Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.
Comment: Published by Scroll Versions from space PDOIDC and version Paris_OIDC

...

ClaimOriginScopeExampleIDPEligibilityDescriptionComment
Minimum ID Token part
typKeycloackopenidIDAnyAnyToken type

Always ID for ID Tokens

acrStandardopenid
4AnyAnyAuthentication Context Class ReferenceLevel of Assurance (LoA) for IDP option being used
amrStandardopenid
BIDAnyAnyAuthentication Method Reference

Name of IDP option being used to authenticate the end-user.

If the end-user is subject to authentication step-up, note that this value may differ from any amr value specified in the login_hint parameter of the Authorize end-point.

aud
Standardopenid
oidc_testclientAnyAnyAudienceAlways client_id
auth_timeStandardopenid
1510497762AnyAnyAuthentication timeEpoc time
azpStandardopenid
oidc_testclientAnyAnyAuthorized partyEquals client_id
bankid_altsubCustomopenid

9578-5999-4-1765512

BankID and xIDAnyAlternate BankID Subject Identifier 

Personal Identifier (PID) / Serial Number) from associated BankID certificate.

expStandardopenid
1510498063AnyAnyExpiration timeEpoc time. Corresponds to a forward session window after iat
iatStandardopenid
1510497763AnyAnyIssuing time

Epoc time

Equal to auth_time for new sessions. Is otherwise set at each session refresh.

issStandardopenid
<oidc-baseurl>AnyAnyIssuer Identifier for the Issuer 
jtiStandardopenid
7f22fd6a-3d46-4d5a-ae56-6de3c53e1873AnyAnyToken identifier 
nbfStandardopenid
0AnyAnyNot before timeEpoc time
nonceStandardopenid
<random value>AnyAnyNonce 
session_stateKeycloackopenid
abf823c2-9810-4133-9369-7bff1223d6c1AnyAnyGUID related to session handling 
subStandardopenid

e8c523ff-52a2-42e2-a7a5-f1d0fbb76204

AnyAnySubject IdentifierGUID from Keycloackthat uniquely identifies the end user across the different IDPs
updated_atStandardopenid
1468582440AnyAnyUpdate timeEpoc time of issuing / create / enrollment of ID in question.
at_hash
Standardopenid
<hash value>AnyAnyAccess Token hash valueIncluded for hybrid- and implicit flows
c_hash
Standardopenid
<hash value>AnyAnyCode hash valueIncluded for hybrid flow
browserEnrolledAtCustomopenid1515437710549xID onlyAnyTime at which the current browser was enrolled for the xID Service

Epoc time

tidCustomopenid2e1eebb7-d5d7-4c55-9410-6ab178070a1cCurrently only BankID (IDP)AnyTransaction ID (reference) for the completed authentication sessionCurrently used as an input parameter for the securityData endpoint of the Fraud Data (VAS) service
Regular ID Token part
birthdateStandardprofile1966-12-18BankID and xIDAnyBirthdateFrom associated BankID certificate
family_nameStandardprofile
NilsenBankID and xIDAnySurname (last name)From associated BankID certificate
given_nameStandardprofile
Frode BeckmannBankID and xIDAnyGiven name (first name)From associated BankID certificate
nameStandardprofile
Nilsen, Frode BeckmannBankID and xIDAnyFull nameFrom associated BankID certificate
Enhanced ID Token part
nnin_altsubCustomnnin_altsub181266*****BankID and xID

Available for OIDC clients that uses NNIN as userID for its already existing users.

For access to NNIN for enrollment of new users, see TINFO or AML (VAS).

Norwegian National Identity Number (NNIN) as alternate Subject Identifier

Only availble with authorization code flow.