Section 4.3 currently states:
Wallets MUST authenticate themselves at the PAR endpoint using the same rules as defined in Section 4.4 for client authentication at the token endpoint.
However, Section 4.4 does not define any rules for client authentication at the token endpoint, so the reference is currently incorrect.
In practice, because HAIP requires FAPI, client authentication at the PAR endpoint is mandatory through the referenced FAPI requirements. Nevertheless, the current wording is confusing because it points to a section that does not actually define the referenced behavior.
Proposal:
Update the text in Section 4.3 to reference the appropriate normative source for client authentication, rather than Section 4.4, or alternatively add the missing client authentication rules to Section 4.4 if that was the original intent.
This would make the specification internally consistent while preserving the existing interoperability requirements.
Section 4.3 currently states:
However, Section 4.4 does not define any rules for client authentication at the token endpoint, so the reference is currently incorrect.
In practice, because HAIP requires FAPI, client authentication at the PAR endpoint is mandatory through the referenced FAPI requirements. Nevertheless, the current wording is confusing because it points to a section that does not actually define the referenced behavior.
Proposal:
Update the text in Section 4.3 to reference the appropriate normative source for client authentication, rather than Section 4.4, or alternatively add the missing client authentication rules to Section 4.4 if that was the original intent.
This would make the specification internally consistent while preserving the existing interoperability requirements.