跳转到内容

token_issuer_unauthorised

← Error codes

errortoken_issuer_unauthorised· reason_code· applies to service_call, auth_decision

A media token's `service_signature.kid` or `participant_binding.issuer_kid` resolves to a service DID that does NOT appear in the current epoch `ak.realm.media_service.service_id` (or the foci[]-aligned token endpoint authority commit). Clients MUST reject — this closes the attack where any service can forge a focus join token. See zh/crypto-media/media-service-binding.md §3.

Source