atproto pds in zig pds.zat.dev
pds atproto

oauth: accept inline jwks for private_key_jwt client assertions master

verifyClientAssertion read only jwks_uri from the client document, so a client publishing its keys inline as jwks (atcr.io does) failed with InvalidClientMetadata and PAR answered 400 invalid_client. Client metadata carries keys either way; the reference provider accepts either and refuses both at once. src/internal/client_attestation.zig already handled both; the OAuth token path now does the same. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Th6389kN3H2AyUae7yEJAW


+58 -3
2 changed files