Skip to content

Make oauth.token_endpoint optional - #27

Merged
frostevent merged 1 commit into
mainfrom
jeremie/optional-token-endpoint
Sep 29, 2026
Merged

frostevent merged 1 commit into
mainfrom
jeremie/optional-token-endpoint

Conversation

@frostevent

Copy link
Copy Markdown
Collaborator

Summary

  • OAuthMetadata.token_endpoint is now optional in the type.
  • parseX401Payload still requires the oauth object but only checks token_endpoint is a string when it is present.
  • Added tests: round-trip without token_endpoint, rejection of a non-string token_endpoint, rejection of a missing oauth object.
  • Updated spec/conformance.md and the README to reflect the new behavior.

The spec (v0.2.0) currently marks token_endpoint as REQUIRED. That is a spec error and will be corrected. The pinned spec artifacts (spec/fixtures/request.schema.json, spec/normative-ledger.json) are verbatim copies of the published spec and are left untouched; they will be re-synced once the spec is updated.

Test plan

  • yarn check-all passes (format, lint, typecheck, 38 tests, publint).

🤖 Generated with Claude Code

The spec currently marks token_endpoint as REQUIRED, but that is being
corrected. The parser still requires the oauth object and only checks
token_endpoint is a string when it is present.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
@frostevent
frostevent merged commit 0a04130 into main Sep 29, 2026
8 checks passed
@frostevent
frostevent deleted the jeremie/optional-token-endpoint branch September 29, 2026 11:55
This was referenced Sep 29, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant