/oauth/token
/oauth/par
/userinfo
cname-api-key
header.
client-certificate
header. Note: Since HTTP headers must be text, the certificate must be converted to a URL component encoded PEM. The header value is limited to 4096 bytes. Therefore, only the first certificate in the chain should be forwarded to Auth0.
client-certificate-ca-verified
header. The client-certificate-ca-verified
header can have the following values:
client-certificate-ca-verified:FAILED
header. Depending on this header value, Auth0 knows which client authentication method has been used and which client credentials need to be verified against.