This repository contains the output of the OpenID AuthZEN working group.
The AuthZEN authorization API is versioned in markdown at api/authorization-api-1_0.md. A GitHub workflow builds this into HTML. See the "Building the spec" section for more details.
The latest published version of the spec is available here.
COAZ (Compatible with OpenID AuthZEN) is a protocol-neutral framework for mapping the information model of an arbitrary protocol or interface into a request to the AuthZEN Authorization API. It is at profiles/authzen-coaz-framework-1_0.md. The HTML version is available here.
COAZ-MCP is the COAZ binding for the Model Context Protocol (MCP), defining how MCP JSON-RPC messages map into AuthZEN Authorization API requests. It is at profiles/authzen-coaz-mcp-binding-1_0.md. The HTML version is available here.
A profile that specifies an approval workflow for handling denials in a structured way. The HTML version is available here
A profile for using the AuthZEN Authorization API to externalize an authorization server's decision to issue a token, and to let the decision response shape what is issued. It is at profiles/authzen-oauth/authzen-oauth-token-issuance-1_0.md. The HTML version is available here.
The binding of the token issuance profile to OAuth 2.0 Token Exchange, covering delegation, impersonation, identity chaining, ID-JAG and Transaction Tokens. It is at profiles/authzen-oauth/authzen-oauth-token-exchange-1_0.md. The HTML version is available here.
A profile that sources the groups, roles and entitlements claims of a JWT access token from AuthZEN Resource Search rather than from a directory or a vendor-specific hook. It is at profiles/authzen-oauth/authzen-oauth-authorization-claims-1_0.md. The HTML version is available here.
The interop directory contains the interoperability scenarios for AuthZEN. Currently, there is a single scenario based on a "Todo" application. The scenario spec and results can be viewed here.
interop/authzen-interop-websitecontains the source code for the https://authzen-interop.net micro-site. It is based on the Docusaurus framework.interop/authzen-todo-applicationcontains the source code for the Todo React front-end hosted at https://todo.authzen-interop.net.interop/authzen-todo-backendcontains the source code for the (TypeScript) Todo backend.
Each of these directories contains a README for further instructions.
To build the spec locally, you need two tools - kramdown (a Ruby gem), and xml2rfc (a python tool).
The GitHub workflow in .github/workflows/jekyll-gh-pages.yml runs on each PR that is merged to main, resulting in a new HTML version of the spec hosted at https://openid.github.io/authzen.
To build locally, ensure that you have both a Python and Ruby distribution.
gem install kramdown-rfc
pip install xml2rfc# Convert from markdown to XML
kramdown-rfc2629 api/authorization-api-1_0.md > api/authorization-api-1_0.xml
# Render XML into HTML
xml2rfc api/authorization-api-1_0.xml --html -o index.html