Registers an external authorization server this whole deployment is willing
to accept workload tokens from, and returns the derivedAudience that
must be configured in that server.
š“ Every tenant inherits this declaration. A tenant's effective trust set
is the deployment-scoped issuers union its own, so enabling one row here
widens what every tenant on the deployment will accept a token from. Declare an
issuer here when the operator also owns the workloads; declare it on the tenant
when one customer owns them.
The declaration lands switched off. enabled is server-set to
false and cannot be sent: a body carrying it is rejected, and admitting
the issuer into the trust set is the separate enable verb. On this
plane that separation is what keeps an abandoned half-finished form from becoming a
deployment-wide change.
derivedAudience is the deployment audience here, not a
per-tenant one ā it follows the SCOPE of the declaration rather than the deployment
type. Configure it verbatim as the API identifier of the machine-to-machine
application in the external IdP.
š“ No credential is submitted here, and none exists. ANKASecure verifies
tokens from this issuer against the public key set the issuer itself publishes, so
there is nothing to store, seal, mask or rotate.
Never entitlement-gated. No Edition widens or narrows this plane; the only
condition is that the deployment is customer-operated.
| Time | Status | User Agent | |
|---|---|---|---|
Retrieving recent requests⦠| |||