Client Authentication
Authentication can take many forms beyond the obvious user authentication. Many times the client application itself must provide some form of authentication in order to be trusted by the server application.
Since the various client authentication mechanisms may differ, the Client SDK defines the style of client authentication as an enumeration which is passed to the client configuration. This allows for different authentication schemes to be defined simply by the developer, while both encapsulating the business logic for how this authentication occurs, and supporting future expansion without breaking API changes.
Implementation
None
No client authentication headers will be supplied to the server. This should be defined as the default.
Client Secret
The developer-supplied client secret password will be included in the client_secret request body key for interactions with the authorization server.
Client Assertion (aka Public/Private Key)
<TBD>