Configuration

PIC-X exposes discovery at two levels: a server control-plane document and a per-realm PIC-X discovery document.
The server is not an issuer. A realm is an isolated trust domain and issuer boundary. Realm discovery publishes issuer-scoped endpoints, keys, token-exchange metadata, and PIC authority and continuity capabilities.
/.well-known/server-configuration
|
+--> realm: acme
|
v
/realms/acme/.well-known/pic-x-configuration
Discovery Model
The server-level document describes the PIC-X instance. The realm-level document describes the issuer clients use for PIC exchange and verification.

PIC-X receives an OAuth access token at the selected realm token endpoint, validates it, and derives the initial PIC Context of Authority, or PCA. A PCA is the logical Context of Authority. Its signed representation is a PIC PCA COSE. PIC-X then returns a realm-signed PIC Token JWT carrying a settled PIC Continuity COSE in pic.root.