OIDC ID Token Claims
Configuration plugin for the OpenID Connect ID Token Claims.
The 'iss' (issuer) claim is always filled from the issuer configured in the top level configuration.
customClaims) List of custom claims added to the OpenID Connect ID Token as additional claims.
Multiple claims with the same name can be configured if each has a claim condition which ensures that only one of them will be included at runtime.
The following claims are automatically set by Airlock IAM and therefore will be ignored if defined as custom claim.- auth_time
- nonce
- acr
Note: When "Persist Claims" is disabled, custom claims are collected when the ID Token is requested by an OpenID Connect client and not when the ID Token is issued. Therefore the values of the custom claims may change between issue and request time.
distributedClaims) Distributed Claims to add to the ID Token.
These claims allow providing a URL to a 3rd party claims provider in the response where additional claims may be obtained.
type: OpenIDConnectClaimsConfiguration
id: OpenIDConnectClaimsConfiguration-xxxxxx
displayName:
comment:
properties:
customClaims:
distributedClaims: