← Back to plugin index

OIDC ID Token Claims

Description

Configuration plugin for the OpenID Connect ID Token Claims.

The 'iss' (issuer) claim is always filled from the issuer configured in the top level configuration.

Type name
OpenIDConnectClaimsConfiguration
Class
com.airlock.iam.oauth2.application.configuration.openid.OpenIDConnectClaimsConfiguration
May be used by
License-Tags
OAuthServer
Properties
Custom Claims (customClaims)
Description

List of custom claims added to the OpenID Connect ID Token as additional claims.

Multiple claims with the same name can be configured if each has a claim condition which ensures that only one of them will be included at runtime.

The following claims are automatically set by Airlock IAM and therefore will be ignored if defined as custom claim.
  • auth_time
  • nonce
  • acr

Note: When "Persist Claims" is disabled, custom claims are collected when the ID Token is requested by an OpenID Connect client and not when the ID Token is issued. Therefore the values of the custom claims may change between issue and request time.

Attributes
Plugin-List
Optional
Assignable plugins
Distributed Claims (distributedClaims)
Description

Distributed Claims to add to the ID Token.

These claims allow providing a URL to a 3rd party claims provider in the response where additional claims may be obtained.

Attributes
Plugin-List
Optional
Assignable plugins
YAML Template (with default values)

type: OpenIDConnectClaimsConfiguration
id: OpenIDConnectClaimsConfiguration-xxxxxx
displayName: 
comment: 
properties:
  customClaims:
  distributedClaims: