invoke

suspend operator fun invoke(signJwt: SignJwtFun<JsonWebToken>, audience: String, nonce: String? = null, clockSkew: Duration = 3.minutes, randomSource: RandomSource = RandomSource.Secure): JwsCompactTyped<JsonWebToken>(source)

Client attestation PoP JWT, issued by the client, which can be sent to an OAuth2 Authorization Server if needed, e.g. as HTTP header OAuth-Client-Attestation-PoP, see OAuth 2.0 Attestation-Based Client Authentication

Parameters

audience

The RFC8414 issuer identifier URL of the authorization server or the resource server MUST be used

nonce

optionally provided from the authorization server

clockSkew

duration to subtract from Clock.System.now when setting the creation timestamp