Switch from OIDC UserInfo to OAuth 2.0 Token Introspection #1

Merged
erth9960 merged 2 commits from token-introspection into main 2025-03-24 13:59:08 +01:00
Owner

The UserInfo endpoint is for fetching the users profile (name, email, phone number, picture, and so on). Token introspection is for inspecting the access token and determining the authorities the user has (subject (principal), entitlements, and scopes granted).

The [UserInfo endpoint](https://openid.net/specs/openid-connect-core-1_0.html#UserInfo) is for fetching the users profile (name, email, phone number, picture, and so on). [Token introspection](https://datatracker.ietf.org/doc/html/rfc7662) is for inspecting the access token and determining the authorities the user has (subject (principal), entitlements, and scopes granted).
ansv7779 added 1 commit 2025-03-24 11:11:06 +01:00
The UserInfo endpoint is for fetching the users profile (name, email, phone number, picture, and so on). Token introspection is for inspecting the access token and determining the authorities the user has (subject (principal), entitlements, and scopes granted).
erth9960 added 1 commit 2025-03-24 13:21:30 +01:00
erth9960 merged commit dcacd0cc1d into main 2025-03-24 13:59:08 +01:00
erth9960 deleted branch token-introspection 2025-03-24 13:59:08 +01:00
Sign in to join this conversation.
No Reviewers
No Label
No Milestone
No project
2 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: DMC/wg-selfserve#1
No description provided.