To answer your questions:
1) Your WebApi 2.2 project, no doubt, uses OWIN / Katana from ASP.NET 4.x, which means that you must use IdentityServer3.AccessTokenValidation . IdentityServer4.AccessTokenValidation is compatible with the new ASP.NET MVC Core pipeline.
2) You can gain your authority by going to the identity provider discovery document in {IdentityUrl}/.well-known/openid-configuration . This body should be the same as the value of the "issuer" in the discovery document. You can also gain authorization by looking at the JWT issued by your identity provider by looking at the iss issuance.
source share