**Problem description** To secure the /authorize endpoint from being abused **Possible evolution** Proposal to follow Telefonica's proposal to use [RFC 9101](https://www.rfc-editor.org/rfc/rfc9101.html#name-request-object-2) Signed Request Object **Alternative solution** N.A **Additional context** #71