skip to content

OpenID Connect

The identity layer over OAuth2: ID tokens, standard claim sets, UserInfo, discovery and logout. Interviewers ask it because 'OAuth2 is not authentication' is a line many candidates only half-know.

part ofFederated identityoverview, primer and where to startread it →
on this pageshow

explore

questions

page 2 of 2

In an OpenID Connect claim set, what do _claim_names and _claim_sources indicate about where a claim came from?

level: seniorimportance: nice to knowfreq 18%

basics

~20 s

_claim_names maps a claim to a key in _claim_sources, which says where it came from: an aggregated claim arrives as a signed JWT inside the response, a distributed claim only as an endpoint to fetch it from.

open as a page

In OpenID Connect, how can three clients run by one organisation receive the same pairwise sub for one user?

level: seniorimportance: nice to knowfreq 30%

basics

~20 s

Register all three clients with the same sector_identifier_uri. A pairwise value is derived per sector rather than per client, and the Sector Identifier is that URI's host component, so the three resolve to one sector and one shared sub.

open as a page

showing 31–32 of 32