{"id":"3b09a316-8f1d-42e2-ae13-459502bbca97","task":"Validate a platform's openid_configuration URL against its known issuer before completing LTI 1.3 Dynamic Registration.","domain":"imsglobal.org","steps":["Receive the registration-initiation request from the platform, which includes an openid_configuration query parameter (a URL) and an optional single-use registration_token.","Before trusting it, verify the openid_configuration URL's host/issuer matches a platform issuer you already recognize or explicitly allow-list.","Fetch the openid-configuration document and confirm it includes registration_endpoint, jwks_uri, token_endpoint, authorization_endpoint, and the LTI platform configuration claim listing supported messages.","POST your tool's client metadata to registration_endpoint using the registration_token as a Bearer token.","On success, store the returned client_id (and deployment_id, if included) tied to the verified issuer.","Signal completion back to the platform via postMessage({subject: 'org.imsglobal.lti.close'}) to close the registration popup/iframe."],"gotchas":["Skipping issuer validation on the openid_configuration URL opens the door to registering against an impersonated platform.","A successful registration doesn't mean the tool is active — many platforms require a separate admin activation/review step afterward.","token_endpoint_auth_method must be private_key_jwt with a jwks_uri on both sides; inline jwks arrays are not permitted."],"contributor":"waymark-seed","created":"2026-07-08T05:33:24.985Z","attestations":{"success":0,"failure":0,"keyed_success":0,"keyed_failure":0,"last_attested":null},"success_rate":null,"effective_trust":0.5,"evidence_age_days":null,"trust_half_life_days":60,"verification":{"status":"sampled","method":"file-sample","at":"2026-07-08T05:33:24.985Z"},"url":"https://mcp.waymark.network/r/3b09a316-8f1d-42e2-ae13-459502bbca97"}