Replaces the declaration whole. Every field is taken from the body, so an omitted
optional field is CLEARED rather than kept — a partial update would leave an
operator unable to see, from the request alone, what the issuer will admit
afterwards.
🔴 The issuer URL is immutable. A body naming a different one
answers 409, because renaming the issuer is not an edit to this trust relationship
— it is a different one, and doing it in place would move every existing actor
binding to an authorization server nobody reviewed. Withdraw and declare again.
A replace that narrows permittedAlgorithms or lowers
maximumTokenLifetime takes effect on the very next token presented.
That is a change to a live authentication rule made by an operator on a customer's
behalf, which is why the audit row for it carries the pre-change state as well as
the new one, and is visible to the customer.
Not entitlement-gated. The operator is the party that sells the edition, so
refusing them on it would be the platform refusing itself. The tenant's own verdict is
readable at ../workload-identity/entitlement (SR-10.6).
| Time | Status | User Agent | |
|---|---|---|---|
Retrieving recent requests… | |||