0Pricing
OAuth2 & OpenID Connect Deep Dive · Lección

Solicitud de claims y claims agregados

Aprenda cómo OpenID Connect permite a los clientes solicitar claims específicos con el parámetro claims y cómo los claims distribuidos y agregados proporcionan aserciones de fuentes externas.

Solicitud de claims y claims agregados es una lección gratuita de OAuth2 & OpenID Connect Deep Dive en CoddyKit. Esta es la lección 4 de 4. Puedes leer la lección completa abajo gratuitamente — luego la practicas en el navegador con un editor de código integrado y un tutor de IA 24/7. Forma parte de la ruta de aprendizaje de OAuth2 & OpenID Connect Deep Dive, y tu progreso se sincroniza en la web y la app de CoddyKit. El curso de OAuth2 & OpenID Connect Deep Dive incluye 4 lecciones en total.

Partes de esta lección aún no han sido traducidas y se muestran en inglés.

Requesting Specific Claims

Beyond scopes like profile or email, OIDC offers a finer-grained claims request parameter. It lets a client ask for individual claims and target where they appear: in the ID token or from UserInfo.

The claims Parameter Shape

The claims parameter is a JSON object with two top-level members: id_token and userinfo. Each maps claim names to a value describing how they are requested.

{
  "id_token": { "auth_time": { "essential": true } },
  "userinfo": { "email": null, "email_verified": null }
}

essential, value, values

Each requested claim can specify:

  • essential: true — the client really needs it.
  • value — request that the claim equals a specific value.
  • values — request one of several allowed values.
{ "acr": { "essential": true,
            "values": ["urn:mace:incommon:iap:silver"] } }

Sending It in the Request

The JSON is URL-encoded and sent as the claims query parameter on the authorization request.

GET /authorize?response_type=code
  &client_id=app123&scope=openid
  &claims=%7B%22id_token%22%3A%7B%22auth_time%22%3A%7B%22essential%22%3Atrue%7D%7D%7D

Why Not Just Scopes?

Scopes bundle many claims at once. The claims parameter is for when you need precision — a single specific claim, an essential requirement, or a constraint on its value. It complements scopes rather than replacing them.

Aggregated Claims

Sometimes claims come from a third party the OP trusts. Aggregated claims are bundled by the OP as a signed JWT from the external claims provider and returned inline, so the client gets verifiable assertions without extra calls.

Aggregated Claims Format

The OP references them via _claim_names (which claim came from which source) and _claim_sources (the JWT holding them).

{
  "_claim_names": { "address": "src1" },
  "_claim_sources": {
    "src1": { "JWT": "eyJhbGciOi..." }
  }
}

Distributed Claims

Distributed claims are not embedded; instead the OP gives an endpoint and access token so the client can fetch them directly from the external source when needed.

{
  "_claim_names": { "payment_info": "src2" },
  "_claim_sources": {
    "src2": {
      "endpoint": "https://bank.example.com/claims",
      "access_token": "ksj3n283dke"
    }
  }
}

Aggregated vs Distributed

The trade-off:

  • Aggregated — claims travel inline, fewer round-trips, larger token.
  • Distributed — claims fetched on demand, smaller token, extra request and live availability of the source.

Processing External Claims

For aggregated claims, verify the embedded JWT's signature against the claims provider's keys. For distributed claims, call the endpoint with the supplied access token and validate the returned JWT before trusting any values.

When to Use These

External claim mechanisms shine in federations: an identity provider asserts who you are, while a bank or government source asserts verified attributes. They keep sensitive data at its authoritative source.

Quick Check

Test your understanding of claim requests.

Recap

The claims parameter enables fine-grained, essential, or value-constrained claim requests targeting the ID token or UserInfo.

  • essential, value, and values refine each request.
  • Aggregated claims are embedded inline as signed JWTs.
  • Distributed claims are fetched from an external endpoint.
  • Always verify external claim signatures before trusting them.

Preguntas frecuentes

¿La lección «Solicitud de claims y claims agregados» es gratis?

Sí — el texto completo de «Solicitud de claims y claims agregados» es gratis para leer aquí en la web. Para practicarla de forma interactiva (editor de código integrado y tutor de IA 24/7) y desbloquear el resto del curso de OAuth2 & OpenID Connect Deep Dive, actualiza a CoddyKit PRO. El curso de OAuth2 & OpenID Connect Deep Dive incluye 4 lecciones en total.

¿Qué aprenderé en «Solicitud de claims y claims agregados»?

Aprenda cómo OpenID Connect permite a los clientes solicitar claims específicos con el parámetro claims y cómo los claims distribuidos y agregados proporcionan aserciones de fuentes externas. Practicas OAuth2 & OpenID Connect Deep Dive con código real que ejecutas directamente en el navegador, y un tutor de IA 24/7 responde tus preguntas mientras trabajas en la lección.

¿Necesito experiencia previa para empezar OAuth2 & OpenID Connect Deep Dive?

No se requiere experiencia previa. OAuth2 & OpenID Connect Deep Dive en CoddyKit está estructurado para principiantes hasta estudiantes avanzados, así que puedes empezar aquí o desde el inicio y avanzar a tu ritmo. Esta es la lección 4 de 4.

¿Cuánto tiempo toma la lección «Solicitud de claims y claims agregados»?

La mayoría de las lecciones de CoddyKit toman alrededor de 5–10 minutos. Cada una es compacta e interactiva, así que avanzas constantemente y retomas exactamente por donde dejaste en la web y la app.

¿Puedo escribir y ejecutar código en esta lección de OAuth2 & OpenID Connect Deep Dive?

Sí. Cada lección de OAuth2 & OpenID Connect Deep Dive incluye un editor de código integrado, así que escribes y ejecutas código real directamente en tu navegador y obtienes retroalimentación instantánea de IA — sin configuración local necesaria.

Todas las lecciones de este curso

  1. Registro dinámico de clientes
  2. Endpoint de descubrimiento de OIDC
  3. Gestión de sesiones
  4. Solicitud de claims y claims agregados
← Volver a OAuth2 & OpenID Connect Deep Dive