We are trying to integrate with another department, each of us have an instance of IdentityServer.
They want to consume our APIs via access_tokens generated from their instance of IdentityServer.
(Our IdentityServer & Our API):
[IdentityServer-A] <--> [API-A]
(Their IdentityServer & Their API):
[IdentityServer-B] --(generate access_tokens)--> [Website-B] --> [API-A]
When I run above scenario
IdentityServer-A logs this error
IdentityServer4.Validation.TokenValidator Invalid reference token.
I can understand this error because this is within IdentityServer-B is an invalid reference token because it is generated from IdentityServer-B.
But the question is how would I trust reference tokens generated from IdentityServer-A in IdentityServer-B?