← Back to plugin index

OIDC UserInfo Endpoint

Description

OpenID Connect UserInfo Endpoint according to the OpenID Connect Specification.

The endpoint is available under /<loginapp-uri>/rest/oauth2/authorization-servers/<as-identifier>/userinfo

The subject claim "sub" will contain the username and always be present in UserInfo Responses. It is not possible to overwrite the subject claim.

Type name
OpenIDConnectUserInfoEndpoint
Class
com.airlock.iam.login.app.misc.configuration.oauth.as.oauth2.OpenIDConnectUserInfoEndpointConfig
May be used by
License-Tags
OAuthServer
Properties
Standard Claims (standardClaims)
Description
Standard claims according to the OpenID Connect Standard Claims to add to the UserInfo Response. Note: Claims must be unique, therefore adding the same standard claim multiple times will result in a runtime error when issuing the response.
Attributes
Plugin-List
Optional
Assignable plugins
Custom Claims (customClaims)
Description

Custom claims to add to the UserInfo Response.

Multiple claims with the same name can be configured if each has a claim condition which ensures that only one of them will be included at runtime. Configuring a custom claim that results in the same claim name as a standard claim will result in a runtime error.

Attributes
Plugin-List
Optional
Assignable plugins
Distributed Claims (distributedClaims)
Description

Distributed Claims to add to the UserInfo Response.

These claims allow providing a URL to a 3rd party claims provider in the response where additional claims may be obtained.

Attributes
Plugin-List
Optional
Assignable plugins
YAML Template (with default values)

type: OpenIDConnectUserInfoEndpoint
id: OpenIDConnectUserInfoEndpoint-xxxxxx
displayName: 
comment: 
properties:
  customClaims:
  distributedClaims:
  standardClaims: