the client's registration, as
applications.clientConfigOf() answers it
Optionaladvertised: any
what the selected authorization server publishes, as { signing, encryption, enc } lists, or null members where it publishes
none
{ ok: true, signAlg, encAlg, encEnc }, or { ok: false, description } carrying an error code
Works out how a client's response is to be signed and encrypted, from what it registered with section 6's defaults applied.
A value this service cannot honour is refused rather than replaced; one the selected authorization server does not advertise is refused with
notAdvertised: true, which the endpoint answers as the client's problem.