oauth-authorization-server metadata (RFC 8414)
A fully populated RFC 8414 authorization-server metadata document for a fictional issuer: seven endpoints including PAR, introspection and dynamic registration, PKCE and DPoP algorithm lists, and policy URIs. Distinct from the minimal OpenID configuration already in this category.
{
"issuer": "https://id.example.com",
"authorization_endpoint": "https://id.example.com/oauth2/authorize",
"token_endpoint": "https://id.example.com/oauth2/token",
"introspection_endpoint": "https://id.example.com/oauth2/introspect",
"revocation_endpoint": "https://id.example.com/oauth2/revoke",
"registration_endpoint": "https://id.example.com/oauth2/register",
"pushed_authorization_request_endpoint": "https://id.example.com/oauth2/par",
"require_pushed_authorization_requests": false,
"jwks_uri": "https://id.example.com/oauth2/jwks.json",
"scopes_supported": [
"openid",
"profile",
"email",
"catalog.read",
"catalog.write"
],
"response_types_supported": [
"code",
"code id_token"
],
"response_modes_supported": [
"query",
"fragment",
"form_post"
],
"grant_types_supported": [
"authorization_code",
"refresh_token",
"client_credentials"
],
"token_endpoint_auth_methods_supported": [
"client_secret_basic",
"private_key_jwt",
"none"
],
"token_endpoint_auth_signing_alg_values_supported": [
"RS256",
"ES256"
],
"code_challenge_methods_supported": [
"S256"
],
"dpop_signing_alg_values_supported": [
"ES256",
"RS256"
],
"service_documentation": "https://id.example.com/docs",
"ui_locales_supported": [
"en",Specifications
- Seed
- 70400
- Site
- example.com (fictional)
- Format
- OAuth 2.0 AS metadata (RFC 8414)
- Endpoints
- 7
- Scopes
- 5
- Pkce
- S256
- Dpop
- true
- Location
- /.well-known/oauth-authorization-server
Testing contract
Expected to pass- Scenario
- Bootstrap an OAuth client from the issuer's metadata document.
- Expected result
- The client discovers the token, authorization and PAR endpoints, selects S256 for PKCE, offers private_key_jwt authentication, and validates that `issuer` matches the host the document was fetched from.
What is a .json file?
JSON (JavaScript Object Notation) is a lightweight, text-based data-interchange format representing objects, arrays, strings, numbers, booleans, and null. It is language-independent, human-readable, and the dominant format for web APIs and configuration. It requires a single well-formed root value.
How to use this file
Use an example JSON file to test parsers and serializers, schema validation, Unicode and number-precision handling, and API request or response processing.
How to use this file for testing
“oauth-authorization-server metadata (RFC 8414)” is a deterministic Novus Examples fixture for Web assets, JSON parsing, Schema validation. Favicons, web app manifests, service workers, robots and sitemap files, Open Graph images, and .well-known resources — for testing web tooling, crawlers, PWA installers, and asset pipelines.
Documented properties for this file: seed 70400 · OAuth 2.0 AS metadata (RFC 8414). Compare results against paired or grouped companions on this page when present (clean↔damaged, searchable↔scanned, or format twins) so scores stay reproducible across runs.
Download the file once, keep the path stable in CI or local scripts, and treat the spec table as the contract: dimensions, seeds, field lists, and roles are intentional. Corrupt or invalid samples are labelled as such — expect parsers to fail loudly rather than silently accept them.
Web-platform fixtures are standards-compliant samples against fictional example.com data. Test crawlers, PWA installers and manifest validators, favicon/icon pipelines, service-worker registration, or .well-known parsers against the documented structure.
Code examples
import json
with open("oauth-authorization-server.json") as f:
data = json.load(f)
print(type(data), len(data))Related files
- jsonJSON-LD @graph with @id cross-referencesA single @graph holding four nodes wired together by @id rather than by nesting - the shape most CMS plugins emit - including a SearchAction, a breadcrumb whose last item has no URL, and one reference to a product node that lives on another page. For testing graph flattening and reference resolution.

- jsonJSON-LD Event with offers and a locationA valid Event record for a hybrid event: both a physical Place with a postal address and geo coordinates and a VirtualLocation, plus a free Offer and a capacity. For testing array-valued properties and event date/timezone handling.

- jsonJSON-LD LocalBusiness with opening hoursA valid LocalBusiness (as a SportingGoodsStore subtype) with a postal address, geo coordinates, weekday and Saturday opening hours, and a 00:00-00:00 specification marking a holiday closure. For testing opening-hours parsing and the closed-all-day convention.

- jsonJSON-LD missing required properties (deliberately invalid)A deliberately invalid Product record: no name, an Offer with a currency but no price, a brand with no @type, a Review with no rating, an AggregateRating with no ratingValue, and an availability given as a bare token instead of a schema.org URL. Valid JSON throughout, so the failure is semantic.

- jsonJSON-LD NewsArticle with author and publisherA valid NewsArticle with two authors, a publisher whose logo carries explicit pixel dimensions, three images at the aspect ratios news results expect, and both publication and modification timestamps. For testing article extraction and date normalisation.

- jsonJSON-LD Product with Offer and AggregateRatingA valid Product record with a nested Offer carrying price, currency, availability, condition and shipping details, plus an AggregateRating. For testing rich-result validators and structured-data extractors against a document that should pass cleanly.

Generated by generation/web_p7.py. Free for any use, no attribution required — license.