The following is an obvious typo/bug in 1.0 and imo needs an errata @jogu @brentzundel @dpostnikov @Sakurann :
the aud claim MUST be equal to the iss (issuer) claim value, when Dynamic Discovery is performed.
This should be something like:
the aud claim MUST be equal to the issuer claim value of the metadata, when Dynamic Discovery is performed.