FND-1043 · OAuth & Authentication · Production
OAuth audience references legacy token endpoint
CriticalAssignedCutover blocker
Detected vs required
Detected configuration
aud = https://matls-auth.directory.openbanking.org.uk/token
Required target
aud = https://auth.directory.openbanking.org.uk
Impact
Directory-issued tokens will be rejected once the new issuer is enforced, blocking all TPP client-credential flows.
Remediation guidance
Update the expected audience to the new issuer and retest token validation in Sandbox then Production.
Remediation workflow: ASSIGNED · Owner L. Mensah · Due 2026-09-26 · OBMIG-241
Evidence
2 artefacts linked to this finding or its control on the affected system
- EVD-2003Validating OAuth audience — FAILOAuth test12 Sept, 12:21Pending
- EVD-4002jans-auth-server.propertiesConfiguration snapshot13 Sept, 06:10Approved
Context
- System
- Jans IAM
- Environment
- Production
- Control
- OAUTH-002 — OAuth audience uses new issuer
- Category
- OAuth & Authentication
- Owner
- L. Mensah
- Detected
- 13 Sept, 06:10
- Evidence ref
- jans-auth-server.properties · oauth.expected.audience
- Cutover blocker
- Yes
Linked tests
TST-004Validating OAuth audienceFAIL