| Friendly Name | A display name for the client. |
| Issuer URL | The IdP issuer URL. Verification keys resolve via OIDC Discovery. Must be reachable without authentication by Distributed Issuer instances. |
| Custom JWKS URI | Optional. Overrides the OIDC Discovery endpoint for key resolution. |
| Subjects | The sub values for token verification. A token is accepted only if its subject exactly matches an entry. For Kubernetes service accounts, use system:serviceaccount:<namespace>:<service-account-name>. |
| Allowed Policies | The issuance policies this client can request. |