← Back to plugin index

OIDC ID Token HMAC

Description
ID tokens will be signed using a Keyed-Hash Message Authentication Code (HMAC) using the client secret as key.
Notice that the client secret must have a minimum length depending on the selected algorithm (see property description).
Type name
OpenIDConnectIDTokenMACSignatureSigner
Class
com.airlock.iam.oauth2.application.configuration.openid.signature.OpenIDConnectIDTokenMACSignatureSigner
May be used by
License-Tags
OAuthServer
Properties
Algorithm (algorithm)
Description

MAC based signature algorithm to use.

Important: The ID Token is signed using the client secret. Therefore, the client must have registered such a secret and it must be long enough for the selected algorithm:

  • HS256: 32 characters
  • HS384: 48 characters
  • HS512: 64 characters
Attributes
Enum
Optional
Default value
HS256
YAML Template (with default values)

type: OpenIDConnectIDTokenMACSignatureSigner
id: OpenIDConnectIDTokenMACSignatureSigner-xxxxxx
displayName: 
comment: 
properties:
  algorithm: HS256