Refuses query.jwt with a response type carrying a token, unless the response is encrypted (section 2.3.1).
query.jwt
the JARM response mode
the response_type
the client's registration
null, or a refusal carrying its error code
Refuses
query.jwtwith a response type carrying a token, unless the response is encrypted (section 2.3.1).