query, client, issuer, asBase, profile (what the
selected authorization server publishes), keySet, authorizationServer
and req
a promise of { ok: true, used: false } for a request that is not
JWT-secured, { ok: true, used: true, params, source, alg, encrypted, once } for one that is, or a refusal; it never rejects
Resolves an authorization request's
requestorrequest_uri: the one entry point for the authorization endpoint.