Skip to main content
Pushed Authorization Requests (PAR, RFC 9126) and JWT-Secured Authorization Requests (JAR, RFC 9101) are two complementary enhancements to the OAuth 2.1 authorization code flow. Together with JWT-Bearer client authentication (RFC 7523), they form the FAPI 2.0 Security Profile baseline required by open banking, healthcare, and other regulated API ecosystems.

Why PAR and JAR?

In the standard authorization code flow, all authorization parameters are sent as query parameters in the browser redirect URL. This has two problems:
  1. Integrity: a network adversary or a compromised browser can tamper with the parameters before the request reaches the authorization server.
  2. Confidentiality: sensitive parameters (scope, claims, resource) are visible in browser history, server access logs, and referrer headers.
PAR solves confidentiality and integrity by sending the request body directly to the AS over a back-channel HTTPS connection before the browser redirect. JAR solves integrity by wrapping the parameters in a signed JWT that the AS verifies against the client’s registered public key.

Standard flow (before PAR/JAR)

Problem: all parameters, including scope and resource, travel through the browser address bar.

Flow with PAR

Advantage: the browser only ever sees the opaque request_uri handle. All sensitive parameters stay server-to-server.

Flow with JAR (on top of PAR)

The /oauth/par body includes a request JWT parameter instead of (or in addition to) plain parameters:
The request JWT is signed with the client’s private key. The AS verifies the signature against the client’s registered public key (jwks_uri or inline jwks). A tampered request JWT fails signature verification and is rejected with invalid_request_object. Advantage: even if the back-channel POST is intercepted or replayed, the parameters cannot be altered without detection.

FAPI 2.0 baseline

FAPI 2.0 (Financial-grade API Security Profile 2.0) requires:
  • PAR (RFC 9126): mandatory.
  • JAR (RFC 9101): mandatory.
  • PKCE S256: mandatory (already mandatory in theauth-go by default).
  • JWT-Bearer client authentication (RFC 7523): mandatory (added in v2.4, see JWT-Bearer).
When all three are active, theauth-go satisfies the FAPI 2.0 Security Profile baseline.

Enabling PAR

The AS advertises PAR support in its metadata: pushed_authorization_request_endpoint: https://auth.example.com/oauth/par.

Enabling JAR

The AS advertises JAR support: request_object_signing_alg_values_supported: ["ES256", "PS256"].

PAR endpoint reference

POST /oauth/par Response (200 OK):
Then redirect the user to:

See also

Last modified on October 7, 2026