@@ -507,14 +507,17 @@ def __init__(self, auth_params_string: str):
507507
508508 .. code-block:: python
509509
510- auth = AuthenticationOauth2('{"issuer_url": "xxx", "private_key": "yyy"}')
510+ auth = AuthenticationOauth2('{"issuer_url": "xxx", "private_key": "yyy", "audience": "zzz" }')
511511
512512 The valid JSON fields are:
513513
514- * issuer_url (required)
514+ * tokenEndpointAuthMethod (optional, default="client_secret_post")
515+ The authentication method used by the OAuth 2.0 token endpoint. Supported values are
516+ ``client_secret_post`` and ``tls_client_auth``.
517+ * issuer_url (required for both authentication methods)
515518 The URL of the authentication provider which allows the Pulsar client to obtain an
516519 access token.
517- * private_key (required)
520+ * private_key (required for ``client_secret_post`` )
518521 The URL to the JSON credentials file. It supports the following pattern formats:
519522
520523 * ``/path/to/file``
@@ -527,10 +530,23 @@ def __init__(self, auth_params_string: str):
527530
528531 * ``client_id``
529532 * ``client_secret``
530- * audience
533+ * audience (required for ``client_secret_post``, optional for ``tls_client_auth``)
531534 The OAuth 2.0 "resource server" identifier for a Pulsar cluster.
532535 * scope
533536 The scope of an access request.
537+ * tls_cert_file (required for ``tls_client_auth``, optional for ``client_secret_post``)
538+ Path to the TLS client certificate file.
539+ * tls_key_file (required for ``tls_client_auth``, optional for ``client_secret_post``)
540+ Path to the TLS client private key file. ``tls_cert_file`` and ``tls_key_file`` must
541+ be specified together.
542+ * client_id (optional for ``tls_client_auth``)
543+ The OAuth 2.0 client identifier. If omitted, ``pulsar-client`` is used. For
544+ ``client_secret_post``, set this field in the JSON credentials file referenced by
545+ ``private_key``.
546+
547+ For ``client_secret_post``, ``issuer_url``, ``private_key``, and ``audience`` are required.
548+ For ``tls_client_auth``, ``private_key`` is not required and ``tls_cert_file`` and
549+ ``tls_key_file`` are required.
534550
535551 Parameters
536552 ----------
0 commit comments