Flow Condition-based OIDC ID Token ACR Value
Description
Configures the contents of the "
acr" (Authentication Context Class Reference) claim in the ID Token, if the flow authentication was used for the OpenID Connect handshake. Note that requesting ACR values is only supported using the "acr_values" claim, but not using the "claims" request parameter. May be used by
Properties
Mappings (
mappings) Description
Mappings from a flow condition to ACR values used to determine the OpenID Connect ID Token ACR value. The matching will be done in this order:
- If
acr_valueshave been requested, they are matched in the requested order against these mappings. The first acr value for which a flow condition matches is used. - If no
acr_valueshave been requested or none could be satisfied, this list is processed in order and the first acr value for which a flow condition matches is used. - If no acr value could be determined so far, the "Default ACR" value below is used (if any).
Attributes
Plugin-List
Mandatory
Assignable plugins
Default ACR (
defaultAcr) Description
Default ACR to issue. This only applies if no mapping matched.
Attributes
String
Optional
YAML Template (with default values)
type: OpenIdConnectAcrMappingClaim
id: OpenIdConnectAcrMappingClaim-xxxxxx
displayName:
comment:
properties:
defaultAcr:
mappings: