keycloak-scim/server_admin/topics/threat/audience-limit.adoc

5 lines
283 B
Text
Raw Normal View History

=== Limit Token Audience
In environments with low levels of trust among services, limit the audiences on the token. See the https://tools.ietf.org/html/rfc6819#section-5.1.5.5[OAuth2 Threat Model] and the xref:con-audience_{context}[Audience Support] section for more information.