSknjICvZ4zEd28mJG_ZTMa5y_G3NrqkkjeLoej86Ru0yHLjYo3ZpXvbRspnlmAqganHVo7CjeBqW8ov2fS6hyRxPRDHfyw-fKHBcLFVqGNTw9-vfqXWfTBB4kwHmSwfJ5jF19UBenKk77eyzOcdwQeSDUKUeS5Ni6_cpvDe9HEQ",
      "e": "AQAB",
      "use": "sig",
      "kid": "fapips2",
      "qi": "jRUHNAE9Rq9slhKVJaHTDc56L040JIlc92nS1lW5tXxwT1032yjOHqvxkUafFsRl2Y_HJhNMXiZH89zk8QIGgO_-o2sOhlVYReE9HZpXaZQegicuG8Oc7AuH78EbPjeBml2ph1B4UV1r1L9EDg6C5otTMvi7AxIG5SH1nDsB8LA",
      "dp": "7hq6y2g0DnnkKWOjS_xlegbPL9uyejt0GoZygTjezr46EUN2YL4vWc1UWzzLBkxvf4stHcIIeTS3xsOHx9tNI4zAwD_hWiEQB_TfXxYIEDAGxg9hBO0Bfojxw0N9tA4t91zEwNGaTMpTHCxVm_UyjEvTfZSDmMSqEbfezpF1IFk",
      "alg": "PS256",
      "dq": "XPniZyEFcKcxH3CslVwRLElYToF3tq6dLdHGTQk18gVFsVWg1IpBuRcuemOMl7NmMCgMERaYqkHHQb6kQXrf5d0fYFJhG-_8P_3LQCyqFnSEHzw-SGvK94T8Sib3utG_AcWnI8Cd0dOnjMXeqkNHAYft4N9rjFyQ8EHCCcf4SzU",
      "n": "jWZuVs7f3z7SVFMH9tggC-wbx_JIEy59aScoFGhb64IoKt886ftpFht6_WTwJJKkMxQiPDeHUmi7xAC5TWV1OmrGOv4QKQ2P-u3wvvkFTrOUFGCVRgZl8dJ8I85StneVZXbVaQ6sJBH3x_wgtAT_KWUOrgs4Asi1QoHU1Qs1m-_lf0nkL7aYJDOBYpY9LYtj8NuNLaKSJSTjkZIabDJzTboNvDarS3YLQiS-LVJSD9svfK3HwAq9XV3-LEpNkqT6xCe1TJiOT-4taXwRTjyoZ9z_ejgjnpPL1AD7TkXgxTIpCQ6vGgq9j4YyUy5QIf9QZnA71L4Xj41WddUdy-4V6w"
    }
  ]
}
2022-12-13 15:34:23 SUCCESS
ValidateMTLSCertificatesAsX509
Mutual TLS authentication cert validated as X.509
2022-12-13 15:34:23 SUCCESS
ValidateClientPrivateKeysAreDifferent
Client signing JWKs have different thumbprints
jwk1
{
  "p": "-JkZq0-X1RAO2UtEohS_gpRIW6vXFq8f_4eldFP7qXQcHzsSfFrul14pXG7grNokcA5S3w7HSBXQXQ7WdVeN-nZSI_232NSyF3GRkiINenSUMoz8_7zKy2MUvo9gW8WkaOlMOv5l8H781ZDfQvMCNjmwb2zE4q8qNbv2ZnA_gfc",
  "kty": "RSA",
  "q": "tj8Ug4uHQnfJEXdNKCPPbUD4kPMNu4T0pAf7lUkZ4Aa56CxKds063qUvdtyPYSiTKlpdAVYibqSyLBauG_RjPDcD6zrziKO93o42mX2Fr4fZJaWFKqlAqA3fZycWyu-VDrjF14QmDUS4NPnnQ7_UuiKYr5o3hO8-iJrW8z4VQJc",
  "d": "j_TQo4CwQ9GHOy2hCJJJfV1rUVxQpWmljB4SNBcJ4cZWbMVc0qRTL9awlgIvFCYmO2H97q3CLJAjigPGNta-TCI1eEbuaTsGrLwsjUrycQz7EIZf_i9rdj3lRhJ-gLpgO2Fj6_hfQLMHQ0yhiHi09FPLpJfPpicqEHwwmwNLQGIwN88c-TDDX2D4Iw3geygigqRnWviDVMejuRL2Luordiw7XOJHzY2BGwqOZdgqYfVS6Dr6PjOaOwWDJ7w9pHT19zz3UEXiarzA-AZKSZtxOoNVSliltj0nIzhVN0fd7g0Ljt13LjrGuyLSrAoTCZdQpCZ0uX02leqFkCAOkCzWlQ",
  "e": "AQAB",
  "use": "sig",
  "kid": "fapips1",
  "qi": "sNIuSo-uVI0TrtcR_6ZdGkps2MIWmVRhqBCKDxJAm21RkW7Sv0buRD8KPSP7WA20KTgs3O9i1Hz6bD8U2Hkjt3rk6MP59JvQev1DxFD8yA_A6aaIHk6Z7BryX5QOJzj0tzIB1tVzrSViVdDg0LUOO5yZdm_IQSU4AN-aaxjrpvA",
  "dp": "NnHJVmRzGz2OEvbSDDFBFAcHpdQHojcuadc6XDS8bAs60Xgtf0Cm-k2r_0tlN1X7HvN0INfquxXT8V17iG1pcc4SBUHezsUeT9YWjIuaqhP4FO4dxqCBRXPoqidach7h9_wILu9iQf59vwQgcVgpRtjxlCWdJQw50VTeDOdOcVc",
  "alg": "PS256",
  "dq": "qwl0dShDnuvQdmXisaM6Dq0FGvQglTZoanFbeXWLpSZq3yyCDhD6CO46J3FD1sk_pGX-Fz0BP5mt5Za7fFzVrTNsqB1BZaFWlkIdl9un1V7HOn-nBKynk5DBc4vJ5lcHKzPZ6TOKirVNs9o9YuXr_Wxuo482P7pQk9_Nj6daRq0",
  "n": "sPoZ2M-WhvDJchlxahAPDtkSaRlXWIK17NF2qHn3RgWUw0Z4XyptMWi-HMwxwwwApCi_g7ytaJ4DBDo5DY-pumFZHdj4mcD8Nb2XhV5smMO3-XABBVAuNH6VW4sFeb6bvlVBNyoHpAA_4VyMCYTjZffxGIqXpyxIND1M5zwP8RaZc1_Yo4yakZa15wXirbwZkCArJaIROpKy5xXFPA_2p4w7PnTQshAqjJx2Jz8N5CKsEvUvHNEg7pfeL1hTqLk1KRpLRh8QZKwfEjuxg0KFIGmi45gAX8SCjjX-BBffN6C7VELESRzILSlCEbTL_hslQkSQNbmyqI--kWCgkTZosQ"
}
jwk2
{
  "p": "_V4SSh_YdQH3_c3zAUQ4RgxImgnYHPRZuVcfRuVztq6fHs1xI5Qcri4wSyfmcQgu-Caos_5Htu6iOrrMnA0Si8s6rsU8lzGCgBF0clQeEdUGX1YKqsTw2OrdcFhjwZWO59uBcmUXw8xw-EMlA_9x82HVKwZcPW94fRJJeUC80Pk",
  "kty": "RSA",
  "q": "jt6KCTdVQV6MLruoTlKPN9MtlLZ16TR-5GUareWhr8GGn81mto_Ua0eCZHGCnleAYzI3il66PvF4ribDXXOHhn6iBiIHph2Oge1Q73gSjdClHGrTq7EHi_yEeoPxXXD8siEplKcREsWtby8XTUktG0GaIg2XgocVpj7AEn_QewM",
  "d": "JhMR3QAhmiyBWEFvYJF7t5ohNOrRa5DWJi1sBmq_baADjt_DuEGBX3mQ2ZCHdWGjIznlqg9NuewHu1RykRujwFImBJaK5XMIdQoDDHlja3jBg-cp6swoQUBrOv0Amq-Co-qmtn5D7gaEkO4cJD1AM_ZJSKYus9k1ra3mEGPPUKiSknjICvZ4zEd28mJG_ZTMa5y_G3NrqkkjeLoej86Ru0yHLjYo3ZpXvbRspnlmAqganHVo7CjeBqW8ov2fS6hyRxPRDHfyw-fKHBcLFVqGNTw9-vfqXWfTBB4kwHmSwfJ5jF19UBenKk77eyzOcdwQeSDUKUeS5Ni6_cpvDe9HEQ",
  "e": "AQAB",
  "use": "sig",
  "kid": "fapips2",
  "qi": "jRUHNAE9Rq9slhKVJaHTDc56L040JIlc92nS1lW5tXxwT1032yjOHqvxkUafFsRl2Y_HJhNMXiZH89zk8QIGgO_-o2sOhlVYReE9HZpXaZQegicuG8Oc7AuH78EbPjeBml2ph1B4UV1r1L9EDg6C5otTMvi7AxIG5SH1nDsB8LA",
  "dp": "7hq6y2g0DnnkKWOjS_xlegbPL9uyejt0GoZygTjezr46EUN2YL4vWc1UWzzLBkxvf4stHcIIeTS3xsOHx9tNI4zAwD_hWiEQB_TfXxYIEDAGxg9hBO0Bfojxw0N9tA4t91zEwNGaTMpTHCxVm_UyjEvTfZSDmMSqEbfezpF1IFk",
  "alg": "PS256",
  "dq": "XPniZyEFcKcxH3CslVwRLElYToF3tq6dLdHGTQk18gVFsVWg1IpBuRcuemOMl7NmMCgMERaYqkHHQb6kQXrf5d0fYFJhG-_8P_3LQCyqFnSEHzw-SGvK94T8Sib3utG_AcWnI8Cd0dOnjMXeqkNHAYft4N9rjFyQ8EHCCcf4SzU",
  "n": "jWZuVs7f3z7SVFMH9tggC-wbx_JIEy59aScoFGhb64IoKt886ftpFht6_WTwJJKkMxQiPDeHUmi7xAC5TWV1OmrGOv4QKQ2P-u3wvvkFTrOUFGCVRgZl8dJ8I85StneVZXbVaQ6sJBH3x_wgtAT_KWUOrgs4Asi1QoHU1Qs1m-_lf0nkL7aYJDOBYpY9LYtj8NuNLaKSJSTjkZIabDJzTboNvDarS3YLQiS-LVJSD9svfK3HwAq9XV3-LEpNkqT6xCe1TJiOT-4taXwRTjyoZ9z_ejgjnpPL1AD7TkXgxTIpCQ6vGgq9j4YyUy5QIf9QZnA71L4Xj41WddUdy-4V6w"
}
2022-12-13 15:34:23 SUCCESS
GetResourceEndpointConfiguration
Found a resource endpoint object
resourceUrl
https://fapipoc.rel.vanitytst.cloudidentity.ibm.com/oauth2/open-banking/v3.1/aisp/accounts
2022-12-13 15:34:23 SUCCESS
SetProtectedResourceUrlToSingleResourceEndpoint
Set protected resource URL
protected_resource_url
https://fapipoc.rel.vanitytst.cloudidentity.ibm.com/oauth2/open-banking/v3.1/aisp/accounts
2022-12-13 15:34:23 SUCCESS
ExtractTLSTestValuesFromResourceConfiguration
Extracted TLS information from resource endpoint
resource_endpoint
{
  "testHost": "fapipoc.rel.vanitytst.cloudidentity.ibm.com",
  "testPort": 443
}
2022-12-13 15:34:23 SUCCESS
ExtractTLSTestValuesFromOBResourceConfiguration
Extracted TLS information from resource endpoint
accounts_resource_endpoint
{
  "testHost": "fapipoc.rel.vanitytst.cloudidentity.ibm.com",
  "testPort": 443
}
accounts_request_endpoint
{
  "testHost": "fapipoc.rel.vanitytst.cloudidentity.ibm.com",
  "testPort": 443
}
2022-12-13 15:34:23
fapi1-advanced-final-attempt-reuse-authorisation-code-after-one-second
Setup Done
Make request to authorization endpoint
2022-12-13 15:34:23 SUCCESS
CreateAuthorizationEndpointRequestFromClientInformation
Created authorization endpoint request
client_id
d74dcd6c-cfa7-41b5-ad33-837ca6013a9c
redirect_uri
https://www.certification.openid.net/test/a/fapipoc_fapi_jarm/callback
scope
openid email
2022-12-13 15:34:23 SUCCESS
AddAcrClaimToAuthorizationEndpointRequest
Added acr claim to authorization_endpoint_request
authorization_endpoint_request
{
  "client_id": "d74dcd6c-cfa7-41b5-ad33-837ca6013a9c",
  "redirect_uri": "https://www.certification.openid.net/test/a/fapipoc_fapi_jarm/callback",
  "scope": "openid email",
  "claims": {
    "id_token": {
      "acr": {
        "value": "urn:mace:incommon:iap:silver",
        "essential": true
      }
    }
  }
}
2022-12-13 15:34:23
CreateRandomStateValue
Created state value
requested_state_length
10
state
vE9Ok3LBgx
2022-12-13 15:34:23 SUCCESS
AddStateToAuthorizationEndpointRequest
Added state parameter to request
client_id
d74dcd6c-cfa7-41b5-ad33-837ca6013a9c
redirect_uri
https://www.certification.openid.net/test/a/fapipoc_fapi_jarm/callback
scope
openid email
claims
{
  "id_token": {
    "acr": {
      "value": "urn:mace:incommon:iap:silver",
      "essential": true
    }
  }
}
state
vE9Ok3LBgx
2022-12-13 15:34:23
CreateRandomNonceValue
Created nonce value
requested_nonce_length
10
nonce
dEoLlAScxs
2022-12-13 15:34:23 SUCCESS
AddNonceToAuthorizationEndpointRequest
Added nonce parameter to request
client_id
d74dcd6c-cfa7-41b5-ad33-837ca6013a9c
redirect_uri
https://www.certification.openid.net/test/a/fapipoc_fapi_jarm/callback
scope
openid email
claims
{
  "id_token": {
    "acr": {
      "value": "urn:mace:incommon:iap:silver",
      "essential": true
    }
  }
}
state
vE9Ok3LBgx
nonce
dEoLlAScxs
2022-12-13 15:34:23 SUCCESS
SetAuthorizationEndpointRequestResponseTypeToCode
Added response_type parameter to request
client_id
d74dcd6c-cfa7-41b5-ad33-837ca6013a9c
redirect_uri
https://www.certification.openid.net/test/a/fapipoc_fapi_jarm/callback
scope
openid email
claims
{
  "id_token": {
    "acr": {
      "value": "urn:mace:incommon:iap:silver",
      "essential": true
    }
  }
}
state
vE9Ok3LBgx
nonce
dEoLlAScxs
response_type
code
2022-12-13 15:34:23 SUCCESS
SetAuthorizationEndpointRequestResponseModeToJWT
Added response_mode parameter to request
client_id
d74dcd6c-cfa7-41b5-ad33-837ca6013a9c
redirect_uri
https://www.certification.openid.net/test/a/fapipoc_fapi_jarm/callback
scope
openid email
claims
{
  "id_token": {
    "acr": {
      "value": "urn:mace:incommon:iap:silver",
      "essential": true
    }
  }
}
state
vE9Ok3LBgx
nonce
dEoLlAScxs
response_type
code
response_mode
jwt
2022-12-13 15:34:23 SUCCESS
ConvertAuthorizationEndpointRequestToRequestObject
Created request object claims
request_object_claims
{
  "client_id": "d74dcd6c-cfa7-41b5-ad33-837ca6013a9c",
  "redirect_uri": "https://www.certification.openid.net/test/a/fapipoc_fapi_jarm/callback",
  "scope": "openid email",
  "claims": {
    "id_token": {
      "acr": {
        "value": "urn:mace:incommon:iap:silver",
        "essential": true
      }
    }
  },
  "state": "vE9Ok3LBgx",
  "nonce": "dEoLlAScxs",
  "response_type": "code",
  "response_mode": "jwt"
}
2022-12-13 15:34:23 SUCCESS
AddNbfToRequestObject
Added nbf to request object claims
nbf
1.670945663E9
2022-12-13 15:34:23 SUCCESS
AddExpToRequestObject
Added exp to request object claims
exp
1.670945963E9
2022-12-13 15:34:23 SUCCESS
AddAudToRequestObject
Added aud to request object claims
aud
https://fapipoc.rel.vanitytst.cloudidentity.ibm.com/oauth2
2022-12-13 15:34:23 SUCCESS
AddIssToRequestObject
Added iss to request object claims
iss
d74dcd6c-cfa7-41b5-ad33-837ca6013a9c
2022-12-13 15:34:23 SUCCESS
AddClientIdToRequestObject
Added client_id to request object claims
client_id
d74dcd6c-cfa7-41b5-ad33-837ca6013a9c
2022-12-13 15:34:23 SUCCESS
SignRequestObject
Signed the request object
claims
{
  "aud": "https://fapipoc.rel.vanitytst.cloudidentity.ibm.com/oauth2",
  "nbf": 1670945663,
  "scope": "openid email",
  "claims": {
    "id_token": {
      "acr": {
        "value": "urn:mace:incommon:iap:silver",
        "essential": true
      }
    }
  },
  "iss": "d74dcd6c-cfa7-41b5-ad33-837ca6013a9c",
  "response_type": "code",
  "redirect_uri": "https://www.certification.openid.net/test/a/fapipoc_fapi_jarm/callback",
  "state": "vE9Ok3LBgx",
  "exp": 1670945963,
  "nonce": "dEoLlAScxs",
  "client_id": "d74dcd6c-cfa7-41b5-ad33-837ca6013a9c",
  "response_mode": "jwt"
}
header
{
  "kid": "fapips1",
  "alg": "PS256"
}
request_object
eyJraWQiOiJmYXBpcHMxIiwiYWxnIjoiUFMyNTYifQ.eyJpc3MiOiJkNzRkY2Q2Yy1jZmE3LTQxYjUtYWQzMy04MzdjYTYwMTNhOWMiLCJyZXNwb25zZV90eXBlIjoiY29kZSIsIm5vbmNlIjoiZEVvTGxBU2N4cyIsImNsaWVudF9pZCI6ImQ3NGRjZDZjLWNmYTctNDFiNS1hZDMzLTgzN2NhNjAxM2E5YyIsInJlc3BvbnNlX21vZGUiOiJqd3QiLCJhdWQiOiJodHRwczpcL1wvZmFwaXBvYy5yZWwudmFuaXR5dHN0LmNsb3VkaWRlbnRpdHkuaWJtLmNvbVwvb2F1dGgyIiwibmJmIjoxNjcwOTQ1NjYzLCJzY29wZSI6Im9wZW5pZCBlbWFpbCIsImNsYWltcyI6eyJpZF90b2tlbiI6eyJhY3IiOnsidmFsdWUiOiJ1cm46bWFjZTppbmNvbW1vbjppYXA6c2lsdmVyIiwiZXNzZW50aWFsIjp0cnVlfX19LCJyZWRpcmVjdF91cmkiOiJodHRwczpcL1wvd3d3LmNlcnRpZmljYXRpb24ub3BlbmlkLm5ldFwvdGVzdFwvYVwvZmFwaXBvY19mYXBpX2phcm1cL2NhbGxiYWNrIiwic3RhdGUiOiJ2RTlPazNMQmd4IiwiZXhwIjoxNjcwOTQ1OTYzfQ.PgM7sOc32zxSQzDFeS3ZnMfqs24fgnZaSZ2GkD1jfV4t4NSHvGNa6X4u23_Q30kJLtGwFXKEA5tU1-qsY5h1gMvvDvhFkmbesn172LdoVRZQg67BrJcN-MsId7MKV1uXnYf8CZsGhYwrb6NPE8M-WEzKkKWAhycE00wLg998g1rR9QY7zPCfQkoXTiXROVJYZ15795khT-cYsySGlQ-Uqf0AV-vpIUigB4LE_-L3g6IebTyPSSiouUPajcFURVV1ILtAWQnB6POJIsVdhtId0WK8cUFQbRiMW5S6bS91x5zKnI5rZJcn6qilBTaR0BUfVc7ubDxA646Qu5Ulp3OcOw
key
{
  "p": "-JkZq0-X1RAO2UtEohS_gpRIW6vXFq8f_4eldFP7qXQcHzsSfFrul14pXG7grNokcA5S3w7HSBXQXQ7WdVeN-nZSI_232NSyF3GRkiINenSUMoz8_7zKy2MUvo9gW8WkaOlMOv5l8H781ZDfQvMCNjmwb2zE4q8qNbv2ZnA_gfc",
  "kty": "RSA",
  "q": "tj8Ug4uHQnfJEXdNKCPPbUD4kPMNu4T0pAf7lUkZ4Aa56CxKds063qUvdtyPYSiTKlpdAVYibqSyLBauG_RjPDcD6zrziKO93o42mX2Fr4fZJaWFKqlAqA3fZycWyu-VDrjF14QmDUS4NPnnQ7_UuiKYr5o3hO8-iJrW8z4VQJc",
  "d": "j_TQo4CwQ9GHOy2hCJJJfV1rUVxQpWmljB4SNBcJ4cZWbMVc0qRTL9awlgIvFCYmO2H97q3CLJAjigPGNta-TCI1eEbuaTsGrLwsjUrycQz7EIZf_i9rdj3lRhJ-gLpgO2Fj6_hfQLMHQ0yhiHi09FPLpJfPpicqEHwwmwNLQGIwN88c-TDDX2D4Iw3geygigqRnWviDVMejuRL2Luordiw7XOJHzY2BGwqOZdgqYfVS6Dr6PjOaOwWDJ7w9pHT19zz3UEXiarzA-AZKSZtxOoNVSliltj0nIzhVN0fd7g0Ljt13LjrGuyLSrAoTCZdQpCZ0uX02leqFkCAOkCzWlQ",
  "e": "AQAB",
  "use": "sig",
  "kid": "fapips1",
  "qi": "sNIuSo-uVI0TrtcR_6ZdGkps2MIWmVRhqBCKDxJAm21RkW7Sv0buRD8KPSP7WA20KTgs3O9i1Hz6bD8U2Hkjt3rk6MP59JvQev1DxFD8yA_A6aaIHk6Z7BryX5QOJzj0tzIB1tVzrSViVdDg0LUOO5yZdm_IQSU4AN-aaxjrpvA",
  "dp": "NnHJVmRzGz2OEvbSDDFBFAcHpdQHojcuadc6XDS8bAs60Xgtf0Cm-k2r_0tlN1X7HvN0INfquxXT8V17iG1pcc4SBUHezsUeT9YWjIuaqhP4FO4dxqCBRXPoqidach7h9_wILu9iQf59vwQgcVgpRtjxlCWdJQw50VTeDOdOcVc",
  "alg": "PS256",
  "dq": "qwl0dShDnuvQdmXisaM6Dq0FGvQglTZoanFbeXWLpSZq3yyCDhD6CO46J3FD1sk_pGX-Fz0BP5mt5Za7fFzVrTNsqB1BZaFWlkIdl9un1V7HOn-nBKynk5DBc4vJ5lcHKzPZ6TOKirVNs9o9YuXr_Wxuo482P7pQk9_Nj6daRq0",
  "n": "sPoZ2M-WhvDJchlxahAPDtkSaRlXWIK17NF2qHn3RgWUw0Z4XyptMWi-HMwxwwwApCi_g7ytaJ4DBDo5DY-pumFZHdj4mcD8Nb2XhV5smMO3-XABBVAuNH6VW4sFeb6bvlVBNyoHpAA_4VyMCYTjZffxGIqXpyxIND1M5zwP8RaZc1_Yo4yakZa15wXirbwZkCArJaIROpKy5xXFPA_2p4w7PnTQshAqjJx2Jz8N5CKsEvUvHNEg7pfeL1hTqLk1KRpLRh8QZKwfEjuxg0KFIGmi45gAX8SCjjX-BBffN6C7VELESRzILSlCEbTL_hslQkSQNbmyqI--kWCgkTZosQ"
}
2022-12-13 15:34:23 SUCCESS
BuildRequestObjectByValueRedirectToAuthorizationEndpoint
Sending to authorization endpoint
redirect_to_authorization_endpoint
https://fapipoc.rel.vanitytst.cloudidentity.ibm.com/oauth2/authorize?request=eyJraWQiOiJmYXBpcHMxIiwiYWxnIjoiUFMyNTYifQ.eyJpc3MiOiJkNzRkY2Q2Yy1jZmE3LTQxYjUtYWQzMy04MzdjYTYwMTNhOWMiLCJyZXNwb25zZV90eXBlIjoiY29kZSIsIm5vbmNlIjoiZEVvTGxBU2N4cyIsImNsaWVudF9pZCI6ImQ3NGRjZDZjLWNmYTctNDFiNS1hZDMzLTgzN2NhNjAxM2E5YyIsInJlc3BvbnNlX21vZGUiOiJqd3QiLCJhdWQiOiJodHRwczpcL1wvZmFwaXBvYy5yZWwudmFuaXR5dHN0LmNsb3VkaWRlbnRpdHkuaWJtLmNvbVwvb2F1dGgyIiwibmJmIjoxNjcwOTQ1NjYzLCJzY29wZSI6Im9wZW5pZCBlbWFpbCIsImNsYWltcyI6eyJpZF90b2tlbiI6eyJhY3IiOnsidmFsdWUiOiJ1cm46bWFjZTppbmNvbW1vbjppYXA6c2lsdmVyIiwiZXNzZW50aWFsIjp0cnVlfX19LCJyZWRpcmVjdF91cmkiOiJodHRwczpcL1wvd3d3LmNlcnRpZmljYXRpb24ub3BlbmlkLm5ldFwvdGVzdFwvYVwvZmFwaXBvY19mYXBpX2phcm1cL2NhbGxiYWNrIiwic3RhdGUiOiJ2RTlPazNMQmd4IiwiZXhwIjoxNjcwOTQ1OTYzfQ.PgM7sOc32zxSQzDFeS3ZnMfqs24fgnZaSZ2GkD1jfV4t4NSHvGNa6X4u23_Q30kJLtGwFXKEA5tU1-qsY5h1gMvvDvhFkmbesn172LdoVRZQg67BrJcN-MsId7MKV1uXnYf8CZsGhYwrb6NPE8M-WEzKkKWAhycE00wLg998g1rR9QY7zPCfQkoXTiXROVJYZ15795khT-cYsySGlQ-Uqf0AV-vpIUigB4LE_-L3g6IebTyPSSiouUPajcFURVV1ILtAWQnB6POJIsVdhtId0WK8cUFQbRiMW5S6bS91x5zKnI5rZJcn6qilBTaR0BUfVc7ubDxA646Qu5Ulp3OcOw&client_id=d74dcd6c-cfa7-41b5-ad33-837ca6013a9c&redirect_uri=https://www.certification.openid.net/test/a/fapipoc_fapi_jarm/callback&scope=openid%20email&response_type=code
2022-12-13 15:34:23 REDIRECT
fapi1-advanced-final-attempt-reuse-authorisation-code-after-one-second
Redirecting to authorization endpoint
redirect_to
https://fapipoc.rel.vanitytst.cloudidentity.ibm.com/oauth2/authorize?request=eyJraWQiOiJmYXBpcHMxIiwiYWxnIjoiUFMyNTYifQ.eyJpc3MiOiJkNzRkY2Q2Yy1jZmE3LTQxYjUtYWQzMy04MzdjYTYwMTNhOWMiLCJyZXNwb25zZV90eXBlIjoiY29kZSIsIm5vbmNlIjoiZEVvTGxBU2N4cyIsImNsaWVudF9pZCI6ImQ3NGRjZDZjLWNmYTctNDFiNS1hZDMzLTgzN2NhNjAxM2E5YyIsInJlc3BvbnNlX21vZGUiOiJqd3QiLCJhdWQiOiJodHRwczpcL1wvZmFwaXBvYy5yZWwudmFuaXR5dHN0LmNsb3VkaWRlbnRpdHkuaWJtLmNvbVwvb2F1dGgyIiwibmJmIjoxNjcwOTQ1NjYzLCJzY29wZSI6Im9wZW5pZCBlbWFpbCIsImNsYWltcyI6eyJpZF90b2tlbiI6eyJhY3IiOnsidmFsdWUiOiJ1cm46bWFjZTppbmNvbW1vbjppYXA6c2lsdmVyIiwiZXNzZW50aWFsIjp0cnVlfX19LCJyZWRpcmVjdF91cmkiOiJodHRwczpcL1wvd3d3LmNlcnRpZmljYXRpb24ub3BlbmlkLm5ldFwvdGVzdFwvYVwvZmFwaXBvY19mYXBpX2phcm1cL2NhbGxiYWNrIiwic3RhdGUiOiJ2RTlPazNMQmd4IiwiZXhwIjoxNjcwOTQ1OTYzfQ.PgM7sOc32zxSQzDFeS3ZnMfqs24fgnZaSZ2GkD1jfV4t4NSHvGNa6X4u23_Q30kJLtGwFXKEA5tU1-qsY5h1gMvvDvhFkmbesn172LdoVRZQg67BrJcN-MsId7MKV1uXnYf8CZsGhYwrb6NPE8M-WEzKkKWAhycE00wLg998g1rR9QY7zPCfQkoXTiXROVJYZ15795khT-cYsySGlQ-Uqf0AV-vpIUigB4LE_-L3g6IebTyPSSiouUPajcFURVV1ILtAWQnB6POJIsVdhtId0WK8cUFQbRiMW5S6bS91x5zKnI5rZJcn6qilBTaR0BUfVc7ubDxA646Qu5Ulp3OcOw&client_id=d74dcd6c-cfa7-41b5-ad33-837ca6013a9c&redirect_uri=https://www.certification.openid.net/test/a/fapipoc_fapi_jarm/callback&scope=openid%20email&response_type=code
2022-12-13 15:36:10 INCOMING
fapi1-advanced-final-attempt-reuse-authorisation-code-after-one-second
Incoming HTTP request to /test/a/fapipoc_fapi_jarm/callback
incoming_headers
{
  "host": "www.certification.openid.net",
  "upgrade-insecure-requests": "1",
  "dnt": "1",
  "user-agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36",
  "accept": "text/html,application/xhtml+xml,application/xml;q\u003d0.9,image/avif,image/webp,image/apng,*/*;q\u003d0.8,application/signed-exchange;v\u003db3;q\u003d0.9",
  "sec-fetch-site": "cross-site",
  "sec-fetch-mode": "navigate",
  "sec-fetch-user": "?1",
  "sec-fetch-dest": "document",
  "sec-ch-ua": "\"Not?A_Brand\";v\u003d\"8\", \"Chromium\";v\u003d\"108\", \"Google Chrome\";v\u003d\"108\"",
  "sec-ch-ua-mobile": "?0",
  "sec-ch-ua-platform": "\"Windows\"",
  "referer": "https://www.certification.openid.net/",
  "accept-encoding": "gzip, deflate, br",
  "accept-language": "en-US,en;q\u003d0.9",
  "cookie": "__utma\u003d201319536.2028225024.1670897618.1670897618.1670897618.1; __utmc\u003d201319536; __utmz\u003d201319536.1670897618.1.1.utmcsr\u003d(direct)|utmccn\u003d(direct)|utmcmd\u003d(none); JSESSIONID\u003dAEE4ACEEF6C995EA545CE88C618BBB9C",
  "connection": "close"
}
incoming_path
/test/a/fapipoc_fapi_jarm/callback
incoming_body_form_params
incoming_method
GET
incoming_tls_version
TLSv1.2
incoming_tls_cert
incoming_query_string_params
{
  "response": "eyJhbGciOiJQUzI1NiIsImtpZCI6InNlcnZlciJ9.eyJhdWQiOiJkNzRkY2Q2Yy1jZmE3LTQxYjUtYWQzMy04MzdjYTYwMTNhOWMiLCJjb2RlIjoiYUtLV1Y4elYxdWpQTmZBc3ptV2Iyc1RscUhDREtZSHBQWk1RT3pIOFR6US5CeGR5RTFYWko2RlNVV1QxNjZZNE8xNmJRbldTUnBkYU1zNTVGSV9NY1VsdndadldnSTU1czZ1MnRtbFEzUmFSdUs1ZkU0OWswLVpYUlAyUjRFcmNxUSIsImV4cCI6MTY3MDk0NjA3MCwiaWF0IjoxNjcwOTQ1NzcwLCJpc3MiOiJodHRwczovL2ZhcGlwb2MucmVsLnZhbml0eXRzdC5jbG91ZGlkZW50aXR5LmlibS5jb20vb2F1dGgyIiwianRpIjoiYWFlMDFjN2UtYmQ3ZS00ZjUxLWFjN2ItNzU1M2UwMzdjNzAwIiwic3RhdGUiOiJ2RTlPazNMQmd4In0.XfetpHCWBKCQ8p4Nts-fbNAeOTVt3tt-iPii5fvr8kbHFzpZWiFNw5T9hG16IT5F4GpF1IqIUxStJTmQYnbqpayj5HgQnZRnEXsLnZ3H3SK13EJStytUFkPWS9uruSxAXnHiaePYRcAlzbb5asIKS0nqg6wSdRab2QfEevzEuVITQmjPzmkKE1bOqT5Jg9ppWWZzu6J4lesK9qcWOOBaRnDTn7ELrFfnrz7y86-Dhp5i2UWhi01Nar4Uohfa7OXx59_9o2DnxdRJLBqbd4B4dyUVIb0_oy-lHKl_Bvn0BGtzrgcl1cMx0qMCx85oqq8vgUpvpj7Dkkv_bicqkM3OrQ"
}
incoming_body
incoming_tls_chain
[
  "CONFORMANCE_SUITE_JSON_NULL",
  "CONFORMANCE_SUITE_JSON_NULL",
  "CONFORMANCE_SUITE_JSON_NULL",
  "CONFORMANCE_SUITE_JSON_NULL",
  "CONFORMANCE_SUITE_JSON_NULL",
  "CONFORMANCE_SUITE_JSON_NULL"
]
incoming_tls_cipher
ECDHE-RSA-AES128-GCM-SHA256
incoming_body_json
2022-12-13 15:36:10 SUCCESS
CreateRandomImplicitSubmitUrl
Created random implicit submission URL
implicit_submit
{
  "path": "implicit/Vt3DJxW6CER7SGS1oWsu",
  "fullUrl": "https://www.certification.openid.net/test/a/fapipoc_fapi_jarm/implicit/Vt3DJxW6CER7SGS1oWsu"
}
2022-12-13 15:36:10 OUTGOING
fapi1-advanced-final-attempt-reuse-authorisation-code-after-one-second
Response to HTTP request to test instance uXqmOQoi1qW9UG5
outgoing
ModelAndView [view="implicitCallback"; model={implicitSubmitUrl=https://www.certification.openid.net/test/a/fapipoc_fapi_jarm/implicit/Vt3DJxW6CER7SGS1oWsu, returnUrl=/log-detail.html?log=uXqmOQoi1qW9UG5}]
outgoing_path
callback
2022-12-13 15:36:11 INCOMING
fapi1-advanced-final-attempt-reuse-authorisation-code-after-one-second
Incoming HTTP request to /test/a/fapipoc_fapi_jarm/implicit/Vt3DJxW6CER7SGS1oWsu
incoming_headers
{
  "host": "www.certification.openid.net",
  "sec-ch-ua": "\"Not?A_Brand\";v\u003d\"8\", \"Chromium\";v\u003d\"108\", \"Google Chrome\";v\u003d\"108\"",
  "dnt": "1",
  "sec-ch-ua-mobile": "?0",
  "user-agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36",
  "content-type": "text/plain",
  "accept": "*/*",
  "x-requested-with": "XMLHttpRequest",
  "sec-ch-ua-platform": "\"Windows\"",
  "origin": "https://www.certification.openid.net",
  "sec-fetch-site": "same-origin",
  "sec-fetch-mode": "cors",
  "sec-fetch-dest": "empty",
  "referer": "https://www.certification.openid.net/test/a/fapipoc_fapi_jarm/callback?response\u003deyJhbGciOiJQUzI1NiIsImtpZCI6InNlcnZlciJ9.eyJhdWQiOiJkNzRkY2Q2Yy1jZmE3LTQxYjUtYWQzMy04MzdjYTYwMTNhOWMiLCJjb2RlIjoiYUtLV1Y4elYxdWpQTmZBc3ptV2Iyc1RscUhDREtZSHBQWk1RT3pIOFR6US5CeGR5RTFYWko2RlNVV1QxNjZZNE8xNmJRbldTUnBkYU1zNTVGSV9NY1VsdndadldnSTU1czZ1MnRtbFEzUmFSdUs1ZkU0OWswLVpYUlAyUjRFcmNxUSIsImV4cCI6MTY3MDk0NjA3MCwiaWF0IjoxNjcwOTQ1NzcwLCJpc3MiOiJodHRwczovL2ZhcGlwb2MucmVsLnZhbml0eXRzdC5jbG91ZGlkZW50aXR5LmlibS5jb20vb2F1dGgyIiwianRpIjoiYWFlMDFjN2UtYmQ3ZS00ZjUxLWFjN2ItNzU1M2UwMzdjNzAwIiwic3RhdGUiOiJ2RTlPazNMQmd4In0.XfetpHCWBKCQ8p4Nts-fbNAeOTVt3tt-iPii5fvr8kbHFzpZWiFNw5T9hG16IT5F4GpF1IqIUxStJTmQYnbqpayj5HgQnZRnEXsLnZ3H3SK13EJStytUFkPWS9uruSxAXnHiaePYRcAlzbb5asIKS0nqg6wSdRab2QfEevzEuVITQmjPzmkKE1bOqT5Jg9ppWWZzu6J4lesK9qcWOOBaRnDTn7ELrFfnrz7y86-Dhp5i2UWhi01Nar4Uohfa7OXx59_9o2DnxdRJLBqbd4B4dyUVIb0_oy-lHKl_Bvn0BGtzrgcl1cMx0qMCx85oqq8vgUpvpj7Dkkv_bicqkM3OrQ",
  "accept-encoding": "gzip, deflate, br",
  "accept-language": "en-US,en;q\u003d0.9",
  "cookie": "__utma\u003d201319536.2028225024.1670897618.1670897618.1670897618.1; __utmc\u003d201319536; __utmz\u003d201319536.1670897618.1.1.utmcsr\u003d(direct)|utmccn\u003d(direct)|utmcmd\u003d(none); JSESSIONID\u003dAEE4ACEEF6C995EA545CE88C618BBB9C",
  "connection": "close",
  "content-length": "0"
}
incoming_path
/test/a/fapipoc_fapi_jarm/implicit/Vt3DJxW6CER7SGS1oWsu
incoming_body_form_params
incoming_method
POST
incoming_tls_version
TLSv1.2
incoming_tls_cert
incoming_query_string_params
{}
incoming_body
incoming_tls_chain
[
  "CONFORMANCE_SUITE_JSON_NULL",
  "CONFORMANCE_SUITE_JSON_NULL",
  "CONFORMANCE_SUITE_JSON_NULL",
  "CONFORMANCE_SUITE_JSON_NULL",
  "CONFORMANCE_SUITE_JSON_NULL",
  "CONFORMANCE_SUITE_JSON_NULL"
]
incoming_tls_cipher
ECDHE-RSA-AES128-GCM-SHA256
incoming_body_json
2022-12-13 15:36:11 OUTGOING
fapi1-advanced-final-attempt-reuse-authorisation-code-after-one-second
Response to HTTP request to test instance uXqmOQoi1qW9UG5
outgoing_status_code
204
outgoing_headers
{}
outgoing_body

                                
outgoing_path
implicit/Vt3DJxW6CER7SGS1oWsu
2022-12-13 15:36:11 SUCCESS
ExtractImplicitHashToCallbackResponse
implicit_hash is empty
2022-12-13 15:36:11 REDIRECT-IN
fapi1-advanced-final-attempt-reuse-authorisation-code-after-one-second
Authorization endpoint response captured
url_query
{
  "response": "eyJhbGciOiJQUzI1NiIsImtpZCI6InNlcnZlciJ9.eyJhdWQiOiJkNzRkY2Q2Yy1jZmE3LTQxYjUtYWQzMy04MzdjYTYwMTNhOWMiLCJjb2RlIjoiYUtLV1Y4elYxdWpQTmZBc3ptV2Iyc1RscUhDREtZSHBQWk1RT3pIOFR6US5CeGR5RTFYWko2RlNVV1QxNjZZNE8xNmJRbldTUnBkYU1zNTVGSV9NY1VsdndadldnSTU1czZ1MnRtbFEzUmFSdUs1ZkU0OWswLVpYUlAyUjRFcmNxUSIsImV4cCI6MTY3MDk0NjA3MCwiaWF0IjoxNjcwOTQ1NzcwLCJpc3MiOiJodHRwczovL2ZhcGlwb2MucmVsLnZhbml0eXRzdC5jbG91ZGlkZW50aXR5LmlibS5jb20vb2F1dGgyIiwianRpIjoiYWFlMDFjN2UtYmQ3ZS00ZjUxLWFjN2ItNzU1M2UwMzdjNzAwIiwic3RhdGUiOiJ2RTlPazNMQmd4In0.XfetpHCWBKCQ8p4Nts-fbNAeOTVt3tt-iPii5fvr8kbHFzpZWiFNw5T9hG16IT5F4GpF1IqIUxStJTmQYnbqpayj5HgQnZRnEXsLnZ3H3SK13EJStytUFkPWS9uruSxAXnHiaePYRcAlzbb5asIKS0nqg6wSdRab2QfEevzEuVITQmjPzmkKE1bOqT5Jg9ppWWZzu6J4lesK9qcWOOBaRnDTn7ELrFfnrz7y86-Dhp5i2UWhi01Nar4Uohfa7OXx59_9o2DnxdRJLBqbd4B4dyUVIb0_oy-lHKl_Bvn0BGtzrgcl1cMx0qMCx85oqq8vgUpvpj7Dkkv_bicqkM3OrQ"
}
headers
{
  "host": "www.certification.openid.net",
  "upgrade-insecure-requests": "1",
  "dnt": "1",
  "user-agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36",
  "accept": "text/html,application/xhtml+xml,application/xml;q\u003d0.9,image/avif,image/webp,image/apng,*/*;q\u003d0.8,application/signed-exchange;v\u003db3;q\u003d0.9",
  "sec-fetch-site": "cross-site",
  "sec-fetch-mode": "navigate",
  "sec-fetch-user": "?1",
  "sec-fetch-dest": "document",
  "sec-ch-ua": "\"Not?A_Brand\";v\u003d\"8\", \"Chromium\";v\u003d\"108\", \"Google Chrome\";v\u003d\"108\"",
  "sec-ch-ua-mobile": "?0",
  "sec-ch-ua-platform": "\"Windows\"",
  "referer": "https://www.certification.openid.net/",
  "accept-encoding": "gzip, deflate, br",
  "accept-language": "en-US,en;q\u003d0.9",
  "cookie": "__utma\u003d201319536.2028225024.1670897618.1670897618.1670897618.1; __utmc\u003d201319536; __utmz\u003d201319536.1670897618.1.1.utmcsr\u003d(direct)|utmccn\u003d(direct)|utmcmd\u003d(none); JSESSIONID\u003dAEE4ACEEF6C995EA545CE88C618BBB9C",
  "x-ssl-cipher": "ECDHE-RSA-AES128-GCM-SHA256",
  "x-ssl-protocol": "TLSv1.2",
  "x-forwarded-proto": "https",
  "x-forwarded-port": "443",
  "connection": "close",
  "x-forwarded-host": "www.certification.openid.net",
  "x-forwarded-server": "www.certification.openid.net"
}
http_method
GET
url_fragment
{}
post_body
Verify authorization endpoint response
2022-12-13 15:36:11 SUCCESS
ExtractJARMFromURLQuery
Found and parsed the jarm_response from callback_query_params
value
eyJhbGciOiJQUzI1NiIsImtpZCI6InNlcnZlciJ9.eyJhdWQiOiJkNzRkY2Q2Yy1jZmE3LTQxYjUtYWQzMy04MzdjYTYwMTNhOWMiLCJjb2RlIjoiYUtLV1Y4elYxdWpQTmZBc3ptV2Iyc1RscUhDREtZSHBQWk1RT3pIOFR6US5CeGR5RTFYWko2RlNVV1QxNjZZNE8xNmJRbldTUnBkYU1zNTVGSV9NY1VsdndadldnSTU1czZ1MnRtbFEzUmFSdUs1ZkU0OWswLVpYUlAyUjRFcmNxUSIsImV4cCI6MTY3MDk0NjA3MCwiaWF0IjoxNjcwOTQ1NzcwLCJpc3MiOiJodHRwczovL2ZhcGlwb2MucmVsLnZhbml0eXRzdC5jbG91ZGlkZW50aXR5LmlibS5jb20vb2F1dGgyIiwianRpIjoiYWFlMDFjN2UtYmQ3ZS00ZjUxLWFjN2ItNzU1M2UwMzdjNzAwIiwic3RhdGUiOiJ2RTlPazNMQmd4In0.XfetpHCWBKCQ8p4Nts-fbNAeOTVt3tt-iPii5fvr8kbHFzpZWiFNw5T9hG16IT5F4GpF1IqIUxStJTmQYnbqpayj5HgQnZRnEXsLnZ3H3SK13EJStytUFkPWS9uruSxAXnHiaePYRcAlzbb5asIKS0nqg6wSdRab2QfEevzEuVITQmjPzmkKE1bOqT5Jg9ppWWZzu6J4lesK9qcWOOBaRnDTn7ELrFfnrz7y86-Dhp5i2UWhi01Nar4Uohfa7OXx59_9o2DnxdRJLBqbd4B4dyUVIb0_oy-lHKl_Bvn0BGtzrgcl1cMx0qMCx85oqq8vgUpvpj7Dkkv_bicqkM3OrQ
header
{
  "kid": "server",
  "alg": "PS256"
}
claims
{
  "aud": "d74dcd6c-cfa7-41b5-ad33-837ca6013a9c",
  "code": "aKKWV8zV1ujPNfAszmWb2sTlqHCDKYHpPZMQOzH8TzQ.BxdyE1XZJ6FSUWT166Y4O16bQnWSRpdaMs55FI_McUlvwZvWgI55s6u2tmlQ3RaRuK5fE49k0-ZXRP2R4ErcqQ",
  "iss": "https://fapipoc.rel.vanitytst.cloudidentity.ibm.com/oauth2",
  "state": "vE9Ok3LBgx",
  "exp": 1670946070,
  "iat": 1670945770,
  "jti": "aae01c7e-bd7e-4f51-ac7b-7553e037c700"
}
2022-12-13 15:36:11 SUCCESS
RejectNonJarmResponsesInUrlQuery
Authorization endpoint response only includes the JARM JWT.
2022-12-13 15:36:11 SUCCESS
ExtractAuthorizationEndpointResponseFromJARMResponse
Extracted the authorization response
code
aKKWV8zV1ujPNfAszmWb2sTlqHCDKYHpPZMQOzH8TzQ.BxdyE1XZJ6FSUWT166Y4O16bQnWSRpdaMs55FI_McUlvwZvWgI55s6u2tmlQ3RaRuK5fE49k0-ZXRP2R4ErcqQ
iss
https://fapipoc.rel.vanitytst.cloudidentity.ibm.com/oauth2
state
vE9Ok3LBgx
2022-12-13 15:36:11 SUCCESS
ValidateJARMResponse
JARM response standard JWT claims are valid
2022-12-13 15:36:11 SUCCESS
FAPI1ValidateJarmSigningAlg
JARM response was signed with a permitted algorithm
permitted
[
  "PS256",
  "ES256"
]
alg
PS256
2022-12-13 15:36:11 SUCCESS
ValidateJARMExpRecommendations
JARM response 'exp' is less than 10 minutes
now
"Dec 13, 2022, 3:36:11 PM"
expiration
"Dec 13, 2022, 3:41:10 PM"
2022-12-13 15:36:11 SUCCESS
ValidateJARMSignatureUsingKid
jarm_response signature validated
jarm_response
eyJhbGciOiJQUzI1NiIsImtpZCI6InNlcnZlciJ9.eyJhdWQiOiJkNzRkY2Q2Yy1jZmE3LTQxYjUtYWQzMy04MzdjYTYwMTNhOWMiLCJjb2RlIjoiYUtLV1Y4elYxdWpQTmZBc3ptV2Iyc1RscUhDREtZSHBQWk1RT3pIOFR6US5CeGR5RTFYWko2RlNVV1QxNjZZNE8xNmJRbldTUnBkYU1zNTVGSV9NY1VsdndadldnSTU1czZ1MnRtbFEzUmFSdUs1ZkU0OWswLVpYUlAyUjRFcmNxUSIsImV4cCI6MTY3MDk0NjA3MCwiaWF0IjoxNjcwOTQ1NzcwLCJpc3MiOiJodHRwczovL2ZhcGlwb2MucmVsLnZhbml0eXRzdC5jbG91ZGlkZW50aXR5LmlibS5jb20vb2F1dGgyIiwianRpIjoiYWFlMDFjN2UtYmQ3ZS00ZjUxLWFjN2ItNzU1M2UwMzdjNzAwIiwic3RhdGUiOiJ2RTlPazNMQmd4In0.XfetpHCWBKCQ8p4Nts-fbNAeOTVt3tt-iPii5fvr8kbHFzpZWiFNw5T9hG16IT5F4GpF1IqIUxStJTmQYnbqpayj5HgQnZRnEXsLnZ3H3SK13EJStytUFkPWS9uruSxAXnHiaePYRcAlzbb5asIKS0nqg6wSdRab2QfEevzEuVITQmjPzmkKE1bOqT5Jg9ppWWZzu6J4lesK9qcWOOBaRnDTn7ELrFfnrz7y86-Dhp5i2UWhi01Nar4Uohfa7OXx59_9o2DnxdRJLBqbd4B4dyUVIb0_oy-lHKl_Bvn0BGtzrgcl1cMx0qMCx85oqq8vgUpvpj7Dkkv_bicqkM3OrQ
2022-12-13 15:36:11 SUCCESS
RejectAuthCodeInUrlQuery
Authorization code is not present in URL query returned from authorization endpoint
2022-12-13 15:36:11 SUCCESS
CheckMatchingCallbackParameters
Callback parameters successfully verified
2022-12-13 15:36:11 SUCCESS
RejectStateInUrlQueryForHybridFlow
state is correctly not present in URL query returned from authorization endpoint (as in the hybrid flow it must be returned in the URL fragment/hash only)
2022-12-13 15:36:11 SUCCESS
CheckIfAuthorizationEndpointError
No error from authorization endpoint
2022-12-13 15:36:11 SUCCESS
ValidateSuccessfulJARMResponseFromAuthorizationEndpoint
authorization endpoint response does not include unexpected parameters
code
aKKWV8zV1ujPNfAszmWb2sTlqHCDKYHpPZMQOzH8TzQ.BxdyE1XZJ6FSUWT166Y4O16bQnWSRpdaMs55FI_McUlvwZvWgI55s6u2tmlQ3RaRuK5fE49k0-ZXRP2R4ErcqQ
iss
https://fapipoc.rel.vanitytst.cloudidentity.ibm.com/oauth2
state
vE9Ok3LBgx
2022-12-13 15:36:11 SUCCESS
CheckStateInAuthorizationResponse
State in response correctly returned
state
vE9Ok3LBgx
2022-12-13 15:36:11 SUCCESS
ValidateIssInAuthorizationResponse
'iss' parameter in authorization response matches server's issuer value.
2022-12-13 15:36:11 SUCCESS
ExtractAuthorizationCodeFromAuthorizationResponse
Found authorization code
code
aKKWV8zV1ujPNfAszmWb2sTlqHCDKYHpPZMQOzH8TzQ.BxdyE1XZJ6FSUWT166Y4O16bQnWSRpdaMs55FI_McUlvwZvWgI55s6u2tmlQ3RaRuK5fE49k0-ZXRP2R4ErcqQ
2022-12-13 15:36:11 SUCCESS
EnsureMinimumAuthorizationCodeLength
Authorization code is of sufficient length
actual
1040
required
128
2022-12-13 15:36:11 SUCCESS
EnsureMinimumAuthorizationCodeEntropy
Calculated shannon entropy seems sufficient
actual
733.3107382998805
expected
96.0
value
aKKWV8zV1ujPNfAszmWb2sTlqHCDKYHpPZMQOzH8TzQ.BxdyE1XZJ6FSUWT166Y4O16bQnWSRpdaMs55FI_McUlvwZvWgI55s6u2tmlQ3RaRuK5fE49k0-ZXRP2R4ErcqQ
Call token endpoint
2022-12-13 15:36:11 SUCCESS
CreateTokenEndpointRequestForAuthorizationCodeGrant
Created token endpoint request
grant_type
authorization_code
code
aKKWV8zV1ujPNfAszmWb2sTlqHCDKYHpPZMQOzH8TzQ.BxdyE1XZJ6FSUWT166Y4O16bQnWSRpdaMs55FI_McUlvwZvWgI55s6u2tmlQ3RaRuK5fE49k0-ZXRP2R4ErcqQ
redirect_uri
https://www.certification.openid.net/test/a/fapipoc_fapi_jarm/callback
2022-12-13 15:36:11
AddClientIdToTokenEndpointRequest
grant_type
authorization_code
code
aKKWV8zV1ujPNfAszmWb2sTlqHCDKYHpPZMQOzH8TzQ.BxdyE1XZJ6FSUWT166Y4O16bQnWSRpdaMs55FI_McUlvwZvWgI55s6u2tmlQ3RaRuK5fE49k0-ZXRP2R4ErcqQ
redirect_uri
https://www.certification.openid.net/test/a/fapipoc_fapi_jarm/callback
client_id
d74dcd6c-cfa7-41b5-ad33-837ca6013a9c
2022-12-13 15:36:11
CallTokenEndpoint
HTTP request
request_uri
https://fapipoc.rel.vanitytst.cloudidentity.ibm.com/oauth2/token
request_method
POST
request_headers
{
  "accept": "application/json",
  "content-type": "application/x-www-form-urlencoded;charset\u003dUTF-8",
  "content-length": "310"
}
request_body
grant_type=authorization_code&code=aKKWV8zV1ujPNfAszmWb2sTlqHCDKYHpPZMQOzH8TzQ.BxdyE1XZJ6FSUWT166Y4O16bQnWSRpdaMs55FI_McUlvwZvWgI55s6u2tmlQ3RaRuK5fE49k0-ZXRP2R4ErcqQ&redirect_uri=https%3A%2F%2Fwww.certification.openid.net%2Ftest%2Fa%2Ffapipoc_fapi_jarm%2Fcallback&client_id=d74dcd6c-cfa7-41b5-ad33-837ca6013a9c
request_mutual_tls
{
  "cert": "MIID2TCCA36gAwIBAgIULVRuRCMrxxQ2YhrJ+h9vwtSuO/QwCgYIKoZIzj0EAwIwgYExCzAJBgNVBAYTAlVTMREwDwYDVQQIDAhOZXcgWW9yazE0MDIGA1UECgwrSW50ZXJuYXRpb25hbCBCdXNpbmVzcyBNYWNoaW5lcyBDb3Jwb3JhdGlvbjEpMCcGA1UEAwwgSUJNIFNlY3VyaXR5IFZlcmlmeSBSZWwtSVRFIENBLTEwHhcNMjIxMjEyMDMxNjAwWhcNMjUxMjExMDMxNjAwWjB0MQswCQYDVQQGEwJTRzETMBEGA1UECBMKa2NhMmNzci1TVDESMBAGA1UEBxMJa2NhMmNzci1MMRIwEAYDVQQKEwlrY2EyY3NyLU8xEzARBgNVBAsTCmtjYTJjc3ItT1UxEzARBgNVBAMTCmtjYTJjc3ItQ04wggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDA8kHL4ANRJU2aW+r4S/5KCmYXgK5OBvvWlgxxwQAVvU/gn/0SoB05rdMRdf/RTQXq3LnvFu/7bA3RkjoKfti6HcD5RxFMm4Lo3jQ4ZtTxrNLIh609ilhkXL3SmkxNuqF0S2WX8FZ62bhxBCS7HAjVbv32ROk92ARPtS5I/mTyo6W2WLmdtpC5J3W6MwMsLpgqPvYB/qo+TEhKiWb2N6XIm+a96CvRuhzH717U97gbR6EhkToNdsh65dZ+0TAIo58Q2ykA8tBhx/T1qk8HKr4jDRbOu/AG6HbsvMuKQrhOdlfc+2AnLnmmxGnLzmmIq9YlCVKO3oJZsiWfiZ+9kflLAgMBAAGjggETMIIBDzAOBgNVHQ8BAf8EBAMCBaAwEwYDVR0lBAwwCgYIKwYBBQUHAwIwDAYDVR0TAQH/BAIwADAdBgNVHQ4EFgQUar6U6YaPLwKeCPOwxzzbNeoTSpUwHwYDVR0jBBgwFoAUy63c0QU2r5F/Z4cdgCgXKPJk+KMwgZkGA1UdEQSBkTCBjoIPd3d3LmV4YW1wbGUuY29tghB0ZXN0LmV4YW1wbGUuY29tghBtYWlsLmV4YW1wbGUuY29tgg93d3cuZXhhbXBsZS5uZXSBE3NoYW5rYXJ2QHNnLmlibS5jb22HBMAAAgGHBMYzZP6HECABDbgAAAAAAAAAAAAAAAGGE2h0dHBzOi8vamtlLmNvbS9mb28wCgYIKoZIzj0EAwIDSQAwRgIhAKD9ml0OBpiloVebUI66xdTxEFwNMgC3BlF3RkTlDG9tAiEAgJVOZFa6grAMPA+yskk267DSu3cx0LBNrGlBncdDoZk\u003d",
  "key": "MIIEogIBAAKCAQEAwPJBy+ADUSVNmlvq+Ev+SgpmF4CuTgb71pYMccEAFb1P4J/9EqAdOa3TEXX/0U0F6ty57xbv+2wN0ZI6Cn7Yuh3A+UcRTJuC6N40OGbU8azSyIetPYpYZFy90ppMTbqhdEtll/BWetm4cQQkuxwI1W799kTpPdgET7UuSP5k8qOltli5nbaQuSd1ujMDLC6YKj72Af6qPkxISolm9jelyJvmvegr0bocx+9e1Pe4G0ehIZE6DXbIeuXWftEwCKOfENspAPLQYcf09apPByq+Iw0WzrvwBuh27LzLikK4TnZX3PtgJy55psRpy85piKvWJQlSjt6CWbIln4mfvZH5SwIDAQABAoIBAGfIJtH1nXMhQHudo2aI4a+LplxP7/GyWfWTYgAx0szetj9ZbvN8whuLPvOuZ7p51ov8y9opmU3AUjJ+l8+baRG6/VhX/JsbLq/5DVelIDcaQYpxSCLI7kCVjdjg+9f3Ye6+u1edg7aysz2+/87RBoNfHyU+7cJBFhiVmN7UTxIfONaVt+gTlW3IPb9xBCLwahIa12w+kSFk9RQZgzi/kUaH20BFZDSzmJsxZSTIG0IL3KwJFM0JFBAHzc14RvAbwGozfoT494qQBVdohaTiid+x7iUrDXgvU95chciL9b7262F3a6wlWO3/a6AVVckzqdgQ27YnIiEcy0s2sukTBTECgYEA/WJiKxvyGXYPsMu/eC5sLM5MGwDMcheru3OV1inB8yIofzviud3n6UXA5sS7qeDEy/sPB9yu8sWDC9+73UXwKYq3+SuEx291koFE0J3PO4sM7UdNRq5N1p3nKzklICbgtumZhtX9aG5wjXu6yXhFIezvnNeHJjcjipsf6iGN0fMCgYEAwvAnkq8lOUxcoCpLKwsWv37M9RyW2zPDixTv9Ddj1wTDnBXYlxzJ5BkL65UAGxTgoESN2mO/ZTk0AnOGJVyYvrDnvY88sRld2jDYK8ALilzUYSoAqAA5dR8y5qS/wAC9yyB1ze7j65lrtIT/I7d442HCM63WDeXATEBVXByWOUkCgYAzVx7q+zOXwxs0yGPYVxemEHrNMeE68N7kEWx3w2g/+ljYRusOnA7kbjTCzXP03M0jQ5BtGGL+X9TIsCGhmQ0rbacPPqkdu9DHyZeG6aLWvrr0zPC0dJbi+IWhdWe3VwlLJpPsBSneYho+IKbdMZhYYmi+j9EbhiqWaA4UY44XzwKBgFFoi441eJ0iJ7h3kSarnddg8+UVCGcIigwGNWNO0nIUOkBv2yDYU/PfBdxfQEkPAfPMTVU7vM1gAzlW11m4/sz8Aftm2xi2mDwrk8tJi0hAFi1xpg6C8XvZCJ/Lg4yCgsBWkPvsXOCiFJmxxP88es6yn7CHU1JAdXsijsNF6PKJAoGAZn9jiGdKVkgtnzHpArY+xxgDvV4p3PRqz5GOopcLLbvS5z1CfHRc/2Hb0ivNf5GlTFuHttZGIadyEqm0FVCoXlfPRq8k5SLYe120+866zZ7eQ7rb4SLm2603F3+Wv1gT5WD2B/9PSD/0ORo5rL4cb4qu4MBm/n0n1PHteZZaGHk\u003d"
}
2022-12-13 15:36:12 RESPONSE
CallTokenEndpoint
HTTP response
response_status_code
200 OK
response_status_text
OK
response_headers
{
  "x-backside-transport": "OK OK",
  "content-type": "application/json;charset\u003dUTF-8",
  "p3p": "CP\u003d\"NON CUR OTPi OUR NOR UNI\"",
  "x-content-type-options": "nosniff",
  "cache-control": "no-store",
  "x-xss-protection": "1; mode\u003dblock",
  "x-correlation-id": "CORR_ID-AK84fe3d5e-02d9-4129-b207-588190510079",
  "pragma": "no-cache",
  "x-global-transaction-id": "efc5c28163989beb33f68a95",
  "content-length": "1553",
  "date": "Tue, 13 Dec 2022 15:36:12 GMT",
  "connection": "close",
  "set-cookie": [
    "CIPD-S-SESSION-ID\u003d0:1:rediscol:LvN3CaN7RgP6mE8w8v3jH8bxhgi+SJWdDgWRyfTcKhU\u003d; Path\u003d/; SameSite\u003dNone; Secure; HttpOnly",
    "CISESSIONIDREL02A\u003dPBC5YS:57871319; Path\u003d/; Domain\u003drel.vanitytst.cloudidentity.ibm.com; Secure; HttpOnly",
    "_abck\u003d3E91C11D7728D3AA64C152BF8BC328CC~-1~YAAQBpMauEMV+4uEAQAAhhIhDAm7CE1X3PpGz7l7Pz44eXuEJlAqmWcRNU0xsakR0BIge/T8dXS7vZn10EkzbbVFVKsXh+ZlGUksZNWfnrNf3ogxyvNfO12J3DLOooCjo2VlhwgTR9al8cKutBQBimO3SJOpmsoXXqGGugvjWUidH5UkWIMWdou4t1WREIoPEbKppBjWSElD45BeNsM0X+h3dhC0UJA841nVwTiswfQtmsq9CAuDDKZdZQB49bRfMv/HBUpQIe5vrc6gaAEjbNZ3KF5UNp81Joj1nlCDkvJhYAlzeU5DvSSBdlGfC1sneNDzhXIgiPAsNH5srzU45yZclz3CwXgNvh+apiL6txlSvCXmQRDjOA\u003d\u003d~-1~-1~-1; Domain\u003d.ibm.com; Path\u003d/; Expires\u003dWed, 13 Dec 2023 15:36:12 GMT; Max-Age\u003d31536000; Secure",
    "bm_sz\u003dF0C9E73F10AB6D322F670228088DB2C8~YAAQBpMauEQV+4uEAQAAhhIhDBKa4hpQGhXCwhmD5NxiQIHMkJsX/vdG35/j2NzdazJyvaQjHjW5vIpUypFtEY4n27IZR9jM5h1lIBJCAiOP2HOKDGTVIhgQL/YzWDG92ZyIuqMAbZAe5kN+Obsjeu3EqgiebrwrgBOSmZDCqG0k8Vs/LjbEfww3gAASAeEspd2UXaWcuY0wSGrLhdMCnaVAfDqSI80dEXrz3dIvX7RK4zH4XLQIR1QYKRcEQ2Nu1Qr6ToO5n9ErU7yJ5hA9u5RjxQDHxpCYkj2+EGY8SMs\u003d~3158081~3223607; Domain\u003d.ibm.com; Path\u003d/; Expires\u003dTue, 13 Dec 2022 19:36:11 GMT; Max-Age\u003d14399; Secure"
  ],
  "server-timing": [
    "cdn-cache; desc\u003dMISS",
    "edge; dur\u003d388",
    "origin; dur\u003d485"
  ],
  "strict-transport-security": "max-age\u003d31536000 ; includeSubDomains"
}
response_body
{"access_token":"r0SaqC-AizQNZ6RDvCXlOA4tm8Jrqv7MZoUu_lGq_pU.b-b3LdYSPM33doi0zvhN5m37s_2h4iL5fgo3EL87O9McsAx_CfrBHEGt2266Nn2NMfW1fT-EAIuXvueP5qBGZQ.M18xNjcwOTQ1NzcyXzE4","expires_in":3599,"id_token":"eyJhbGciOiJQUzI1NiIsImtpZCI6InNlcnZlciJ9.eyJhY3IiOiJ1cm46bWFjZTppbmNvbW1vbjppYXA6c2lsdmVyIiwiYW1yIjpbInBhc3N3b3JkIl0sImF0X2hhc2giOiJobk1nNnhYSE0taHhLLWJFNFY4c0ZRIiwiYXVkIjpbImQ3NGRjZDZjLWNmYTctNDFiNS1hZDMzLTgzN2NhNjAxM2E5YyJdLCJhdXRoX3RpbWUiOjE2NzA5NDU1ODAsImVtYWlsIjoiamhhbGxAbWFpbGluYXRvci5jb20iLCJleHAiOjE2NzA5NTI5NzIsImlhdCI6MTY3MDk0NTc3MiwiaXNzIjoiaHR0cHM6Ly9mYXBpcG9jLnJlbC52YW5pdHl0c3QuY2xvdWRpZGVudGl0eS5pYm0uY29tL29hdXRoMiIsImp0aSI6Ijc2MGE4NDZkLTg1MWItNDQ3OS1iMjRiLTMwN2VhZTc3N2UwMiIsIm5hbWUiOiJKZXNzaWNhIEhhbGwiLCJub25jZSI6ImRFb0xsQVNjeHMiLCJwcmVmZXJyZWRfdXNlcm5hbWUiOiJqaGFsbEBtYWlsaW5hdG9yLmNvbSIsInJhdCI6MTY3MDk0NTc2OCwicmVhbG1OYW1lIjoiY2xvdWRJZGVudGl0eVJlYWxtIiwicnRfaGFzaCI6IkFkUEhuZXM5M19XdWRyM2xyQlZLcVEiLCJzX2hhc2giOiJSMExqSkUwYl9JeU1BWTU5VXlvTldRIiwic3ViIjoiNjE4MDAxOEVCVCJ9.eOwKoA0KcdSE2D1cjoLqJJAgkYK6q-pw0EIVnLa97btxebV2RZ_p0UYhUri-3KScPupnSxdk_XIujnprNKMCaJ6fNK4J6LEBgOBBXQm9QMjbaJt2RWQPgny8ZtjzWwdllMycpciNLUBhSbpGMoeqyd6Gliau2iHQavut-SaATjAZDmZ113LJFJJImQ9_PrNsLnRo8qog0pg78C9I67-RkQyzUobOU4lNYlgOe24VvEW_9q_ZwYB7iOMxd44VtwJp5I82oN_kibyFNkAmcMjabyihAxt_Se5wVts81brDNv21qrddxKrC_iCf0fKK9bih70lilsCn6R1kKpZiDhrKpQ","refresh_token":"_ZI0wI1trINQxFTCiR8Rf5a1TkqIZSMbmyc5KFO2WDg.7tna7V457pcY43F0UenuGgzah4xBkPQOD_d5-xHthUVIgBzZ0sp_4lEEU_LcA5eFPLbw8K8IE7cmwUOVzczHQQ.M18xNjcwOTQ1NzcyXzE4","scope":"openid email","token_type":"bearer"}
2022-12-13 15:36:12 SUCCESS
CallTokenEndpoint
Parsed token endpoint response
access_token
r0SaqC-AizQNZ6RDvCXlOA4tm8Jrqv7MZoUu_lGq_pU.b-b3LdYSPM33doi0zvhN5m37s_2h4iL5fgo3EL87O9McsAx_CfrBHEGt2266Nn2NMfW1fT-EAIuXvueP5qBGZQ.M18xNjcwOTQ1NzcyXzE4
expires_in
3599
id_token
eyJhbGciOiJQUzI1NiIsImtpZCI6InNlcnZlciJ9.eyJhY3IiOiJ1cm46bWFjZTppbmNvbW1vbjppYXA6c2lsdmVyIiwiYW1yIjpbInBhc3N3b3JkIl0sImF0X2hhc2giOiJobk1nNnhYSE0taHhLLWJFNFY4c0ZRIiwiYXVkIjpbImQ3NGRjZDZjLWNmYTctNDFiNS1hZDMzLTgzN2NhNjAxM2E5YyJdLCJhdXRoX3RpbWUiOjE2NzA5NDU1ODAsImVtYWlsIjoiamhhbGxAbWFpbGluYXRvci5jb20iLCJleHAiOjE2NzA5NTI5NzIsImlhdCI6MTY3MDk0NTc3MiwiaXNzIjoiaHR0cHM6Ly9mYXBpcG9jLnJlbC52YW5pdHl0c3QuY2xvdWRpZGVudGl0eS5pYm0uY29tL29hdXRoMiIsImp0aSI6Ijc2MGE4NDZkLTg1MWItNDQ3OS1iMjRiLTMwN2VhZTc3N2UwMiIsIm5hbWUiOiJKZXNzaWNhIEhhbGwiLCJub25jZSI6ImRFb0xsQVNjeHMiLCJwcmVmZXJyZWRfdXNlcm5hbWUiOiJqaGFsbEBtYWlsaW5hdG9yLmNvbSIsInJhdCI6MTY3MDk0NTc2OCwicmVhbG1OYW1lIjoiY2xvdWRJZGVudGl0eVJlYWxtIiwicnRfaGFzaCI6IkFkUEhuZXM5M19XdWRyM2xyQlZLcVEiLCJzX2hhc2giOiJSMExqSkUwYl9JeU1BWTU5VXlvTldRIiwic3ViIjoiNjE4MDAxOEVCVCJ9.eOwKoA0KcdSE2D1cjoLqJJAgkYK6q-pw0EIVnLa97btxebV2RZ_p0UYhUri-3KScPupnSxdk_XIujnprNKMCaJ6fNK4J6LEBgOBBXQm9QMjbaJt2RWQPgny8ZtjzWwdllMycpciNLUBhSbpGMoeqyd6Gliau2iHQavut-SaATjAZDmZ113LJFJJImQ9_PrNsLnRo8qog0pg78C9I67-RkQyzUobOU4lNYlgOe24VvEW_9q_ZwYB7iOMxd44VtwJp5I82oN_kibyFNkAmcMjabyihAxt_Se5wVts81brDNv21qrddxKrC_iCf0fKK9bih70lilsCn6R1kKpZiDhrKpQ
refresh_token
_ZI0wI1trINQxFTCiR8Rf5a1TkqIZSMbmyc5KFO2WDg.7tna7V457pcY43F0UenuGgzah4xBkPQOD_d5-xHthUVIgBzZ0sp_4lEEU_LcA5eFPLbw8K8IE7cmwUOVzczHQQ.M18xNjcwOTQ1NzcyXzE4
scope
openid email
token_type
bearer
Verify token endpoint response
2022-12-13 15:36:12 SUCCESS
CheckIfTokenEndpointResponseError
No error from token endpoint
2022-12-13 15:36:12 SUCCESS
CheckForAccessTokenValue
Found an access token
access_token
r0SaqC-AizQNZ6RDvCXlOA4tm8Jrqv7MZoUu_lGq_pU.b-b3LdYSPM33doi0zvhN5m37s_2h4iL5fgo3EL87O9McsAx_CfrBHEGt2266Nn2NMfW1fT-EAIuXvueP5qBGZQ.M18xNjcwOTQ1NzcyXzE4
2022-12-13 15:36:12 SUCCESS
ExtractAccessTokenFromTokenResponse
Extracted the access token
value
r0SaqC-AizQNZ6RDvCXlOA4tm8Jrqv7MZoUu_lGq_pU.b-b3LdYSPM33doi0zvhN5m37s_2h4iL5fgo3EL87O9McsAx_CfrBHEGt2266Nn2NMfW1fT-EAIuXvueP5qBGZQ.M18xNjcwOTQ1NzcyXzE4
type
bearer
2022-12-13 15:36:12 SUCCESS
ExtractExpiresInFromTokenEndpointResponse
Extracted 'expires_in'
expires_in
3599
2022-12-13 15:36:12 SUCCESS
ValidateExpiresIn
expires_in passed all validation checks
expires_in
3599
2022-12-13 15:36:12 SUCCESS
CheckForRefreshTokenValue
Found a refresh token
refresh_token
_ZI0wI1trINQxFTCiR8Rf5a1TkqIZSMbmyc5KFO2WDg.7tna7V457pcY43F0UenuGgzah4xBkPQOD_d5-xHthUVIgBzZ0sp_4lEEU_LcA5eFPLbw8K8IE7cmwUOVzczHQQ.M18xNjcwOTQ1NzcyXzE4
2022-12-13 15:36:12 SUCCESS
EnsureMinimumRefreshTokenLength
Refresh token is of sufficient length
actual
1208
required
128
2022-12-13 15:36:12 SUCCESS
EnsureMinimumRefreshTokenEntropy
Calculated shannon entropy seems sufficient
actual
855.4600597344111
expected
96.0
value
_ZI0wI1trINQxFTCiR8Rf5a1TkqIZSMbmyc5KFO2WDg.7tna7V457pcY43F0UenuGgzah4xBkPQOD_d5-xHthUVIgBzZ0sp_4lEEU_LcA5eFPLbw8K8IE7cmwUOVzczHQQ.M18xNjcwOTQ1NzcyXzE4
2022-12-13 15:36:12 SUCCESS
EnsureMinimumAccessTokenLength
Access token is of sufficient length
actual
1208
required
128
2022-12-13 15:36:12 SUCCESS
EnsureMinimumAccessTokenEntropy
Calculated shannon entropy seems sufficient
actual
869.9271971437803
expected
96.0
value
r0SaqC-AizQNZ6RDvCXlOA4tm8Jrqv7MZoUu_lGq_pU.b-b3LdYSPM33doi0zvhN5m37s_2h4iL5fgo3EL87O9McsAx_CfrBHEGt2266Nn2NMfW1fT-EAIuXvueP5qBGZQ.M18xNjcwOTQ1NzcyXzE4
2022-12-13 15:36:12 SUCCESS
ExtractIdTokenFromTokenResponse
Found and parsed the id_token from token_endpoint_response
value
eyJhbGciOiJQUzI1NiIsImtpZCI6InNlcnZlciJ9.eyJhY3IiOiJ1cm46bWFjZTppbmNvbW1vbjppYXA6c2lsdmVyIiwiYW1yIjpbInBhc3N3b3JkIl0sImF0X2hhc2giOiJobk1nNnhYSE0taHhLLWJFNFY4c0ZRIiwiYXVkIjpbImQ3NGRjZDZjLWNmYTctNDFiNS1hZDMzLTgzN2NhNjAxM2E5YyJdLCJhdXRoX3RpbWUiOjE2NzA5NDU1ODAsImVtYWlsIjoiamhhbGxAbWFpbGluYXRvci5jb20iLCJleHAiOjE2NzA5NTI5NzIsImlhdCI6MTY3MDk0NTc3MiwiaXNzIjoiaHR0cHM6Ly9mYXBpcG9jLnJlbC52YW5pdHl0c3QuY2xvdWRpZGVudGl0eS5pYm0uY29tL29hdXRoMiIsImp0aSI6Ijc2MGE4NDZkLTg1MWItNDQ3OS1iMjRiLTMwN2VhZTc3N2UwMiIsIm5hbWUiOiJKZXNzaWNhIEhhbGwiLCJub25jZSI6ImRFb0xsQVNjeHMiLCJwcmVmZXJyZWRfdXNlcm5hbWUiOiJqaGFsbEBtYWlsaW5hdG9yLmNvbSIsInJhdCI6MTY3MDk0NTc2OCwicmVhbG1OYW1lIjoiY2xvdWRJZGVudGl0eVJlYWxtIiwicnRfaGFzaCI6IkFkUEhuZXM5M19XdWRyM2xyQlZLcVEiLCJzX2hhc2giOiJSMExqSkUwYl9JeU1BWTU5VXlvTldRIiwic3ViIjoiNjE4MDAxOEVCVCJ9.eOwKoA0KcdSE2D1cjoLqJJAgkYK6q-pw0EIVnLa97btxebV2RZ_p0UYhUri-3KScPupnSxdk_XIujnprNKMCaJ6fNK4J6LEBgOBBXQm9QMjbaJt2RWQPgny8ZtjzWwdllMycpciNLUBhSbpGMoeqyd6Gliau2iHQavut-SaATjAZDmZ113LJFJJImQ9_PrNsLnRo8qog0pg78C9I67-RkQyzUobOU4lNYlgOe24VvEW_9q_ZwYB7iOMxd44VtwJp5I82oN_kibyFNkAmcMjabyihAxt_Se5wVts81brDNv21qrddxKrC_iCf0fKK9bih70lilsCn6R1kKpZiDhrKpQ
header
{
  "kid": "server",
  "alg": "PS256"
}
claims
{
  "at_hash": "hnMg6xXHM-hxK-bE4V8sFQ",
  "sub": "6180018EBT",
  "rat": 1670945768,
  "realmName": "cloudIdentityRealm",
  "amr": [
    "password"
  ],
  "iss": "https://fapipoc.rel.vanitytst.cloudidentity.ibm.com/oauth2",
  "preferred_username": "jhall@mailinator.com",
  "nonce": "dEoLlAScxs",
  "rt_hash": "AdPHnes93_Wudr3lrBVKqQ",
  "acr": "urn:mace:incommon:iap:silver",
  "aud": "d74dcd6c-cfa7-41b5-ad33-837ca6013a9c",
  "s_hash": "R0LjJE0b_IyMAY59UyoNWQ",
  "auth_time": 1670945580,
  "name": "Jessica Hall",
  "exp": 1670952972,
  "iat": 1670945772,
  "email": "jhall@mailinator.com",
  "jti": "760a846d-851b-4479-b24b-307eae777e02"
}
2022-12-13 15:36:12 SUCCESS
ValidateIdToken
ID token iss, aud, exp, iat, auth_time, acr & nbf claims passed validation checks
2022-12-13 15:36:12
ValidateIdTokenStandardClaims
sub is a string with content
2022-12-13 15:36:12
ValidateIdTokenStandardClaims
Skipping unknown claim: rat
2022-12-13 15:36:12
ValidateIdTokenStandardClaims
Skipping unknown claim: realmName
2022-12-13 15:36:12
ValidateIdTokenStandardClaims
preferred_username is a string with content
2022-12-13 15:36:12
ValidateIdTokenStandardClaims
Skipping unknown claim: rt_hash
2022-12-13 15:36:12
ValidateIdTokenStandardClaims
name is a string with content
2022-12-13 15:36:12
ValidateIdTokenStandardClaims
email is a string with content
2022-12-13 15:36:12 SUCCESS
ValidateIdTokenStandardClaims
id_token claims are valid
2022-12-13 15:36:12 SUCCESS
ValidateIdTokenNonce
Nonce values match
nonce
dEoLlAScxs
2022-12-13 15:36:12 SUCCESS
ValidateIdTokenACRClaimAgainstRequest
acr value in id_token is (one of) the requested values
actual
urn:mace:incommon:iap:silver
requested
[
  "urn:mace:incommon:iap:silver"
]
2022-12-13 15:36:12 SUCCESS
ValidateIdTokenSignature
id_token signature validated
id_token
eyJhbGciOiJQUzI1NiIsImtpZCI6InNlcnZlciJ9.eyJhY3IiOiJ1cm46bWFjZTppbmNvbW1vbjppYXA6c2lsdmVyIiwiYW1yIjpbInBhc3N3b3JkIl0sImF0X2hhc2giOiJobk1nNnhYSE0taHhLLWJFNFY4c0ZRIiwiYXVkIjpbImQ3NGRjZDZjLWNmYTctNDFiNS1hZDMzLTgzN2NhNjAxM2E5YyJdLCJhdXRoX3RpbWUiOjE2NzA5NDU1ODAsImVtYWlsIjoiamhhbGxAbWFpbGluYXRvci5jb20iLCJleHAiOjE2NzA5NTI5NzIsImlhdCI6MTY3MDk0NTc3MiwiaXNzIjoiaHR0cHM6Ly9mYXBpcG9jLnJlbC52YW5pdHl0c3QuY2xvdWRpZGVudGl0eS5pYm0uY29tL29hdXRoMiIsImp0aSI6Ijc2MGE4NDZkLTg1MWItNDQ3OS1iMjRiLTMwN2VhZTc3N2UwMiIsIm5hbWUiOiJKZXNzaWNhIEhhbGwiLCJub25jZSI6ImRFb0xsQVNjeHMiLCJwcmVmZXJyZWRfdXNlcm5hbWUiOiJqaGFsbEBtYWlsaW5hdG9yLmNvbSIsInJhdCI6MTY3MDk0NTc2OCwicmVhbG1OYW1lIjoiY2xvdWRJZGVudGl0eVJlYWxtIiwicnRfaGFzaCI6IkFkUEhuZXM5M19XdWRyM2xyQlZLcVEiLCJzX2hhc2giOiJSMExqSkUwYl9JeU1BWTU5VXlvTldRIiwic3ViIjoiNjE4MDAxOEVCVCJ9.eOwKoA0KcdSE2D1cjoLqJJAgkYK6q-pw0EIVnLa97btxebV2RZ_p0UYhUri-3KScPupnSxdk_XIujnprNKMCaJ6fNK4J6LEBgOBBXQm9QMjbaJt2RWQPgny8ZtjzWwdllMycpciNLUBhSbpGMoeqyd6Gliau2iHQavut-SaATjAZDmZ113LJFJJImQ9_PrNsLnRo8qog0pg78C9I67-RkQyzUobOU4lNYlgOe24VvEW_9q_ZwYB7iOMxd44VtwJp5I82oN_kibyFNkAmcMjabyihAxt_Se5wVts81brDNv21qrddxKrC_iCf0fKK9bih70lilsCn6R1kKpZiDhrKpQ
2022-12-13 15:36:12 SUCCESS
ValidateIdTokenSignatureUsingKid
id_token signature validated
id_token
eyJhbGciOiJQUzI1NiIsImtpZCI6InNlcnZlciJ9.eyJhY3IiOiJ1cm46bWFjZTppbmNvbW1vbjppYXA6c2lsdmVyIiwiYW1yIjpbInBhc3N3b3JkIl0sImF0X2hhc2giOiJobk1nNnhYSE0taHhLLWJFNFY4c0ZRIiwiYXVkIjpbImQ3NGRjZDZjLWNmYTctNDFiNS1hZDMzLTgzN2NhNjAxM2E5YyJdLCJhdXRoX3RpbWUiOjE2NzA5NDU1ODAsImVtYWlsIjoiamhhbGxAbWFpbGluYXRvci5jb20iLCJleHAiOjE2NzA5NTI5NzIsImlhdCI6MTY3MDk0NTc3MiwiaXNzIjoiaHR0cHM6Ly9mYXBpcG9jLnJlbC52YW5pdHl0c3QuY2xvdWRpZGVudGl0eS5pYm0uY29tL29hdXRoMiIsImp0aSI6Ijc2MGE4NDZkLTg1MWItNDQ3OS1iMjRiLTMwN2VhZTc3N2UwMiIsIm5hbWUiOiJKZXNzaWNhIEhhbGwiLCJub25jZSI6ImRFb0xsQVNjeHMiLCJwcmVmZXJyZWRfdXNlcm5hbWUiOiJqaGFsbEBtYWlsaW5hdG9yLmNvbSIsInJhdCI6MTY3MDk0NTc2OCwicmVhbG1OYW1lIjoiY2xvdWRJZGVudGl0eVJlYWxtIiwicnRfaGFzaCI6IkFkUEhuZXM5M19XdWRyM2xyQlZLcVEiLCJzX2hhc2giOiJSMExqSkUwYl9JeU1BWTU5VXlvTldRIiwic3ViIjoiNjE4MDAxOEVCVCJ9.eOwKoA0KcdSE2D1cjoLqJJAgkYK6q-pw0EIVnLa97btxebV2RZ_p0UYhUri-3KScPupnSxdk_XIujnprNKMCaJ6fNK4J6LEBgOBBXQm9QMjbaJt2RWQPgny8ZtjzWwdllMycpciNLUBhSbpGMoeqyd6Gliau2iHQavut-SaATjAZDmZ113LJFJJImQ9_PrNsLnRo8qog0pg78C9I67-RkQyzUobOU4lNYlgOe24VvEW_9q_ZwYB7iOMxd44VtwJp5I82oN_kibyFNkAmcMjabyihAxt_Se5wVts81brDNv21qrddxKrC_iCf0fKK9bih70lilsCn6R1kKpZiDhrKpQ
2022-12-13 15:36:12 SUCCESS
CheckForSubjectInIdToken
Found 'sub' in id_token
sub
6180018EBT
2022-12-13 15:36:12
EnsureIdTokenUpdatedAtValid
id_token response does not contain 'updated_at'
2022-12-13 15:36:12 INFO
ValidateEncryptedIdTokenHasKid
Skipped evaluation due to missing required element: id_token jwe_header
path
jwe_header
mapped
object
id_token
2022-12-13 15:36:12 SUCCESS
EnsureIdTokenContainsKid
kid was found in the ID token header
kid
server
2022-12-13 15:36:12 SUCCESS
FAPIValidateIdTokenSigningAlg
id_token was signed with a permitted algorithm
permitted
[
  "ES256",
  "PS256"
]
alg
PS256
2022-12-13 15:36:12 INFO
FAPIValidateIdTokenEncryptionAlg
Skipped evaluation due to missing required element: id_token jwe_header
path
jwe_header
mapped
object
id_token
2022-12-13 15:36:12 INFO
ExtractCHash
Couldn't find c_hash in ID token
2022-12-13 15:36:12 SUCCESS
ExtractSHash
Extracted s_hash from ID Token
s_hash
R0LjJE0b_IyMAY59UyoNWQ
alg
PS256
2022-12-13 15:36:12 SUCCESS
ExtractAtHash
Extracted at_hash from ID Token
at_hash
hnMg6xXHM-hxK-bE4V8sFQ
alg
PS256
2022-12-13 15:36:12 INFO
ValidateCHash
Skipped evaluation due to missing required object: c_hash
expected
c_hash
mapped
2022-12-13 15:36:12 SUCCESS
ValidateSHash
s_hash validated successfully
expected_hash
R0LjJE0b_IyMAY59UyoNWQ
unhashed_value
vE9Ok3LBgx
id_token_hash
R0LjJE0b_IyMAY59UyoNWQ
2022-12-13 15:36:12 SUCCESS
ValidateAtHash
at_hash validated successfully
expected_hash
hnMg6xXHM-hxK-bE4V8sFQ
unhashed_value
r0SaqC-AizQNZ6RDvCXlOA4tm8Jrqv7MZoUu_lGq_pU.b-b3LdYSPM33doi0zvhN5m37s_2h4iL5fgo3EL87O9McsAx_CfrBHEGt2266Nn2NMfW1fT-EAIuXvueP5qBGZQ.M18xNjcwOTQ1NzcyXzE4
id_token_hash
hnMg6xXHM-hxK-bE4V8sFQ
Resource server endpoint tests
2022-12-13 15:36:12
CreateEmptyResourceEndpointRequestHeaders
Created empty headers
resource_endpoint_request_headers
{}
2022-12-13 15:36:12 SUCCESS
AddFAPIAuthDateToResourceEndpointRequest
Added x-fapi-auth-date to resource endpoint request headers
resource_endpoint_request_headers
{
  "x-fapi-auth-date": "Tue, 13 Dec 2022 15:36:12 GMT"
}
2022-12-13 15:36:12
AddIpV4FapiCustomerIpAddressToResourceEndpointRequest
Added x-fapi-customer-ip-address containing IPv4 address to resource endpoint request headers
resource_endpoint_request_headers
{
  "x-fapi-auth-date": "Tue, 13 Dec 2022 15:36:12 GMT",
  "x-fapi-customer-ip-address": "198.51.100.119"
}
2022-12-13 15:36:12
CreateRandomFAPIInteractionId
Created interaction ID
fapi_interaction_id
2782afe4-9c39-4876-8cc5-117d338268d6
2022-12-13 15:36:12 SUCCESS
AddFAPIInteractionIdToResourceEndpointRequest
Added x-fapi-interaction-id to resource endpoint request headers
resource_endpoint_request_headers
{
  "x-fapi-auth-date": "Tue, 13 Dec 2022 15:36:12 GMT",
  "x-fapi-customer-ip-address": "198.51.100.119",
  "x-fapi-interaction-id": "2782afe4-9c39-4876-8cc5-117d338268d6"
}
2022-12-13 15:36:12
CallProtectedResource
HTTP request
request_uri
https://fapipoc.rel.vanitytst.cloudidentity.ibm.com/oauth2/open-banking/v3.1/aisp/accounts
request_method
GET
request_headers
{
  "accept": "application/json",
  "authorization": "bearer r0SaqC-AizQNZ6RDvCXlOA4tm8Jrqv7MZoUu_lGq_pU.b-b3LdYSPM33doi0zvhN5m37s_2h4iL5fgo3EL87O9McsAx_CfrBHEGt2266Nn2NMfW1fT-EAIuXvueP5qBGZQ.M18xNjcwOTQ1NzcyXzE4",
  "x-fapi-auth-date": "Tue, 13 Dec 2022 15:36:12 GMT",
  "x-fapi-customer-ip-address": "198.51.100.119",
  "x-fapi-interaction-id": "2782afe4-9c39-4876-8cc5-117d338268d6",
  "content-length": "0"
}
request_body

                                
request_mutual_tls
{
  "cert": "MIID2TCCA36gAwIBAgIULVRuRCMrxxQ2YhrJ+h9vwtSuO/QwCgYIKoZIzj0EAwIwgYExCzAJBgNVBAYTAlVTMREwDwYDVQQIDAhOZXcgWW9yazE0MDIGA1UECgwrSW50ZXJuYXRpb25hbCBCdXNpbmVzcyBNYWNoaW5lcyBDb3Jwb3JhdGlvbjEpMCcGA1UEAwwgSUJNIFNlY3VyaXR5IFZlcmlmeSBSZWwtSVRFIENBLTEwHhcNMjIxMjEyMDMxNjAwWhcNMjUxMjExMDMxNjAwWjB0MQswCQYDVQQGEwJTRzETMBEGA1UECBMKa2NhMmNzci1TVDESMBAGA1UEBxMJa2NhMmNzci1MMRIwEAYDVQQKEwlrY2EyY3NyLU8xEzARBgNVBAsTCmtjYTJjc3ItT1UxEzARBgNVBAMTCmtjYTJjc3ItQ04wggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDA8kHL4ANRJU2aW+r4S/5KCmYXgK5OBvvWlgxxwQAVvU/gn/0SoB05rdMRdf/RTQXq3LnvFu/7bA3RkjoKfti6HcD5RxFMm4Lo3jQ4ZtTxrNLIh609ilhkXL3SmkxNuqF0S2WX8FZ62bhxBCS7HAjVbv32ROk92ARPtS5I/mTyo6W2WLmdtpC5J3W6MwMsLpgqPvYB/qo+TEhKiWb2N6XIm+a96CvRuhzH717U97gbR6EhkToNdsh65dZ+0TAIo58Q2ykA8tBhx/T1qk8HKr4jDRbOu/AG6HbsvMuKQrhOdlfc+2AnLnmmxGnLzmmIq9YlCVKO3oJZsiWfiZ+9kflLAgMBAAGjggETMIIBDzAOBgNVHQ8BAf8EBAMCBaAwEwYDVR0lBAwwCgYIKwYBBQUHAwIwDAYDVR0TAQH/BAIwADAdBgNVHQ4EFgQUar6U6YaPLwKeCPOwxzzbNeoTSpUwHwYDVR0jBBgwFoAUy63c0QU2r5F/Z4cdgCgXKPJk+KMwgZkGA1UdEQSBkTCBjoIPd3d3LmV4YW1wbGUuY29tghB0ZXN0LmV4YW1wbGUuY29tghBtYWlsLmV4YW1wbGUuY29tgg93d3cuZXhhbXBsZS5uZXSBE3NoYW5rYXJ2QHNnLmlibS5jb22HBMAAAgGHBMYzZP6HECABDbgAAAAAAAAAAAAAAAGGE2h0dHBzOi8vamtlLmNvbS9mb28wCgYIKoZIzj0EAwIDSQAwRgIhAKD9ml0OBpiloVebUI66xdTxEFwNMgC3BlF3RkTlDG9tAiEAgJVOZFa6grAMPA+yskk267DSu3cx0LBNrGlBncdDoZk\u003d",
  "key": "MIIEogIBAAKCAQEAwPJBy+ADUSVNmlvq+Ev+SgpmF4CuTgb71pYMccEAFb1P4J/9EqAdOa3TEXX/0U0F6ty57xbv+2wN0ZI6Cn7Yuh3A+UcRTJuC6N40OGbU8azSyIetPYpYZFy90ppMTbqhdEtll/BWetm4cQQkuxwI1W799kTpPdgET7UuSP5k8qOltli5nbaQuSd1ujMDLC6YKj72Af6qPkxISolm9jelyJvmvegr0bocx+9e1Pe4G0ehIZE6DXbIeuXWftEwCKOfENspAPLQYcf09apPByq+Iw0WzrvwBuh27LzLikK4TnZX3PtgJy55psRpy85piKvWJQlSjt6CWbIln4mfvZH5SwIDAQABAoIBAGfIJtH1nXMhQHudo2aI4a+LplxP7/GyWfWTYgAx0szetj9ZbvN8whuLPvOuZ7p51ov8y9opmU3AUjJ+l8+baRG6/VhX/JsbLq/5DVelIDcaQYpxSCLI7kCVjdjg+9f3Ye6+u1edg7aysz2+/87RBoNfHyU+7cJBFhiVmN7UTxIfONaVt+gTlW3IPb9xBCLwahIa12w+kSFk9RQZgzi/kUaH20BFZDSzmJsxZSTIG0IL3KwJFM0JFBAHzc14RvAbwGozfoT494qQBVdohaTiid+x7iUrDXgvU95chciL9b7262F3a6wlWO3/a6AVVckzqdgQ27YnIiEcy0s2sukTBTECgYEA/WJiKxvyGXYPsMu/eC5sLM5MGwDMcheru3OV1inB8yIofzviud3n6UXA5sS7qeDEy/sPB9yu8sWDC9+73UXwKYq3+SuEx291koFE0J3PO4sM7UdNRq5N1p3nKzklICbgtumZhtX9aG5wjXu6yXhFIezvnNeHJjcjipsf6iGN0fMCgYEAwvAnkq8lOUxcoCpLKwsWv37M9RyW2zPDixTv9Ddj1wTDnBXYlxzJ5BkL65UAGxTgoESN2mO/ZTk0AnOGJVyYvrDnvY88sRld2jDYK8ALilzUYSoAqAA5dR8y5qS/wAC9yyB1ze7j65lrtIT/I7d442HCM63WDeXATEBVXByWOUkCgYAzVx7q+zOXwxs0yGPYVxemEHrNMeE68N7kEWx3w2g/+ljYRusOnA7kbjTCzXP03M0jQ5BtGGL+X9TIsCGhmQ0rbacPPqkdu9DHyZeG6aLWvrr0zPC0dJbi+IWhdWe3VwlLJpPsBSneYho+IKbdMZhYYmi+j9EbhiqWaA4UY44XzwKBgFFoi441eJ0iJ7h3kSarnddg8+UVCGcIigwGNWNO0nIUOkBv2yDYU/PfBdxfQEkPAfPMTVU7vM1gAzlW11m4/sz8Aftm2xi2mDwrk8tJi0hAFi1xpg6C8XvZCJ/Lg4yCgsBWkPvsXOCiFJmxxP88es6yn7CHU1JAdXsijsNF6PKJAoGAZn9jiGdKVkgtnzHpArY+xxgDvV4p3PRqz5GOopcLLbvS5z1CfHRc/2Hb0ivNf5GlTFuHttZGIadyEqm0FVCoXlfPRq8k5SLYe120+866zZ7eQ7rb4SLm2603F3+Wv1gT5WD2B/9PSD/0ORo5rL4cb4qu4MBm/n0n1PHteZZaGHk\u003d"
}
2022-12-13 15:36:13 RESPONSE
CallProtectedResource
HTTP response
response_status_code
200 OK
response_status_text
OK
response_headers
{
  "x-backside-transport": "OK OK",
  "content-type": "application/json;charset\u003dUTF-8",
  "p3p": "CP\u003d\"NON CUR OTPi OUR NOR UNI\"",
  "x-frame-options": "SAMEORIGIN",
  "x-content-type-options": "nosniff",
  "cache-control": "no-cache, no-store, max-age\u003d0, must-revalidate",
  "expires": "0",
  "x-xss-protection": "1; mode\u003dblock",
  "x-correlation-id": "CORR_ID-AK7266b1dc-755e-4305-b366-644990c2e64c",
  "x-fapi-interaction-id": "2782afe4-9c39-4876-8cc5-117d338268d6",
  "content-security-policy": "frame-ancestors \u0027self\u0027",
  "x-ua-compatible": "IE\u003dedge",
  "x-global-transaction-id": "efc5c28163989bec0c5f8e03",
  "content-length": "39",
  "date": "Tue, 13 Dec 2022 15:36:13 GMT",
  "connection": "close",
  "set-cookie": [
    "CIPD-S-SESSION-ID\u003d0:1:rediscol:Zy3SehaZ7glIGa+z5yBnz5hCsihPRDTLZIOgmgwNY48\u003d; Path\u003d/; SameSite\u003dNone; Secure; HttpOnly",
    "CISESSIONIDREL02A\u003dPBC5YS:61017047; Path\u003d/; Domain\u003drel.vanitytst.cloudidentity.ibm.com; Secure; HttpOnly",
    "_abck\u003dED26E2696E1E45E185C9FB15FE787B40~-1~YAAQBpMauG0V+4uEAQAAkxYhDAlZaw0Wxt+oomKf5lXrvtIGNYWPCrGTrQXj3fLlHR48Rx3pv1zkbIaqoZJNX/ftyVG06nJxDe0euLgtypF/b+W6GtCmt8c3LJxQldJnhme5I7GOxBXmgjDkLdv2CbuTycoktMJaGQYD2cPoWlgmA6SpOYAJV71930T5xdbHBYPhM4JutUlAZviJRSh0EPlDVbfLRC1KIC3nhfNgwlmgKi049p7PTgbheKNhhxxsV7+h9Jcc960+0/SPllVnf6EUNOqfA9BCT+LX0PshhBbEKnOVBlvC88V9SorkWszVHvLMD6i/PlVJiZWVIsLNbNhpY3yviEStODtqxEUNWDB3iVKxLEcitQ\u003d\u003d~-1~-1~-1; Domain\u003d.ibm.com; Path\u003d/; Expires\u003dWed, 13 Dec 2023 15:36:13 GMT; Max-Age\u003d31536000; Secure",
    "bm_sz\u003d4147EFDF0D5424DA72FD68BB97EC7A0E~YAAQBpMauG4V+4uEAQAAkxYhDBKRV1H6sPO4liiiF+kFe8BHCUiLAoJ2ykP8Th8zptgOwy9tkw3qahv+LpfGQ8PcSWFDJpHJV3WsmjbKlVZiyVQx3RZEe0dHvfCAuHJscwJmZ/v/ZnjAXvqxNqvFn6kPzb/Q9C1N0Ou978UyF+gFCEmn94mwUGHNZeFRor6DdgnfRiutfdK2a9u3dahG3QGzBEhSsFABd8oaurZUMXCjK3PwlgVJ2JMl+sov6LsC7RITkf5i3dSRYNKvuaqf0NupAgOs2M9zn4CprWjNnD4\u003d~3552322~3163448; Domain\u003d.ibm.com; Path\u003d/; Expires\u003dTue, 13 Dec 2022 19:36:12 GMT; Max-Age\u003d14399; Secure"
  ],
  "server-timing": [
    "cdn-cache; desc\u003dMISS",
    "edge; dur\u003d90",
    "origin; dur\u003d853"
  ],
  "strict-transport-security": "max-age\u003d31536000 ; includeSubDomains"
}
response_body
{"content":"This is a sample resource"}
2022-12-13 15:36:13 SUCCESS
CallProtectedResource
Got a response from the resource endpoint
status
200
endpoint_name
resource
headers
{
  "x-backside-transport": "OK OK",
  "content-type": "application/json;charset\u003dUTF-8",
  "p3p": "CP\u003d\"NON CUR OTPi OUR NOR UNI\"",
  "x-frame-options": "SAMEORIGIN",
  "x-content-type-options": "nosniff",
  "cache-control": "no-cache, no-store, max-age\u003d0, must-revalidate",
  "expires": "0",
  "x-xss-protection": "1; mode\u003dblock",
  "x-correlation-id": "CORR_ID-AK7266b1dc-755e-4305-b366-644990c2e64c",
  "x-fapi-interaction-id": "2782afe4-9c39-4876-8cc5-117d338268d6",
  "content-security-policy": "frame-ancestors \u0027self\u0027",
  "x-ua-compatible": "IE\u003dedge",
  "x-global-transaction-id": "efc5c28163989bec0c5f8e03",
  "content-length": "39",
  "date": "Tue, 13 Dec 2022 15:36:13 GMT",
  "connection": "close",
  "set-cookie": [
    "CIPD-S-SESSION-ID\u003d0:1:rediscol:Zy3SehaZ7glIGa+z5yBnz5hCsihPRDTLZIOgmgwNY48\u003d; Path\u003d/; SameSite\u003dNone; Secure; HttpOnly",
    "CISESSIONIDREL02A\u003dPBC5YS:61017047; Path\u003d/; Domain\u003drel.vanitytst.cloudidentity.ibm.com; Secure; HttpOnly",
    "_abck\u003dED26E2696E1E45E185C9FB15FE787B40~-1~YAAQBpMauG0V+4uEAQAAkxYhDAlZaw0Wxt+oomKf5lXrvtIGNYWPCrGTrQXj3fLlHR48Rx3pv1zkbIaqoZJNX/ftyVG06nJxDe0euLgtypF/b+W6GtCmt8c3LJxQldJnhme5I7GOxBXmgjDkLdv2CbuTycoktMJaGQYD2cPoWlgmA6SpOYAJV71930T5xdbHBYPhM4JutUlAZviJRSh0EPlDVbfLRC1KIC3nhfNgwlmgKi049p7PTgbheKNhhxxsV7+h9Jcc960+0/SPllVnf6EUNOqfA9BCT+LX0PshhBbEKnOVBlvC88V9SorkWszVHvLMD6i/PlVJiZWVIsLNbNhpY3yviEStODtqxEUNWDB3iVKxLEcitQ\u003d\u003d~-1~-1~-1; Domain\u003d.ibm.com; Path\u003d/; Expires\u003dWed, 13 Dec 2023 15:36:13 GMT; Max-Age\u003d31536000; Secure",
    "bm_sz\u003d4147EFDF0D5424DA72FD68BB97EC7A0E~YAAQBpMauG4V+4uEAQAAkxYhDBKRV1H6sPO4liiiF+kFe8BHCUiLAoJ2ykP8Th8zptgOwy9tkw3qahv+LpfGQ8PcSWFDJpHJV3WsmjbKlVZiyVQx3RZEe0dHvfCAuHJscwJmZ/v/ZnjAXvqxNqvFn6kPzb/Q9C1N0Ou978UyF+gFCEmn94mwUGHNZeFRor6DdgnfRiutfdK2a9u3dahG3QGzBEhSsFABd8oaurZUMXCjK3PwlgVJ2JMl+sov6LsC7RITkf5i3dSRYNKvuaqf0NupAgOs2M9zn4CprWjNnD4\u003d~3552322~3163448; Domain\u003d.ibm.com; Path\u003d/; Expires\u003dTue, 13 Dec 2022 19:36:12 GMT; Max-Age\u003d14399; Secure"
  ],
  "server-timing": [
    "cdn-cache; desc\u003dMISS",
    "edge; dur\u003d90",
    "origin; dur\u003d853"
  ],
  "strict-transport-security": "max-age\u003d31536000 ; includeSubDomains"
}
body
{"content":"This is a sample resource"}
2022-12-13 15:36:13 SUCCESS
EnsureHttpStatusCodeIs200or201
resource endpoint http status code was 200
2022-12-13 15:36:13 SUCCESS
CheckForDateHeaderInResourceResponse
Date header present and validated
date
Tue, 13 Dec 2022 15:36:13 GMT
skew
209
2022-12-13 15:36:13 SUCCESS
CheckForFAPIInteractionIdInResourceResponse
Found x-fapi-interaction-id
interaction_id
2782afe4-9c39-4876-8cc5-117d338268d6
2022-12-13 15:36:13 SUCCESS
EnsureMatchingFAPIInteractionId
Interaction ID matched
fapi_interaction_id
2782afe4-9c39-4876-8cc5-117d338268d6
2022-12-13 15:36:13 SUCCESS
EnsureResourceResponseReturnedJsonContentType
Response content type is json
content_type
application/json;charset=UTF-8
Attempting reuse of authorization code
2022-12-13 15:36:13 SUCCESS
WaitForOneSecond
Pausing for 1 seconds
2022-12-13 15:36:14 SUCCESS
WaitForOneSecond
Woke up after 1 seconds sleep
2022-12-13 15:36:14
CallTokenEndpointAndReturnFullResponse
HTTP request
request_uri
https://fapipoc.rel.vanitytst.cloudidentity.ibm.com/oauth2/token
request_method
POST
request_headers
{
  "accept": "application/json",
  "content-type": "application/x-www-form-urlencoded;charset\u003dUTF-8",
  "content-length": "310"
}
request_body
grant_type=authorization_code&code=aKKWV8zV1ujPNfAszmWb2sTlqHCDKYHpPZMQOzH8TzQ.BxdyE1XZJ6FSUWT166Y4O16bQnWSRpdaMs55FI_McUlvwZvWgI55s6u2tmlQ3RaRuK5fE49k0-ZXRP2R4ErcqQ&redirect_uri=https%3A%2F%2Fwww.certification.openid.net%2Ftest%2Fa%2Ffapipoc_fapi_jarm%2Fcallback&client_id=d74dcd6c-cfa7-41b5-ad33-837ca6013a9c
request_mutual_tls
{
  "cert": "MIID2TCCA36gAwIBAgIULVRuRCMrxxQ2YhrJ+h9vwtSuO/QwCgYIKoZIzj0EAwIwgYExCzAJBgNVBAYTAlVTMREwDwYDVQQIDAhOZXcgWW9yazE0MDIGA1UECgwrSW50ZXJuYXRpb25hbCBCdXNpbmVzcyBNYWNoaW5lcyBDb3Jwb3JhdGlvbjEpMCcGA1UEAwwgSUJNIFNlY3VyaXR5IFZlcmlmeSBSZWwtSVRFIENBLTEwHhcNMjIxMjEyMDMxNjAwWhcNMjUxMjExMDMxNjAwWjB0MQswCQYDVQQGEwJTRzETMBEGA1UECBMKa2NhMmNzci1TVDESMBAGA1UEBxMJa2NhMmNzci1MMRIwEAYDVQQKEwlrY2EyY3NyLU8xEzARBgNVBAsTCmtjYTJjc3ItT1UxEzARBgNVBAMTCmtjYTJjc3ItQ04wggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDA8kHL4ANRJU2aW+r4S/5KCmYXgK5OBvvWlgxxwQAVvU/gn/0SoB05rdMRdf/RTQXq3LnvFu/7bA3RkjoKfti6HcD5RxFMm4Lo3jQ4ZtTxrNLIh609ilhkXL3SmkxNuqF0S2WX8FZ62bhxBCS7HAjVbv32ROk92ARPtS5I/mTyo6W2WLmdtpC5J3W6MwMsLpgqPvYB/qo+TEhKiWb2N6XIm+a96CvRuhzH717U97gbR6EhkToNdsh65dZ+0TAIo58Q2ykA8tBhx/T1qk8HKr4jDRbOu/AG6HbsvMuKQrhOdlfc+2AnLnmmxGnLzmmIq9YlCVKO3oJZsiWfiZ+9kflLAgMBAAGjggETMIIBDzAOBgNVHQ8BAf8EBAMCBaAwEwYDVR0lBAwwCgYIKwYBBQUHAwIwDAYDVR0TAQH/BAIwADAdBgNVHQ4EFgQUar6U6YaPLwKeCPOwxzzbNeoTSpUwHwYDVR0jBBgwFoAUy63c0QU2r5F/Z4cdgCgXKPJk+KMwgZkGA1UdEQSBkTCBjoIPd3d3LmV4YW1wbGUuY29tghB0ZXN0LmV4YW1wbGUuY29tghBtYWlsLmV4YW1wbGUuY29tgg93d3cuZXhhbXBsZS5uZXSBE3NoYW5rYXJ2QHNnLmlibS5jb22HBMAAAgGHBMYzZP6HECABDbgAAAAAAAAAAAAAAAGGE2h0dHBzOi8vamtlLmNvbS9mb28wCgYIKoZIzj0EAwIDSQAwRgIhAKD9ml0OBpiloVebUI66xdTxEFwNMgC3BlF3RkTlDG9tAiEAgJVOZFa6grAMPA+yskk267DSu3cx0LBNrGlBncdDoZk\u003d",
  "key": "MIIEogIBAAKCAQEAwPJBy+ADUSVNmlvq+Ev+SgpmF4CuTgb71pYMccEAFb1P4J/9EqAdOa3TEXX/0U0F6ty57xbv+2wN0ZI6Cn7Yuh3A+UcRTJuC6N40OGbU8azSyIetPYpYZFy90ppMTbqhdEtll/BWetm4cQQkuxwI1W799kTpPdgET7UuSP5k8qOltli5nbaQuSd1ujMDLC6YKj72Af6qPkxISolm9jelyJvmvegr0bocx+9e1Pe4G0ehIZE6DXbIeuXWftEwCKOfENspAPLQYcf09apPByq+Iw0WzrvwBuh27LzLikK4TnZX3PtgJy55psRpy85piKvWJQlSjt6CWbIln4mfvZH5SwIDAQABAoIBAGfIJtH1nXMhQHudo2aI4a+LplxP7/GyWfWTYgAx0szetj9ZbvN8whuLPvOuZ7p51ov8y9opmU3AUjJ+l8+baRG6/VhX/JsbLq/5DVelIDcaQYpxSCLI7kCVjdjg+9f3Ye6+u1edg7aysz2+/87RBoNfHyU+7cJBFhiVmN7UTxIfONaVt+gTlW3IPb9xBCLwahIa12w+kSFk9RQZgzi/kUaH20BFZDSzmJsxZSTIG0IL3KwJFM0JFBAHzc14RvAbwGozfoT494qQBVdohaTiid+x7iUrDXgvU95chciL9b7262F3a6wlWO3/a6AVVckzqdgQ27YnIiEcy0s2sukTBTECgYEA/WJiKxvyGXYPsMu/eC5sLM5MGwDMcheru3OV1inB8yIofzviud3n6UXA5sS7qeDEy/sPB9yu8sWDC9+73UXwKYq3+SuEx291koFE0J3PO4sM7UdNRq5N1p3nKzklICbgtumZhtX9aG5wjXu6yXhFIezvnNeHJjcjipsf6iGN0fMCgYEAwvAnkq8lOUxcoCpLKwsWv37M9RyW2zPDixTv9Ddj1wTDnBXYlxzJ5BkL65UAGxTgoESN2mO/ZTk0AnOGJVyYvrDnvY88sRld2jDYK8ALilzUYSoAqAA5dR8y5qS/wAC9yyB1ze7j65lrtIT/I7d442HCM63WDeXATEBVXByWOUkCgYAzVx7q+zOXwxs0yGPYVxemEHrNMeE68N7kEWx3w2g/+ljYRusOnA7kbjTCzXP03M0jQ5BtGGL+X9TIsCGhmQ0rbacPPqkdu9DHyZeG6aLWvrr0zPC0dJbi+IWhdWe3VwlLJpPsBSneYho+IKbdMZhYYmi+j9EbhiqWaA4UY44XzwKBgFFoi441eJ0iJ7h3kSarnddg8+UVCGcIigwGNWNO0nIUOkBv2yDYU/PfBdxfQEkPAfPMTVU7vM1gAzlW11m4/sz8Aftm2xi2mDwrk8tJi0hAFi1xpg6C8XvZCJ/Lg4yCgsBWkPvsXOCiFJmxxP88es6yn7CHU1JAdXsijsNF6PKJAoGAZn9jiGdKVkgtnzHpArY+xxgDvV4p3PRqz5GOopcLLbvS5z1CfHRc/2Hb0ivNf5GlTFuHttZGIadyEqm0FVCoXlfPRq8k5SLYe120+866zZ7eQ7rb4SLm2603F3+Wv1gT5WD2B/9PSD/0ORo5rL4cb4qu4MBm/n0n1PHteZZaGHk\u003d"
}
2022-12-13 15:36:14 RESPONSE
CallTokenEndpointAndReturnFullResponse
HTTP response
response_status_code
400 BAD_REQUEST
response_status_text
Bad Request
response_headers
{
  "x-backside-transport": "FAIL FAIL",
  "content-type": "application/json;charset\u003dUTF-8",
  "p3p": "CP\u003d\"NON CUR OTPi OUR NOR UNI\"",
  "x-content-type-options": "nosniff",
  "cache-control": "no-store",
  "x-xss-protection": "1; mode\u003dblock",
  "x-correlation-id": "CORR_ID-AK2c2f0e8f-94fa-41b5-99b6-4d146960efd5",
  "pragma": "no-cache",
  "x-global-transaction-id": "efc5c28163989bee53f82001",
  "content-length": "104",
  "date": "Tue, 13 Dec 2022 15:36:14 GMT",
  "connection": "close",
  "set-cookie": [
    "CIPD-S-SESSION-ID\u003d0:1:rediscol:aydoxREgF1NkT8lELNxSGU7S7dC4os+XLMAP4X6CCyI\u003d; Path\u003d/; SameSite\u003dNone; Secure; HttpOnly",
    "CISESSIONIDREL02A\u003dPBC5YS:57871319; Path\u003d/; Domain\u003drel.vanitytst.cloudidentity.ibm.com; Secure; HttpOnly",
    "_abck\u003dBABEE93A36CB1982EC8344256916B41A~-1~YAAQBpMauJ4V+4uEAQAAnRshDAn3A5hh0VO6Nblm1uKEvWoeoZuOYOX94krmeExUZIK5N9xBXaRGnb45QwsBaft4JaXCattcYJZnz4fM9oNS2HHfppDU2I7LmNevAxA3yHyj53PQZktFTNmWhbywr0OTPZ1JZkNspDrF5WWI4m9dpmV4LXMLYcoJ0Lma0hkK08PAotzg1E0hwf3LPwdKWT8vBdF0w6RsKdVIqyybDpR7SknIZ7A/0+PZ13IsskI7aAOfly+xanZfYcMl7hTCZ+mQ2ngkR3ZW0mulUlwJ1qenflTC6EwWmTzVRRdLdTzcTQ7NXeLBhHGr1e3Hr2dUcqEb+eIUivwT+n4rZeQyRd1hOpso6zCy2A\u003d\u003d~-1~-1~-1; Domain\u003d.ibm.com; Path\u003d/; Expires\u003dWed, 13 Dec 2023 15:36:14 GMT; Max-Age\u003d31536000; Secure",
    "bm_sz\u003d8DDE76843109AA3B186D2CFD8B97A53E~YAAQBpMauJ8V+4uEAQAAnRshDBJfOoHrYmRD1xV75oJzpB2jARfEhYoT971XbeiLYQZpI9fjxGUvCg8ilhakcs4b//fxfbCRkA01PJh7nQQBz/2sDRVZcVIoLWmOQ3cU49Tc+2SjA8ghrTTbdwojmEvnVCVbf/mjsJ/83KLuEAbTSNoSPD80c3mUb8HuX2KdeRNpqkEhS/cPrh/T77CXoWUR5rYm+Y4cF9cbq2W4lMq2W8WvfXhHLEBXsg8/Yxp/uWbt2hMMK3jXRF7FMCI2Nqr7JBSz5nufWeOMZvbqDb0\u003d~3618629~4470577; Domain\u003d.ibm.com; Path\u003d/; Expires\u003dTue, 13 Dec 2022 19:36:14 GMT; Max-Age\u003d14400; Secure"
  ],
  "server-timing": [
    "cdn-cache; desc\u003dMISS",
    "edge; dur\u003d93",
    "origin; dur\u003d125"
  ],
  "strict-transport-security": "max-age\u003d31536000 ; includeSubDomains"
}
response_body
{"error":"invalid_grant","error_description":"CSIAQ5119E The authorization code has already been used."}
2022-12-13 15:36:14 SUCCESS
CallTokenEndpointAndReturnFullResponse
Parsed token endpoint response
error
invalid_grant
error_description
CSIAQ5119E The authorization code has already been used.
2022-12-13 15:36:14 SUCCESS
CheckTokenEndpointHttpStatus400
Token endpoint http status code was 400
2022-12-13 15:36:14 SUCCESS
CheckTokenEndpointReturnedJsonContentType
token_endpoint_response_headers Content-Type: header is application/json
2022-12-13 15:36:14 SUCCESS
CheckErrorFromTokenEndpointResponseErrorInvalidGrant
Token Endpoint response error returned expected 'error' of 'invalid_grant'
expected
[
  "invalid_grant"
]
2022-12-13 15:36:14 SUCCESS
ValidateErrorFromTokenEndpointResponseError
Token endpoint response error returned valid 'error' field
error
invalid_grant
2022-12-13 15:36:14 SUCCESS
CheckErrorDescriptionFromTokenEndpointResponseErrorContainsCRLFTAB
token_endpoint_response 'error_description' field does not include CR/LF/TAB
error_description
CSIAQ5119E The authorization code has already been used.
2022-12-13 15:36:14 SUCCESS
ValidateErrorDescriptionFromTokenEndpointResponseError
token_endpoint_response error returned valid 'error_description' field
error_description
CSIAQ5119E The authorization code has already been used.
2022-12-13 15:36:14 SUCCESS
ValidateErrorUriFromTokenEndpointResponseError
token_endpoint_response did not include optional 'error_uri' field
Testing if access token was revoked after authorization code reuse (the AS 'should' have revoked the access token)
2022-12-13 15:36:14
CallProtectedResource
HTTP request
request_uri
https://fapipoc.rel.vanitytst.cloudidentity.ibm.com/oauth2/open-banking/v3.1/aisp/accounts
request_method
GET
request_headers
{
  "accept": "application/json",
  "authorization": "bearer r0SaqC-AizQNZ6RDvCXlOA4tm8Jrqv7MZoUu_lGq_pU.b-b3LdYSPM33doi0zvhN5m37s_2h4iL5fgo3EL87O9McsAx_CfrBHEGt2266Nn2NMfW1fT-EAIuXvueP5qBGZQ.M18xNjcwOTQ1NzcyXzE4",
  "x-fapi-auth-date": "Tue, 13 Dec 2022 15:36:12 GMT",
  "x-fapi-customer-ip-address": "198.51.100.119",
  "x-fapi-interaction-id": "2782afe4-9c39-4876-8cc5-117d338268d6",
  "content-length": "0"
}
request_body

                                
request_mutual_tls
{
  "cert": "MIID2TCCA36gAwIBAgIULVRuRCMrxxQ2YhrJ+h9vwtSuO/QwCgYIKoZIzj0EAwIwgYExCzAJBgNVBAYTAlVTMREwDwYDVQQIDAhOZXcgWW9yazE0MDIGA1UECgwrSW50ZXJuYXRpb25hbCBCdXNpbmVzcyBNYWNoaW5lcyBDb3Jwb3JhdGlvbjEpMCcGA1UEAwwgSUJNIFNlY3VyaXR5IFZlcmlmeSBSZWwtSVRFIENBLTEwHhcNMjIxMjEyMDMxNjAwWhcNMjUxMjExMDMxNjAwWjB0MQswCQYDVQQGEwJTRzETMBEGA1UECBMKa2NhMmNzci1TVDESMBAGA1UEBxMJa2NhMmNzci1MMRIwEAYDVQQKEwlrY2EyY3NyLU8xEzARBgNVBAsTCmtjYTJjc3ItT1UxEzARBgNVBAMTCmtjYTJjc3ItQ04wggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDA8kHL4ANRJU2aW+r4S/5KCmYXgK5OBvvWlgxxwQAVvU/gn/0SoB05rdMRdf/RTQXq3LnvFu/7bA3RkjoKfti6HcD5RxFMm4Lo3jQ4ZtTxrNLIh609ilhkXL3SmkxNuqF0S2WX8FZ62bhxBCS7HAjVbv32ROk92ARPtS5I/mTyo6W2WLmdtpC5J3W6MwMsLpgqPvYB/qo+TEhKiWb2N6XIm+a96CvRuhzH717U97gbR6EhkToNdsh65dZ+0TAIo58Q2ykA8tBhx/T1qk8HKr4jDRbOu/AG6HbsvMuKQrhOdlfc+2AnLnmmxGnLzmmIq9YlCVKO3oJZsiWfiZ+9kflLAgMBAAGjggETMIIBDzAOBgNVHQ8BAf8EBAMCBaAwEwYDVR0lBAwwCgYIKwYBBQUHAwIwDAYDVR0TAQH/BAIwADAdBgNVHQ4EFgQUar6U6YaPLwKeCPOwxzzbNeoTSpUwHwYDVR0jBBgwFoAUy63c0QU2r5F/Z4cdgCgXKPJk+KMwgZkGA1UdEQSBkTCBjoIPd3d3LmV4YW1wbGUuY29tghB0ZXN0LmV4YW1wbGUuY29tghBtYWlsLmV4YW1wbGUuY29tgg93d3cuZXhhbXBsZS5uZXSBE3NoYW5rYXJ2QHNnLmlibS5jb22HBMAAAgGHBMYzZP6HECABDbgAAAAAAAAAAAAAAAGGE2h0dHBzOi8vamtlLmNvbS9mb28wCgYIKoZIzj0EAwIDSQAwRgIhAKD9ml0OBpiloVebUI66xdTxEFwNMgC3BlF3RkTlDG9tAiEAgJVOZFa6grAMPA+yskk267DSu3cx0LBNrGlBncdDoZk\u003d",
  "key": "MIIEogIBAAKCAQEAwPJBy+ADUSVNmlvq+Ev+SgpmF4CuTgb71pYMccEAFb1P4J/9EqAdOa3TEXX/0U0F6ty57xbv+2wN0ZI6Cn7Yuh3A+UcRTJuC6N40OGbU8azSyIetPYpYZFy90ppMTbqhdEtll/BWetm4cQQkuxwI1W799kTpPdgET7UuSP5k8qOltli5nbaQuSd1ujMDLC6YKj72Af6qPkxISolm9jelyJvmvegr0bocx+9e1Pe4G0ehIZE6DXbIeuXWftEwCKOfENspAPLQYcf09apPByq+Iw0WzrvwBuh27LzLikK4TnZX3PtgJy55psRpy85piKvWJQlSjt6CWbIln4mfvZH5SwIDAQABAoIBAGfIJtH1nXMhQHudo2aI4a+LplxP7/GyWfWTYgAx0szetj9ZbvN8whuLPvOuZ7p51ov8y9opmU3AUjJ+l8+baRG6/VhX/JsbLq/5DVelIDcaQYpxSCLI7kCVjdjg+9f3Ye6+u1edg7aysz2+/87RBoNfHyU+7cJBFhiVmN7UTxIfONaVt+gTlW3IPb9xBCLwahIa12w+kSFk9RQZgzi/kUaH20BFZDSzmJsxZSTIG0IL3KwJFM0JFBAHzc14RvAbwGozfoT494qQBVdohaTiid+x7iUrDXgvU95chciL9b7262F3a6wlWO3/a6AVVckzqdgQ27YnIiEcy0s2sukTBTECgYEA/WJiKxvyGXYPsMu/eC5sLM5MGwDMcheru3OV1inB8yIofzviud3n6UXA5sS7qeDEy/sPB9yu8sWDC9+73UXwKYq3+SuEx291koFE0J3PO4sM7UdNRq5N1p3nKzklICbgtumZhtX9aG5wjXu6yXhFIezvnNeHJjcjipsf6iGN0fMCgYEAwvAnkq8lOUxcoCpLKwsWv37M9RyW2zPDixTv9Ddj1wTDnBXYlxzJ5BkL65UAGxTgoESN2mO/ZTk0AnOGJVyYvrDnvY88sRld2jDYK8ALilzUYSoAqAA5dR8y5qS/wAC9yyB1ze7j65lrtIT/I7d442HCM63WDeXATEBVXByWOUkCgYAzVx7q+zOXwxs0yGPYVxemEHrNMeE68N7kEWx3w2g/+ljYRusOnA7kbjTCzXP03M0jQ5BtGGL+X9TIsCGhmQ0rbacPPqkdu9DHyZeG6aLWvrr0zPC0dJbi+IWhdWe3VwlLJpPsBSneYho+IKbdMZhYYmi+j9EbhiqWaA4UY44XzwKBgFFoi441eJ0iJ7h3kSarnddg8+UVCGcIigwGNWNO0nIUOkBv2yDYU/PfBdxfQEkPAfPMTVU7vM1gAzlW11m4/sz8Aftm2xi2mDwrk8tJi0hAFi1xpg6C8XvZCJ/Lg4yCgsBWkPvsXOCiFJmxxP88es6yn7CHU1JAdXsijsNF6PKJAoGAZn9jiGdKVkgtnzHpArY+xxgDvV4p3PRqz5GOopcLLbvS5z1CfHRc/2Hb0ivNf5GlTFuHttZGIadyEqm0FVCoXlfPRq8k5SLYe120+866zZ7eQ7rb4SLm2603F3+Wv1gT5WD2B/9PSD/0ORo5rL4cb4qu4MBm/n0n1PHteZZaGHk\u003d"
}
2022-12-13 15:36:15 RESPONSE
CallProtectedResource
HTTP response
response_status_code
400 BAD_REQUEST
response_status_text
Bad Request
response_headers
{
  "x-backside-transport": "FAIL FAIL",
  "p3p": "CP\u003d\"NON CUR OTPi OUR NOR UNI\"",
  "x-frame-options": "SAMEORIGIN",
  "x-content-type-options": "nosniff",
  "cache-control": "no-cache, no-store, max-age\u003d0, must-revalidate",
  "expires": "0",
  "x-xss-protection": "1; mode\u003dblock",
  "x-correlation-id": "CORR_ID-AK6b81c8ae-5c6d-4653-ae59-e34cbdc24344",
  "content-security-policy": "frame-ancestors \u0027self\u0027",
  "x-ua-compatible": "IE\u003dedge",
  "x-global-transaction-id": "efc5c28163989bee33f675a5",
  "content-length": "0",
  "date": "Tue, 13 Dec 2022 15:36:15 GMT",
  "connection": "close",
  "set-cookie": [
    "CIPD-S-SESSION-ID\u003d0:1:rediscol:Bjgua6AqrygGY5US82+CMM4zBAd0l0HOEzgwldBJR6Q\u003d; Path\u003d/; SameSite\u003dNone; Secure; HttpOnly",
    "CISESSIONIDREL02A\u003dPBC5YS:61017047; Path\u003d/; Domain\u003drel.vanitytst.cloudidentity.ibm.com; Secure; HttpOnly",
    "_abck\u003dA26E87B2C600C00BAFB93484D4027DE5~-1~YAAQBpMauN8V+4uEAQAAWSEhDAkJlm9BEiLYCAF8Njho+eKtcGeQhnQ21/+FLZZPQt+DpouvVSasWAAW+Fq+tL4/6ppsKSoEzK39gKDuuOIoB7wMDVcN683VXXTGRhjrjqWBtNecCZbyGH7k6pDH+3tdmbWJMxQQRHBg7OO7UbPUc5u2d1khOt+YuUQNs62b+jjqkrgZBBb3JcFXjTxcvznvdL7xF8Kk2gdfuLam9j7vVtsrGKyHXVVtDG0wIE/N40qzgZHgQv+i4Unx3bAM4YekQ58ztXxJkIy6sp0+BjURvWhB/bBOO2oiGZFuNPf7k5APWV6OBIANXXSTBJcRutE86iEhXSVwljpETPu4iuVneAIUBv737Q\u003d\u003d~-1~-1~-1; Domain\u003d.ibm.com; Path\u003d/; Expires\u003dWed, 13 Dec 2023 15:36:15 GMT; Max-Age\u003d31536000; Secure",
    "bm_sz\u003dD04F4FCDA105514FB062D665312A161B~YAAQBpMauOAV+4uEAQAAWSEhDBJLxOofVi/82fcx+zjPYjgYBEOCKObyBIiTIR2EYHT9wNrXzXbo9LEmwYU18DTIhKsRsSliV6dMRSbUSK9kB9CH1RHz76BJVF/9O8uTnLpTGlsPZjG+aCousw/iOk+cXDq0B2JHPmvoDk3wh2ZLqBQSnpFpm+45jFLsk2FUWIPC3Y1Bc4zzhSS834hJM8PCyLqezomB3I3T6nUzQl6a69Qcir8iOeCQ8BiEiLkdshXbfMxE9hwNvlO6XpPIeDLolCNpLRpBkWJ65cLmOtg\u003d~3618629~4470577; Domain\u003d.ibm.com; Path\u003d/; Expires\u003dTue, 13 Dec 2022 19:36:14 GMT; Max-Age\u003d14399; Secure"
  ],
  "server-timing": [
    "cdn-cache; desc\u003dMISS",
    "edge; dur\u003d408",
    "origin; dur\u003d993"
  ],
  "strict-transport-security": "max-age\u003d31536000 ; includeSubDomains"
}
response_body

                                
2022-12-13 15:36:15 SUCCESS
CallProtectedResource
Got a response from the resource endpoint
status
400
endpoint_name
resource
headers
{
  "x-backside-transport": "FAIL FAIL",
  "p3p": "CP\u003d\"NON CUR OTPi OUR NOR UNI\"",
  "x-frame-options": "SAMEORIGIN",
  "x-content-type-options": "nosniff",
  "cache-control": "no-cache, no-store, max-age\u003d0, must-revalidate",
  "expires": "0",
  "x-xss-protection": "1; mode\u003dblock",
  "x-correlation-id": "CORR_ID-AK6b81c8ae-5c6d-4653-ae59-e34cbdc24344",
  "content-security-policy": "frame-ancestors \u0027self\u0027",
  "x-ua-compatible": "IE\u003dedge",
  "x-global-transaction-id": "efc5c28163989bee33f675a5",
  "content-length": "0",
  "date": "Tue, 13 Dec 2022 15:36:15 GMT",
  "connection": "close",
  "set-cookie": [
    "CIPD-S-SESSION-ID\u003d0:1:rediscol:Bjgua6AqrygGY5US82+CMM4zBAd0l0HOEzgwldBJR6Q\u003d; Path\u003d/; SameSite\u003dNone; Secure; HttpOnly",
    "CISESSIONIDREL02A\u003dPBC5YS:61017047; Path\u003d/; Domain\u003drel.vanitytst.cloudidentity.ibm.com; Secure; HttpOnly",
    "_abck\u003dA26E87B2C600C00BAFB93484D4027DE5~-1~YAAQBpMauN8V+4uEAQAAWSEhDAkJlm9BEiLYCAF8Njho+eKtcGeQhnQ21/+FLZZPQt+DpouvVSasWAAW+Fq+tL4/6ppsKSoEzK39gKDuuOIoB7wMDVcN683VXXTGRhjrjqWBtNecCZbyGH7k6pDH+3tdmbWJMxQQRHBg7OO7UbPUc5u2d1khOt+YuUQNs62b+jjqkrgZBBb3JcFXjTxcvznvdL7xF8Kk2gdfuLam9j7vVtsrGKyHXVVtDG0wIE/N40qzgZHgQv+i4Unx3bAM4YekQ58ztXxJkIy6sp0+BjURvWhB/bBOO2oiGZFuNPf7k5APWV6OBIANXXSTBJcRutE86iEhXSVwljpETPu4iuVneAIUBv737Q\u003d\u003d~-1~-1~-1; Domain\u003d.ibm.com; Path\u003d/; Expires\u003dWed, 13 Dec 2023 15:36:15 GMT; Max-Age\u003d31536000; Secure",
    "bm_sz\u003dD04F4FCDA105514FB062D665312A161B~YAAQBpMauOAV+4uEAQAAWSEhDBJLxOofVi/82fcx+zjPYjgYBEOCKObyBIiTIR2EYHT9wNrXzXbo9LEmwYU18DTIhKsRsSliV6dMRSbUSK9kB9CH1RHz76BJVF/9O8uTnLpTGlsPZjG+aCousw/iOk+cXDq0B2JHPmvoDk3wh2ZLqBQSnpFpm+45jFLsk2FUWIPC3Y1Bc4zzhSS834hJM8PCyLqezomB3I3T6nUzQl6a69Qcir8iOeCQ8BiEiLkdshXbfMxE9hwNvlO6XpPIeDLolCNpLRpBkWJ65cLmOtg\u003d~3618629~4470577; Domain\u003d.ibm.com; Path\u003d/; Expires\u003dTue, 13 Dec 2022 19:36:14 GMT; Max-Age\u003d14399; Secure"
  ],
  "server-timing": [
    "cdn-cache; desc\u003dMISS",
    "edge; dur\u003d408",
    "origin; dur\u003d993"
  ],
  "strict-transport-security": "max-age\u003d31536000 ; includeSubDomains"
}
body
CONFORMANCE_SUITE_JSON_NULL
2022-12-13 15:36:15 SUCCESS
EnsureHttpStatusCodeIs4xx
resource endpoint http status code was 400
2022-12-13 15:36:15 FINISHED
fapi1-advanced-final-attempt-reuse-authorisation-code-after-one-second
Test has run to completion
testmodule_result
PASSED
2022-12-13 15:36:19
TEST-RUNNER
Alias has now been claimed by another test
alias
fapipoc_fapi_jarm
new_test_id
c1uyL0Lz8P99CBY
Test Results