Findings
FND-1043 · OAuth & Authentication · Production

OAuth audience references legacy token endpoint

CriticalAssignedCutover blocker
View evidence

Detected vs required

Detected configuration

aud = https://matls-auth.directory.openbanking.org.uk/token

Required target

aud = https://auth.directory.openbanking.org.uk

Impact

Directory-issued tokens will be rejected once the new issuer is enforced, blocking all TPP client-credential flows.

Remediation guidance

REM-102

Update the expected audience to the new issuer and retest token validation in Sandbox then Production.

Remediation workflow: ASSIGNED · Owner L. Mensah · Due 2026-09-26 · OBMIG-241

Evidence

2 artefacts linked to this finding or its control on the affected system

  • EVD-2003Validating OAuth audience — FAILOAuth test12 Sept, 12:21Pending
  • EVD-4002jans-auth-server.propertiesConfiguration snapshot13 Sept, 06:10Approved

Context

System
Jans IAM
Environment
Production
Control
OAUTH-002OAuth audience uses new issuer
Category
OAuth & Authentication
Owner
L. Mensah
Detected
13 Sept, 06:10
Evidence ref
jans-auth-server.properties · oauth.expected.audience
Cutover blocker
Yes

Linked tests

TST-004Validating OAuth audienceFAIL