{"kind": "conn", "major": "18", "item": {"slug": "oauth-issuer", "name": "oauth_issuer", "name_zh": "", "category": "Authentication", "summary": "The HTTPS URL of a trusted issuer to contact if the server requests an OAuth token for the connection. This parameter is required for all OAuth connections; it should exactly match the issuer setting in the server's HBA configuration .", "aliases": ["oauth_issuer"], "content_hash": "4bf7411991e894cdddfbd8ddd85ecc54313ed982f5d0248011abf1b0da0d54fe", "versions": {"18": {"facts": [{"label": "Client library", "value": "libpq 18.6"}, {"label": "Manual definition", "value": "Documented"}, {"label": "Source environment fallback", "value": "None declared in the option table"}, {"label": "Compiled fallback expression", "value": "NULL"}], "tables": [], "keyword": "oauth_issuer", "related": [{"url": "/docs/18/libpq-pgservice.html", "label": "Connection service file"}, {"url": "/docs/18/libpq-pgpass.html", "label": "Password file"}, {"url": "/docs/18/libpq-envars.html", "label": "All libpq environment variables"}], "release": {"ref": "https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2", "label": "18.6", "major": "18", "channel": "stable", "manifest": {"pdf": {"A4": {"url": "/files/documentation/pdf/18/postgresql-18-A4.pdf", "bytes": 15865106, "pages": 3154, "sha256": "19512c405da53f9f7fcf0abba359223aa65f021be025bf3411381918f92e3190", "built_at": "2026-09-26"}, "US": {"url": "/files/documentation/pdf/18/postgresql-18-US.pdf", "bytes": 15748059, "pages": 3328, "sha256": "facbe6c229e598b872d3d98bef53308f46e06746006fa4590de9a7de9dd46319", "built_at": "2026-09-26"}}, "tree": "18", "index": "index.html", "major": "18", "pages": 1148, "release": "18.6", "source_url": "https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2", "svg_assets": 3, "source_mode": "en SGML built with pinned official archive", "source_sha256": "555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f"}, "revision": "ee8d1a3612338fd9adf250730cb640fcc5233b5491337cc00a316a44e3a0b9f8", "evidence_kind": "English manual and source declarations", "source_sha256": "555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f"}, "sources": [{"url": "/docs/18/libpq-connect.html#LIBPQ-CONNECT-OAUTH-ISSUER", "file": "libpq-connect.html", "label": "18.6 English manual \u00b7 libpq-connect.html", "anchor": "LIBPQ-CONNECT-OAUTH-ISSUER", "sha256": "c26a7fc3dcda6066cfe540641ae2690faf3d3c03277f30b4dfc2328ab45c212f"}, {"url": "https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2", "file": "src/interfaces/libpq/fe-connect.c", "label": "18.6 libpq connection option declarations", "sha256": "44a6e386cbfd67ebe768d6ef5493098119c2e6b4796239d53e5ed7b122b206a5", "archive_sha256": "555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f"}, {"url": "/docs/18/libpq-envars.html", "file": "libpq-envars.html", "label": "18.6 English manual \u00b7 libpq-envars.html", "anchor": "", "sha256": "d64db73f3d48127bb984a5f775e77b7bcca2ba4bd218333cf24a45fcdd7c4363"}, {"url": "/docs/18/libpq-pgservice.html", "file": "libpq-pgservice.html", "label": "18.6 English manual \u00b7 libpq-pgservice.html", "anchor": "", "sha256": "6035a3f0ee1d0fd80db5bf58834390b884eecd23206659bdf6f07560deea5aa7"}], "sections": [{"title": "Default resolution and service-file precedence", "paragraphs": ["The following environment variables can be used to select default connection parameter values, which will be used by PQconnectdb , PQsetdbLogin and PQsetdb if no value is directly specified by the calling code. These are useful to avoid hard-coding database connection information into simple client applications, for example.", "Service names can be defined in either a per-user service file or a system-wide file. If the same service name exists in both the user and the system file, the user file takes precedence. By default, the per-user service file is named ~/.pg_service.conf . On Microsoft Windows, it is named %APPDATA%\\postgresql\\.pg_service.conf (where %APPDATA% refers to the Application Data subdirectory in the user's profile). A different file name can be specified by setting the environment variable PGSERVICEFILE . The system-wide file is named pg_service.conf . By default it is sought in the etc directory of the PostgreSQL installation (use pg_config --sysconfdir to identify this directory precisely). Another directory, but not a different file name, can be specified by setting the environment variable PGSYSCONFDIR .", "Connection parameters obtained from a service file are combined with parameters obtained from other sources. A service file setting overrides the corresponding environment variable, and in turn can be overridden by a value given directly in the connection string. For example, using the above service file, a connection string service=mydb port=5434 will use host somehost , port 5434 , user admin , and other parameters as set by environment variables or built-in defaults."]}, {"title": "Environment variable evidence", "paragraphs": []}], "signature": "oauth_issuer", "documented": true, "description": ["The HTTPS URL of a trusted issuer to contact if the server requests an OAuth token for the connection. This parameter is required for all OAuth connections; it should exactly match the issuer setting in the server's HBA configuration ."], "environment": [], "manual_html": "<div><dl class=\"variablelist\"><dt id=\"LIBPQ-CONNECT-OAUTH-ISSUER\"><span class=\"term\"><code class=\"literal\">oauth_issuer</code></span> </dt><dd>\n<p>The HTTPS URL of a trusted issuer to contact if the server requests an OAuth token for the connection. This parameter is required for all OAuth connections; it should exactly match the <code class=\"literal\">issuer</code> setting in <a class=\"link\" href=\"/docs/18/auth-oauth.html\" title=\"20.15.\u00a0OAuth Authorization/Authentication\">the server's HBA configuration</a>.</p>\n<p>As part of the standard authentication handshake, <span class=\"application\">libpq</span> will ask the server for a <span class=\"emphasis\"><em>discovery document:</em></span> a URL providing a set of OAuth configuration parameters. The server must provide a URL that is directly constructed from the components of the <code class=\"literal\">oauth_issuer</code>, and this value must exactly match the issuer identifier that is declared in the discovery document itself, or the connection will fail. This is required to prevent a class of <a class=\"ulink\" href=\"https://mailarchive.ietf.org/arch/msg/oauth/JIVxFBGsJBVtm7ljwJhPUm3Fr-w/\">\"mix-up attacks\"</a> on OAuth clients.</p>\n<p>You may also explicitly set <code class=\"literal\">oauth_issuer</code> to the <code class=\"literal\">/.well-known/</code> URI used for OAuth discovery. In this case, if the server asks for a different URL, the connection will fail, but a <a class=\"link\" href=\"/docs/18/libpq-oauth.html#LIBPQ-OAUTH-AUTHDATA-HOOKS\" title=\"32.20.1.\u00a0Authdata Hooks\">custom OAuth flow</a> may be able to speed up the standard handshake by using previously cached tokens. (In this case, it is recommended that <a class=\"xref\" href=\"/docs/18/libpq-connect.html#LIBPQ-CONNECT-OAUTH-SCOPE\">oauth_scope</a> be set as well, since the client will not have a chance to ask the server for a correct scope setting, and the default scopes for a token may not be sufficient to connect.) <span class=\"application\">libpq</span> currently supports the following well-known endpoints:</p>\n<div class=\"itemizedlist\">\n<ul class=\"itemizedlist compact\">\n<li class=\"listitem\">\n<p><code class=\"literal\">/.well-known/openid-configuration</code></p>\n</li>\n<li class=\"listitem\">\n<p><code class=\"literal\">/.well-known/oauth-authorization-server</code></p>\n</li>\n</ul>\n</div>\n<div class=\"warning\">\n<h3 class=\"title\">Warning</h3>\n<p>Issuers are highly privileged during the OAuth connection handshake. As a rule of thumb, if you would not trust the operator of a URL to handle access to your servers, or to impersonate you directly, that URL should not be trusted as an <code class=\"literal\">oauth_issuer</code>.</p>\n</div>\n</dd></dl></div>", "manual_path": "libpq-connect.html#LIBPQ-CONNECT-OAUTH-ISSUER", "source_option": {"keyword": "oauth_issuer", "declaration": "\"oauth_issuer\", NULL, NULL, NULL, \"OAuth-Issuer\", \"\", 40, offsetof(struct pg_conn, oauth_issuer)", "environment": "", "source_notes": [], "compiled_default_expression": "NULL"}, "comparison_data": {"keyword": "oauth_issuer", "definition": "The HTTPS URL of a trusted issuer to contact if the server requests an OAuth token for the connection. This parameter is required for all OAuth connections; it should exactly match the issuer setting in the server's HBA configuration . As part of the standard authentication handshake, libpq will ask the server for a discovery document: a URL providing a set of OAuth configuration parameters. The server must provide a URL that is directly constructed from the components of the oauth_issuer , and this value must exactly match the issuer identifier that is declared in the discovery document itself, or the connection will fail. This is required to prevent a class of \"mix-up attacks\" on OAuth clients. You may also explicitly set oauth_issuer to the /.well-known/ URI used for OAuth discovery. In this case, if the server asks for a different URL, the connection will fail, but a custom OAuth flow may be able to speed up the standard handshake by using previously cached tokens. (In this case, it is recommended that oauth_scope be set as well, since the client will not have a chance to ask the server for a correct scope setting, and the default scopes for a token may not be sufficient to connect.) libpq currently supports the following well-known endpoints: /.well-known/openid-configuration /.well-known/oauth-authorization-server Warning Issuers are highly privileged during the OAuth connection handshake. As a rule of thumb, if you would not trust the operator of a URL to handle access to your servers, or to impersonate you directly, that URL should not be trusted as an oauth_issuer .", "documented": true, "environment": "", "default_evidence": ["You may also explicitly set oauth_issuer to the /.well-known/ URI used for OAuth discovery. In this case, if the server asks for a different URL, the connection will fail, but a custom OAuth flow may be able to speed up the standard handshake by using previously cached tokens. (In this case, it is recommended that oauth_scope be set as well, since the client will not have a chance to ask the server for a correct scope setting, and the default scopes for a token may not be sufficient to connect.) libpq currently supports the following well-known endpoints:"], "compiled_default_expression": "NULL"}, "comparison_hash": "9afc5e8603b6a862d897284099f310b696b3365ecc6dbb724802de062d37fa13", "default_evidence": ["You may also explicitly set oauth_issuer to the /.well-known/ URI used for OAuth discovery. In this case, if the server asks for a different URL, the connection will fail, but a custom OAuth flow may be able to speed up the standard handshake by using previously cached tokens. (In this case, it is recommended that oauth_scope be set as well, since the client will not have a chance to ask the server for a correct scope setting, and the default scopes for a token may not be sufficient to connect.) libpq currently supports the following well-known endpoints:"], "precedence_evidence": ["The following environment variables can be used to select default connection parameter values, which will be used by PQconnectdb , PQsetdbLogin and PQsetdb if no value is directly specified by the calling code. These are useful to avoid hard-coding database connection information into simple client applications, for example.", "Service names can be defined in either a per-user service file or a system-wide file. If the same service name exists in both the user and the system file, the user file takes precedence. By default, the per-user service file is named ~/.pg_service.conf . On Microsoft Windows, it is named %APPDATA%\\postgresql\\.pg_service.conf (where %APPDATA% refers to the Application Data subdirectory in the user's profile). A different file name can be specified by setting the environment variable PGSERVICEFILE . The system-wide file is named pg_service.conf . By default it is sought in the etc directory of the PostgreSQL installation (use pg_config --sysconfdir to identify this directory precisely). Another directory, but not a different file name, can be specified by setting the environment variable PGSYSCONFDIR .", "Connection parameters obtained from a service file are combined with parameters obtained from other sources. A service file setting overrides the corresponding environment variable, and in turn can be overridden by a value given directly in the connection string. For example, using the above service file, a connection string service=mydb port=5434 will use host somehost , port 5434 , user admin , and other parameters as set by environment variables or built-in defaults."]}, "19": {"facts": [{"label": "Client library", "value": "libpq 19beta4"}, {"label": "Manual definition", "value": "Documented"}, {"label": "Source environment fallback", "value": "None declared in the option table"}, {"label": "Compiled fallback expression", "value": "NULL"}], "tables": [], "keyword": "oauth_issuer", "related": [{"url": "/docs/19/libpq-pgservice.html", "label": "Connection service file"}, {"url": "/docs/19/libpq-pgpass.html", "label": "Password file"}, {"url": "/docs/19/libpq-envars.html", "label": "All libpq environment variables"}], "release": {"ref": "https://ftp.postgresql.org/pub/source/v19beta4/postgresql-19beta4.tar.bz2", "label": "19beta4", "major": "19", "channel": "preview", "manifest": {"pdf": {"A4": {"url": "/files/documentation/pdf/19/postgresql-19-A4.pdf", "bytes": 16064841, "pages": 3052, "sha256": "4dd099e4125c591128fc5f3ebd02178dc24781f9e5ae629f96d67c4c8547427b", "built_at": "2026-09-26"}, "US": {"url": "/files/documentation/pdf/19/postgresql-19-US.pdf", "bytes": 15974616, "pages": 3225, "sha256": "61971fa857f0956d47341a0388fa6af9ae10acf691d4b2fc009007d384b0342b", "built_at": "2026-09-26"}}, "tree": "19", "index": "index.html", "major": "19", "pages": 1155, "release": "19beta4", "source_url": "https://ftp.postgresql.org/pub/source/v19beta4/postgresql-19beta4.tar.bz2", "svg_assets": 5, "source_mode": "en SGML built with pinned official archive", "source_sha256": "83157ee9c599d03b2f7a3d73ef3a56ec24e0e79cc2b3501a64d1364f56398c86"}, "revision": "1bbbbf4133d426f0e4304010688d2984c30fb67df0cc3a61b3e37eb3f6f37833", "evidence_kind": "English manual and source declarations", "source_sha256": "83157ee9c599d03b2f7a3d73ef3a56ec24e0e79cc2b3501a64d1364f56398c86"}, "sources": [{"url": "/docs/19/libpq-connect.html#LIBPQ-CONNECT-OAUTH-ISSUER", "file": "libpq-connect.html", "label": "19beta4 English manual \u00b7 libpq-connect.html", "anchor": "LIBPQ-CONNECT-OAUTH-ISSUER", "sha256": "14917417235a95d969bf3642c347dea7ae548c5f73b0dd00991a580ebcfbb47e"}, {"url": "https://ftp.postgresql.org/pub/source/v19beta4/postgresql-19beta4.tar.bz2", "file": "src/interfaces/libpq/fe-connect.c", "label": "19beta4 libpq connection option declarations", "sha256": "ae8005372c570ff47a4922c942238653a034f01f9db40c9e0f57cb48915ffd98", "archive_sha256": "83157ee9c599d03b2f7a3d73ef3a56ec24e0e79cc2b3501a64d1364f56398c86"}, {"url": "/docs/19/libpq-envars.html", "file": "libpq-envars.html", "label": "19beta4 English manual \u00b7 libpq-envars.html", "anchor": "", "sha256": "d8f0afee19bae6323942ea5415649fbd66e3880fe8c8415350fcf3915f7c7047"}, {"url": "/docs/19/libpq-pgservice.html", "file": "libpq-pgservice.html", "label": "19beta4 English manual \u00b7 libpq-pgservice.html", "anchor": "", "sha256": "4c858fe55701d703cc00e7adf55eeac09cafcfdc37929b8e23ccf8ba42af9f98"}], "sections": [{"title": "Default resolution and service-file precedence", "paragraphs": ["The following environment variables can be used to select default connection parameter values, which will be used by PQconnectdb , PQsetdbLogin and PQsetdb if no value is directly specified by the calling code. These are useful to avoid hard-coding database connection information into simple client applications, for example.", "Service names can be defined in either a per-user service file or a system-wide file. If the same service name exists in both the user and the system file, the user file takes precedence. By default, the per-user service file is named ~/.pg_service.conf . On Microsoft Windows, it is named %APPDATA%\\postgresql\\.pg_service.conf (where %APPDATA% refers to the Application Data subdirectory in the user's profile). A different file name can be specified using the servicefile key word in a libpq connection string or by setting the environment variable PGSERVICEFILE . The system-wide file is named pg_service.conf . By default it is sought in the etc directory of the PostgreSQL installation (use pg_config --sysconfdir to identify this directory precisely). Another directory, but not a different file name, can be specified by setting the environment variable PGSYSCONFDIR .", "Connection parameters obtained from a service file are combined with parameters obtained from other sources. A service file setting overrides the corresponding environment variable, and in turn can be overridden by a value given directly in the connection string. For example, using the above service file, a connection string service=mydb port=5434 will use host somehost , port 5434 , user admin , and other parameters as set by environment variables or built-in defaults."]}, {"title": "Environment variable evidence", "paragraphs": []}], "signature": "oauth_issuer", "documented": true, "description": ["The HTTPS URL of a trusted issuer to contact if the server requests an OAuth token for the connection. This parameter is required for all OAuth connections; it should exactly match the issuer setting in the server's HBA configuration ."], "environment": [], "manual_html": "<div><dl class=\"variablelist\"><dt id=\"LIBPQ-CONNECT-OAUTH-ISSUER\"><span class=\"term\"><code class=\"literal\">oauth_issuer</code></span> </dt><dd>\n<p>The HTTPS URL of a trusted issuer to contact if the server requests an OAuth token for the connection. This parameter is required for all OAuth connections; it should exactly match the <code class=\"literal\">issuer</code> setting in <a class=\"link\" href=\"/docs/19/auth-oauth.html\" title=\"20.14.\u00a0OAuth Authorization/Authentication\">the server's HBA configuration</a>.</p>\n<p>As part of the standard authentication handshake, <span class=\"application\">libpq</span> will ask the server for a <span class=\"emphasis\"><em>discovery document:</em></span> a URL providing a set of OAuth configuration parameters. The server must provide a URL that is directly constructed from the components of the <code class=\"literal\">oauth_issuer</code>, and this value must exactly match the issuer identifier that is declared in the discovery document itself, or the connection will fail. This is required to prevent a class of <a class=\"ulink\" href=\"https://mailarchive.ietf.org/arch/msg/oauth/JIVxFBGsJBVtm7ljwJhPUm3Fr-w/\">\"mix-up attacks\"</a> on OAuth clients.</p>\n<p>You may also explicitly set <code class=\"literal\">oauth_issuer</code> to the <code class=\"literal\">/.well-known/</code> URI used for OAuth discovery. In this case, if the server asks for a different URL, the connection will fail, but a <a class=\"link\" href=\"/docs/19/libpq-oauth.html#LIBPQ-OAUTH-AUTHDATA-HOOKS\" title=\"32.20.1.\u00a0Authdata Hooks\">custom OAuth flow</a> may be able to speed up the standard handshake by using previously cached tokens. (In this case, it is recommended that <a class=\"xref\" href=\"/docs/19/libpq-connect.html#LIBPQ-CONNECT-OAUTH-SCOPE\">oauth_scope</a> be set as well, since the client will not have a chance to ask the server for a correct scope setting, and the default scopes for a token may not be sufficient to connect.) <span class=\"application\">libpq</span> currently supports the following well-known endpoints:</p>\n<div class=\"itemizedlist\">\n<ul class=\"itemizedlist compact\">\n<li class=\"listitem\">\n<p><code class=\"literal\">/.well-known/openid-configuration</code></p>\n</li>\n<li class=\"listitem\">\n<p><code class=\"literal\">/.well-known/oauth-authorization-server</code></p>\n</li>\n</ul>\n</div>\n<div class=\"warning\">\n<h3 class=\"title\">Warning</h3>\n<p>Issuers are highly privileged during the OAuth connection handshake. As a rule of thumb, if you would not trust the operator of a URL to handle access to your servers, or to impersonate you directly, that URL should not be trusted as an <code class=\"literal\">oauth_issuer</code>.</p>\n</div>\n</dd></dl></div>", "manual_path": "libpq-connect.html#LIBPQ-CONNECT-OAUTH-ISSUER", "source_option": {"keyword": "oauth_issuer", "declaration": "\"oauth_issuer\", NULL, NULL, NULL, \"OAuth-Issuer\", \"\", 40, offsetof(struct pg_conn, oauth_issuer)", "environment": "", "source_notes": [], "compiled_default_expression": "NULL"}, "comparison_data": {"keyword": "oauth_issuer", "definition": "The HTTPS URL of a trusted issuer to contact if the server requests an OAuth token for the connection. This parameter is required for all OAuth connections; it should exactly match the issuer setting in the server's HBA configuration . As part of the standard authentication handshake, libpq will ask the server for a discovery document: a URL providing a set of OAuth configuration parameters. The server must provide a URL that is directly constructed from the components of the oauth_issuer , and this value must exactly match the issuer identifier that is declared in the discovery document itself, or the connection will fail. This is required to prevent a class of \"mix-up attacks\" on OAuth clients. You may also explicitly set oauth_issuer to the /.well-known/ URI used for OAuth discovery. In this case, if the server asks for a different URL, the connection will fail, but a custom OAuth flow may be able to speed up the standard handshake by using previously cached tokens. (In this case, it is recommended that oauth_scope be set as well, since the client will not have a chance to ask the server for a correct scope setting, and the default scopes for a token may not be sufficient to connect.) libpq currently supports the following well-known endpoints: /.well-known/openid-configuration /.well-known/oauth-authorization-server Warning Issuers are highly privileged during the OAuth connection handshake. As a rule of thumb, if you would not trust the operator of a URL to handle access to your servers, or to impersonate you directly, that URL should not be trusted as an oauth_issuer .", "documented": true, "environment": "", "default_evidence": ["You may also explicitly set oauth_issuer to the /.well-known/ URI used for OAuth discovery. In this case, if the server asks for a different URL, the connection will fail, but a custom OAuth flow may be able to speed up the standard handshake by using previously cached tokens. (In this case, it is recommended that oauth_scope be set as well, since the client will not have a chance to ask the server for a correct scope setting, and the default scopes for a token may not be sufficient to connect.) libpq currently supports the following well-known endpoints:"], "compiled_default_expression": "NULL"}, "comparison_hash": "9afc5e8603b6a862d897284099f310b696b3365ecc6dbb724802de062d37fa13", "default_evidence": ["You may also explicitly set oauth_issuer to the /.well-known/ URI used for OAuth discovery. In this case, if the server asks for a different URL, the connection will fail, but a custom OAuth flow may be able to speed up the standard handshake by using previously cached tokens. (In this case, it is recommended that oauth_scope be set as well, since the client will not have a chance to ask the server for a correct scope setting, and the default scopes for a token may not be sufficient to connect.) libpq currently supports the following well-known endpoints:"], "precedence_evidence": ["The following environment variables can be used to select default connection parameter values, which will be used by PQconnectdb , PQsetdbLogin and PQsetdb if no value is directly specified by the calling code. These are useful to avoid hard-coding database connection information into simple client applications, for example.", "Service names can be defined in either a per-user service file or a system-wide file. If the same service name exists in both the user and the system file, the user file takes precedence. By default, the per-user service file is named ~/.pg_service.conf . On Microsoft Windows, it is named %APPDATA%\\postgresql\\.pg_service.conf (where %APPDATA% refers to the Application Data subdirectory in the user's profile). A different file name can be specified using the servicefile key word in a libpq connection string or by setting the environment variable PGSERVICEFILE . The system-wide file is named pg_service.conf . By default it is sought in the etc directory of the PostgreSQL installation (use pg_config --sysconfdir to identify this directory precisely). Another directory, but not a different file name, can be specified by setting the environment variable PGSYSCONFDIR .", "Connection parameters obtained from a service file are combined with parameters obtained from other sources. A service file setting overrides the corresponding environment variable, and in turn can be overridden by a value given directly in the connection string. For example, using the above service file, a connection string service=mydb port=5434 will use host somehost , port 5434 , user admin , and other parameters as set by environment variables or built-in defaults."]}, "20": {"facts": [{"label": "Client library", "value": "libpq 20devel"}, {"label": "Manual definition", "value": "Documented"}, {"label": "Source environment fallback", "value": "None declared in the option table"}, {"label": "Compiled fallback expression", "value": "NULL"}], "tables": [], "keyword": "oauth_issuer", "related": [{"url": "/docs/devel/libpq-pgservice.html", "label": "Connection service file"}, {"url": "/docs/devel/libpq-pgpass.html", "label": "Password file"}, {"url": "/docs/devel/libpq-envars.html", "label": "All libpq environment variables"}], "release": {"ref": "https://ftp.postgresql.org/pub/snapshot/dev/postgresql-snapshot.tar.bz2", "label": "20devel", "major": "20", "channel": "devel", "manifest": {"pdf": {"A4": {"url": "/files/documentation/pdf/20/postgresql-20-A4.pdf", "bytes": 16030631, "pages": 3052, "sha256": "bd5d82c0ce38fc18f92a0447818a91a193a261776bca1c37564bf9a683e177d0", "built_at": "2026-09-28"}, "US": {"url": "/files/documentation/pdf/20/postgresql-20-US.pdf", "bytes": 15936613, "pages": 3223, "sha256": "d97d9e0db479a02f4234b175f50fcad70c3661619afc8d6df9b9437882e3c299", "built_at": "2026-09-28"}}, "tree": "0", "index": "index.html", "major": "20", "pages": 1156, "release": "20devel", "source_url": "https://ftp.postgresql.org/pub/snapshot/dev/postgresql-snapshot.tar.bz2", "svg_assets": 6, "source_mode": "en SGML built with pinned official archive", "source_sha256": "4d3346909b201ac1648232cf290462a7070c119326f56196f1f0253ed80fae41", "source_snapshot_utc": "26-Sep-2026 20:22"}, "revision": "2eba5e0fd4c3bffb2803247b6cd537878e9d6ee5a6dfbe3c50ece8b421b80918", "evidence_kind": "English manual and source declarations", "source_sha256": "4d3346909b201ac1648232cf290462a7070c119326f56196f1f0253ed80fae41"}, "sources": [{"url": "/docs/devel/libpq-connect.html#LIBPQ-CONNECT-OAUTH-ISSUER", "file": "libpq-connect.html", "label": "20devel English manual \u00b7 libpq-connect.html", "anchor": "LIBPQ-CONNECT-OAUTH-ISSUER", "sha256": "eeb28ce798c0f99c3581400b4baaae7687ee5d4176fcb9f5d2fd28809282d48f"}, {"url": "https://ftp.postgresql.org/pub/snapshot/dev/postgresql-snapshot.tar.bz2", "file": "src/interfaces/libpq/fe-connect.c", "label": "20devel libpq connection option declarations", "sha256": "d6eab6e2f37054b32a7ee7039b53beae603316f8ec3f0a14716061e042fc4aa1", "archive_sha256": "4d3346909b201ac1648232cf290462a7070c119326f56196f1f0253ed80fae41"}, {"url": "/docs/devel/libpq-envars.html", "file": "libpq-envars.html", "label": "20devel English manual \u00b7 libpq-envars.html", "anchor": "", "sha256": "7c49cf204e26ea86654491db5ea06c4f558c670e2e60a60b1dbf708ce682accc"}, {"url": "/docs/devel/libpq-pgservice.html", "file": "libpq-pgservice.html", "label": "20devel English manual \u00b7 libpq-pgservice.html", "anchor": "", "sha256": "a1ccd63a6e307a5541d58eabd57be5b467dff2480770838ec9b6a59a3ef110dc"}], "sections": [{"title": "Default resolution and service-file precedence", "paragraphs": ["The following environment variables can be used to select default connection parameter values, which will be used by PQconnectdb , PQsetdbLogin and PQsetdb if no value is directly specified by the calling code. These are useful to avoid hard-coding database connection information into simple client applications, for example.", "Service names can be defined in either a per-user service file or a system-wide file. If the same service name exists in both the user and the system file, the user file takes precedence. By default, the per-user service file is named ~/.pg_service.conf . On Microsoft Windows, it is named %APPDATA%\\postgresql\\.pg_service.conf (where %APPDATA% refers to the Application Data subdirectory in the user's profile). A different file name can be specified using the servicefile key word in a libpq connection string or by setting the environment variable PGSERVICEFILE . The system-wide file is named pg_service.conf . By default it is sought in the etc directory of the PostgreSQL installation (use pg_config --sysconfdir to identify this directory precisely). Another directory, but not a different file name, can be specified by setting the environment variable PGSYSCONFDIR .", "Connection parameters obtained from a service file are combined with parameters obtained from other sources. A service file setting overrides the corresponding environment variable, and in turn can be overridden by a value given directly in the connection string. For example, using the above service file, a connection string service=mydb port=5434 will use host somehost , port 5434 , user admin , and other parameters as set by environment variables or built-in defaults."]}, {"title": "Environment variable evidence", "paragraphs": []}], "signature": "oauth_issuer", "documented": true, "description": ["The HTTPS URL of a trusted issuer to contact if the server requests an OAuth token for the connection. This parameter is required for all OAuth connections; it should exactly match the issuer setting in the server's HBA configuration ."], "environment": [], "manual_html": "<div><dl class=\"variablelist\"><dt id=\"LIBPQ-CONNECT-OAUTH-ISSUER\"><span class=\"term\"><code class=\"literal\">oauth_issuer</code></span> </dt><dd>\n<p>The HTTPS URL of a trusted issuer to contact if the server requests an OAuth token for the connection. This parameter is required for all OAuth connections; it should exactly match the <code class=\"literal\">issuer</code> setting in <a class=\"link\" href=\"/docs/devel/auth-oauth.html\" title=\"20.14.\u00a0OAuth Authorization/Authentication\">the server's HBA configuration</a>.</p>\n<p>As part of the standard authentication handshake, <span class=\"application\">libpq</span> will ask the server for a <span class=\"emphasis\"><em>discovery document:</em></span> a URL providing a set of OAuth configuration parameters. The server must provide a URL that is directly constructed from the components of the <code class=\"literal\">oauth_issuer</code>, and this value must exactly match the issuer identifier that is declared in the discovery document itself, or the connection will fail. This is required to prevent a class of <a class=\"ulink\" href=\"https://mailarchive.ietf.org/arch/msg/oauth/JIVxFBGsJBVtm7ljwJhPUm3Fr-w/\">\"mix-up attacks\"</a> on OAuth clients.</p>\n<p>You may also explicitly set <code class=\"literal\">oauth_issuer</code> to the <code class=\"literal\">/.well-known/</code> URI used for OAuth discovery. In this case, if the server asks for a different URL, the connection will fail, but a <a class=\"link\" href=\"/docs/devel/libpq-oauth.html#LIBPQ-OAUTH-AUTHDATA-HOOKS\" title=\"32.19.1.\u00a0Authdata Hooks\">custom OAuth flow</a> may be able to speed up the standard handshake by using previously cached tokens. (In this case, it is recommended that <a class=\"xref\" href=\"/docs/devel/libpq-connect.html#LIBPQ-CONNECT-OAUTH-SCOPE\">oauth_scope</a> be set as well, since the client will not have a chance to ask the server for a correct scope setting, and the default scopes for a token may not be sufficient to connect.) <span class=\"application\">libpq</span> currently supports the following well-known endpoints:</p>\n<div class=\"itemizedlist\">\n<ul class=\"itemizedlist compact\">\n<li class=\"listitem\">\n<p><code class=\"literal\">/.well-known/openid-configuration</code></p>\n</li>\n<li class=\"listitem\">\n<p><code class=\"literal\">/.well-known/oauth-authorization-server</code></p>\n</li>\n</ul>\n</div>\n<div class=\"warning\">\n<h3 class=\"title\">Warning</h3>\n<p>Issuers are highly privileged during the OAuth connection handshake. As a rule of thumb, if you would not trust the operator of a URL to handle access to your servers, or to impersonate you directly, that URL should not be trusted as an <code class=\"literal\">oauth_issuer</code>.</p>\n</div>\n</dd></dl></div>", "manual_path": "libpq-connect.html#LIBPQ-CONNECT-OAUTH-ISSUER", "source_option": {"keyword": "oauth_issuer", "declaration": "\"oauth_issuer\", NULL, NULL, NULL, \"OAuth-Issuer\", \"\", 40, offsetof(struct pg_conn, oauth_issuer)", "environment": "", "source_notes": [], "compiled_default_expression": "NULL"}, "comparison_data": {"keyword": "oauth_issuer", "definition": "The HTTPS URL of a trusted issuer to contact if the server requests an OAuth token for the connection. This parameter is required for all OAuth connections; it should exactly match the issuer setting in the server's HBA configuration . As part of the standard authentication handshake, libpq will ask the server for a discovery document: a URL providing a set of OAuth configuration parameters. The server must provide a URL that is directly constructed from the components of the oauth_issuer , and this value must exactly match the issuer identifier that is declared in the discovery document itself, or the connection will fail. This is required to prevent a class of \"mix-up attacks\" on OAuth clients. You may also explicitly set oauth_issuer to the /.well-known/ URI used for OAuth discovery. In this case, if the server asks for a different URL, the connection will fail, but a custom OAuth flow may be able to speed up the standard handshake by using previously cached tokens. (In this case, it is recommended that oauth_scope be set as well, since the client will not have a chance to ask the server for a correct scope setting, and the default scopes for a token may not be sufficient to connect.) libpq currently supports the following well-known endpoints: /.well-known/openid-configuration /.well-known/oauth-authorization-server Warning Issuers are highly privileged during the OAuth connection handshake. As a rule of thumb, if you would not trust the operator of a URL to handle access to your servers, or to impersonate you directly, that URL should not be trusted as an oauth_issuer .", "documented": true, "environment": "", "default_evidence": ["You may also explicitly set oauth_issuer to the /.well-known/ URI used for OAuth discovery. In this case, if the server asks for a different URL, the connection will fail, but a custom OAuth flow may be able to speed up the standard handshake by using previously cached tokens. (In this case, it is recommended that oauth_scope be set as well, since the client will not have a chance to ask the server for a correct scope setting, and the default scopes for a token may not be sufficient to connect.) libpq currently supports the following well-known endpoints:"], "compiled_default_expression": "NULL"}, "comparison_hash": "9afc5e8603b6a862d897284099f310b696b3365ecc6dbb724802de062d37fa13", "default_evidence": ["You may also explicitly set oauth_issuer to the /.well-known/ URI used for OAuth discovery. In this case, if the server asks for a different URL, the connection will fail, but a custom OAuth flow may be able to speed up the standard handshake by using previously cached tokens. (In this case, it is recommended that oauth_scope be set as well, since the client will not have a chance to ask the server for a correct scope setting, and the default scopes for a token may not be sufficient to connect.) libpq currently supports the following well-known endpoints:"], "precedence_evidence": ["The following environment variables can be used to select default connection parameter values, which will be used by PQconnectdb , PQsetdbLogin and PQsetdb if no value is directly specified by the calling code. These are useful to avoid hard-coding database connection information into simple client applications, for example.", "Service names can be defined in either a per-user service file or a system-wide file. If the same service name exists in both the user and the system file, the user file takes precedence. By default, the per-user service file is named ~/.pg_service.conf . On Microsoft Windows, it is named %APPDATA%\\postgresql\\.pg_service.conf (where %APPDATA% refers to the Application Data subdirectory in the user's profile). A different file name can be specified using the servicefile key word in a libpq connection string or by setting the environment variable PGSERVICEFILE . The system-wide file is named pg_service.conf . By default it is sought in the etc directory of the PostgreSQL installation (use pg_config --sysconfdir to identify this directory precisely). Another directory, but not a different file name, can be specified by setting the environment variable PGSYSCONFDIR .", "Connection parameters obtained from a service file are combined with parameters obtained from other sources. A service file setting overrides the corresponding environment variable, and in turn can be overridden by a value given directly in the connection string. For example, using the above service file, a connection string service=mydb port=5434 will use host somehost , port 5434 , user admin , and other parameters as set by environment variables or built-in defaults."]}}}, "snapshot": {"facts": [{"label": "Client library", "value": "libpq 18.6"}, {"label": "Manual definition", "value": "Documented"}, {"label": "Source environment fallback", "value": "None declared in the option table"}, {"label": "Compiled fallback expression", "value": "NULL"}], "tables": [], "keyword": "oauth_issuer", "related": [{"url": "/docs/18/libpq-pgservice.html", "label": "Connection service file"}, {"url": "/docs/18/libpq-pgpass.html", "label": "Password file"}, {"url": "/docs/18/libpq-envars.html", "label": "All libpq environment variables"}], "release": {"ref": "https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2", "label": "18.6", "major": "18", "channel": "stable", "manifest": {"pdf": {"A4": {"url": "/files/documentation/pdf/18/postgresql-18-A4.pdf", "bytes": 15865106, "pages": 3154, "sha256": "19512c405da53f9f7fcf0abba359223aa65f021be025bf3411381918f92e3190", "built_at": "2026-09-26"}, "US": {"url": "/files/documentation/pdf/18/postgresql-18-US.pdf", "bytes": 15748059, "pages": 3328, "sha256": "facbe6c229e598b872d3d98bef53308f46e06746006fa4590de9a7de9dd46319", "built_at": "2026-09-26"}}, "tree": "18", "index": "index.html", "major": "18", "pages": 1148, "release": "18.6", "source_url": "https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2", "svg_assets": 3, "source_mode": "en SGML built with pinned official archive", "source_sha256": "555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f"}, "revision": "ee8d1a3612338fd9adf250730cb640fcc5233b5491337cc00a316a44e3a0b9f8", "evidence_kind": "English manual and source declarations", "source_sha256": "555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f"}, "sources": [{"url": "/docs/18/libpq-connect.html#LIBPQ-CONNECT-OAUTH-ISSUER", "file": "libpq-connect.html", "label": "18.6 English manual \u00b7 libpq-connect.html", "anchor": "LIBPQ-CONNECT-OAUTH-ISSUER", "sha256": "c26a7fc3dcda6066cfe540641ae2690faf3d3c03277f30b4dfc2328ab45c212f"}, {"url": "https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2", "file": "src/interfaces/libpq/fe-connect.c", "label": "18.6 libpq connection option declarations", "sha256": "44a6e386cbfd67ebe768d6ef5493098119c2e6b4796239d53e5ed7b122b206a5", "archive_sha256": "555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f"}, {"url": "/docs/18/libpq-envars.html", "file": "libpq-envars.html", "label": "18.6 English manual \u00b7 libpq-envars.html", "anchor": "", "sha256": "d64db73f3d48127bb984a5f775e77b7bcca2ba4bd218333cf24a45fcdd7c4363"}, {"url": "/docs/18/libpq-pgservice.html", "file": "libpq-pgservice.html", "label": "18.6 English manual \u00b7 libpq-pgservice.html", "anchor": "", "sha256": "6035a3f0ee1d0fd80db5bf58834390b884eecd23206659bdf6f07560deea5aa7"}], "sections": [{"title": "Default resolution and service-file precedence", "paragraphs": ["The following environment variables can be used to select default connection parameter values, which will be used by PQconnectdb , PQsetdbLogin and PQsetdb if no value is directly specified by the calling code. These are useful to avoid hard-coding database connection information into simple client applications, for example.", "Service names can be defined in either a per-user service file or a system-wide file. If the same service name exists in both the user and the system file, the user file takes precedence. By default, the per-user service file is named ~/.pg_service.conf . On Microsoft Windows, it is named %APPDATA%\\postgresql\\.pg_service.conf (where %APPDATA% refers to the Application Data subdirectory in the user's profile). A different file name can be specified by setting the environment variable PGSERVICEFILE . The system-wide file is named pg_service.conf . By default it is sought in the etc directory of the PostgreSQL installation (use pg_config --sysconfdir to identify this directory precisely). Another directory, but not a different file name, can be specified by setting the environment variable PGSYSCONFDIR .", "Connection parameters obtained from a service file are combined with parameters obtained from other sources. A service file setting overrides the corresponding environment variable, and in turn can be overridden by a value given directly in the connection string. For example, using the above service file, a connection string service=mydb port=5434 will use host somehost , port 5434 , user admin , and other parameters as set by environment variables or built-in defaults."]}, {"title": "Environment variable evidence", "paragraphs": []}], "signature": "oauth_issuer", "documented": true, "description": ["The HTTPS URL of a trusted issuer to contact if the server requests an OAuth token for the connection. This parameter is required for all OAuth connections; it should exactly match the issuer setting in the server's HBA configuration ."], "environment": [], "manual_html": "<div><dl class=\"variablelist\"><dt id=\"LIBPQ-CONNECT-OAUTH-ISSUER\"><span class=\"term\"><code class=\"literal\">oauth_issuer</code></span> </dt><dd>\n<p>The HTTPS URL of a trusted issuer to contact if the server requests an OAuth token for the connection. This parameter is required for all OAuth connections; it should exactly match the <code class=\"literal\">issuer</code> setting in <a class=\"link\" href=\"/docs/18/auth-oauth.html\" title=\"20.15.\u00a0OAuth Authorization/Authentication\">the server's HBA configuration</a>.</p>\n<p>As part of the standard authentication handshake, <span class=\"application\">libpq</span> will ask the server for a <span class=\"emphasis\"><em>discovery document:</em></span> a URL providing a set of OAuth configuration parameters. The server must provide a URL that is directly constructed from the components of the <code class=\"literal\">oauth_issuer</code>, and this value must exactly match the issuer identifier that is declared in the discovery document itself, or the connection will fail. This is required to prevent a class of <a class=\"ulink\" href=\"https://mailarchive.ietf.org/arch/msg/oauth/JIVxFBGsJBVtm7ljwJhPUm3Fr-w/\">\"mix-up attacks\"</a> on OAuth clients.</p>\n<p>You may also explicitly set <code class=\"literal\">oauth_issuer</code> to the <code class=\"literal\">/.well-known/</code> URI used for OAuth discovery. In this case, if the server asks for a different URL, the connection will fail, but a <a class=\"link\" href=\"/docs/18/libpq-oauth.html#LIBPQ-OAUTH-AUTHDATA-HOOKS\" title=\"32.20.1.\u00a0Authdata Hooks\">custom OAuth flow</a> may be able to speed up the standard handshake by using previously cached tokens. (In this case, it is recommended that <a class=\"xref\" href=\"/docs/18/libpq-connect.html#LIBPQ-CONNECT-OAUTH-SCOPE\">oauth_scope</a> be set as well, since the client will not have a chance to ask the server for a correct scope setting, and the default scopes for a token may not be sufficient to connect.) <span class=\"application\">libpq</span> currently supports the following well-known endpoints:</p>\n<div class=\"itemizedlist\">\n<ul class=\"itemizedlist compact\">\n<li class=\"listitem\">\n<p><code class=\"literal\">/.well-known/openid-configuration</code></p>\n</li>\n<li class=\"listitem\">\n<p><code class=\"literal\">/.well-known/oauth-authorization-server</code></p>\n</li>\n</ul>\n</div>\n<div class=\"warning\">\n<h3 class=\"title\">Warning</h3>\n<p>Issuers are highly privileged during the OAuth connection handshake. As a rule of thumb, if you would not trust the operator of a URL to handle access to your servers, or to impersonate you directly, that URL should not be trusted as an <code class=\"literal\">oauth_issuer</code>.</p>\n</div>\n</dd></dl></div>", "manual_path": "libpq-connect.html#LIBPQ-CONNECT-OAUTH-ISSUER", "source_option": {"keyword": "oauth_issuer", "declaration": "\"oauth_issuer\", NULL, NULL, NULL, \"OAuth-Issuer\", \"\", 40, offsetof(struct pg_conn, oauth_issuer)", "environment": "", "source_notes": [], "compiled_default_expression": "NULL"}, "comparison_data": {"keyword": "oauth_issuer", "definition": "The HTTPS URL of a trusted issuer to contact if the server requests an OAuth token for the connection. This parameter is required for all OAuth connections; it should exactly match the issuer setting in the server's HBA configuration . As part of the standard authentication handshake, libpq will ask the server for a discovery document: a URL providing a set of OAuth configuration parameters. The server must provide a URL that is directly constructed from the components of the oauth_issuer , and this value must exactly match the issuer identifier that is declared in the discovery document itself, or the connection will fail. This is required to prevent a class of \"mix-up attacks\" on OAuth clients. You may also explicitly set oauth_issuer to the /.well-known/ URI used for OAuth discovery. In this case, if the server asks for a different URL, the connection will fail, but a custom OAuth flow may be able to speed up the standard handshake by using previously cached tokens. (In this case, it is recommended that oauth_scope be set as well, since the client will not have a chance to ask the server for a correct scope setting, and the default scopes for a token may not be sufficient to connect.) libpq currently supports the following well-known endpoints: /.well-known/openid-configuration /.well-known/oauth-authorization-server Warning Issuers are highly privileged during the OAuth connection handshake. As a rule of thumb, if you would not trust the operator of a URL to handle access to your servers, or to impersonate you directly, that URL should not be trusted as an oauth_issuer .", "documented": true, "environment": "", "default_evidence": ["You may also explicitly set oauth_issuer to the /.well-known/ URI used for OAuth discovery. In this case, if the server asks for a different URL, the connection will fail, but a custom OAuth flow may be able to speed up the standard handshake by using previously cached tokens. (In this case, it is recommended that oauth_scope be set as well, since the client will not have a chance to ask the server for a correct scope setting, and the default scopes for a token may not be sufficient to connect.) libpq currently supports the following well-known endpoints:"], "compiled_default_expression": "NULL"}, "comparison_hash": "9afc5e8603b6a862d897284099f310b696b3365ecc6dbb724802de062d37fa13", "default_evidence": ["You may also explicitly set oauth_issuer to the /.well-known/ URI used for OAuth discovery. In this case, if the server asks for a different URL, the connection will fail, but a custom OAuth flow may be able to speed up the standard handshake by using previously cached tokens. (In this case, it is recommended that oauth_scope be set as well, since the client will not have a chance to ask the server for a correct scope setting, and the default scopes for a token may not be sufficient to connect.) libpq currently supports the following well-known endpoints:"], "precedence_evidence": ["The following environment variables can be used to select default connection parameter values, which will be used by PQconnectdb , PQsetdbLogin and PQsetdb if no value is directly specified by the calling code. These are useful to avoid hard-coding database connection information into simple client applications, for example.", "Service names can be defined in either a per-user service file or a system-wide file. If the same service name exists in both the user and the system file, the user file takes precedence. By default, the per-user service file is named ~/.pg_service.conf . On Microsoft Windows, it is named %APPDATA%\\postgresql\\.pg_service.conf (where %APPDATA% refers to the Application Data subdirectory in the user's profile). A different file name can be specified by setting the environment variable PGSERVICEFILE . The system-wide file is named pg_service.conf . By default it is sought in the etc directory of the PostgreSQL installation (use pg_config --sysconfdir to identify this directory precisely). Another directory, but not a different file name, can be specified by setting the environment variable PGSYSCONFDIR .", "Connection parameters obtained from a service file are combined with parameters obtained from other sources. A service file setting overrides the corresponding environment variable, and in turn can be overridden by a value given directly in the connection string. For example, using the above service file, a connection string service=mydb port=5434 will use host somehost , port 5434 , user admin , and other parameters as set by environment variables or built-in defaults."]}, "comparison": {"left": "17", "right": "18", "status": "added", "diff": "--- PostgreSQL 17\n+++ PostgreSQL 18\n@@ -1 +1,10 @@\n-Not recorded in this version\n+{\n+  \"compiled_default_expression\": \"NULL\",\n+  \"default_evidence\": [\n+    \"You may also explicitly set oauth_issuer to the /.well-known/ URI used for OAuth discovery. In this case, if the server asks for a different URL, the connection will fail, but a custom OAuth flow may be able to speed up the standard handshake by using previously cached tokens. (In this case, it is recommended that oauth_scope be set as well, since the client will not have a chance to ask the server for a correct scope setting, and the default scopes for a token may not be sufficient to connect.) libpq currently supports the following well-known endpoints:\"\n+  ],\n+  \"definition\": \"The HTTPS URL of a trusted issuer to contact if the server requests an OAuth token for the connection. This parameter is required for all OAuth connections; it should exactly match the issuer setting in the server's HBA configuration . As part of the standard authentication handshake, libpq will ask the server for a discovery document: a URL providing a set of OAuth configuration parameters. The server must provide a URL that is directly constructed from the components of the oauth_issuer , and this value must exactly match the issuer identifier that is declared in the discovery document itself, or the connection will fail. This is required to prevent a class of \\\"mix-up attacks\\\" on OAuth clients. You may also explicitly set oauth_issuer to the /.well-known/ URI used for OAuth discovery. In this case, if the server asks for a different URL, the connection will fail, but a custom OAuth flow may be able to speed up the standard handshake by using previously cached tokens. (In this case, it is recommended that oauth_scope be set as well, since the client will not have a chance to ask the server for a correct scope setting, and the default scopes for a token may not be sufficient to connect.) libpq currently supports the following well-known endpoints: /.well-known/openid-configuration /.well-known/oauth-authorization-server Warning Issuers are highly privileged during the OAuth connection handshake. As a rule of thumb, if you would not trust the operator of a URL to handle access to your servers, or to impersonate you directly, that URL should not be trusted as an oauth_issuer .\",\n+  \"documented\": true,\n+  \"environment\": \"\",\n+  \"keyword\": \"oauth_issuer\"\n+}"}}