ID Tokenの構造と署名
ID Token(JWT)のヘッダー、ペイロード、署名を分解し、署名方法と含まれる情報を理解します。
「ID Tokenの構造と署名」はCoddyKit上の無料OAuth2 & OpenID Connect Deep Diveレッスンです。 これはレッスン1/4です。 下記で完全なレッスンを無料で読むことができます。その後、ブラウザ内の組み込みコードエディタと24時間対応のAIチューターでハンズオン演習できます。 これはOAuth2 & OpenID Connect Deep Dive学習パスの一部であり、ウェブとCoddyKitアプリ全体で進捗が同期されます。 OAuth2 & OpenID Connect Deep Diveコースには全4レッスンが含まれています。
このレッスンの一部はまだ翻訳されておらず、英語で表示されています。
Meet the ID Token
In OpenID Connect (OIDC), the ID Token is a crucial piece of information. It's a security token that contains claims about the authentication of an end-user by an Authorization Server.
Think of it as a digital ID card for the user, issued after they successfully log in.
ID Tokens Are JWTs
ID Tokens are always formatted as JSON Web Tokens (JWTs). A JWT is a compact, URL-safe means of representing claims to be transferred between two parties.
Every JWT has three main parts, separated by dots:
- Header
- Payload
- Signature
The Header: What Algorithm?
The first part of an ID Token is the Header. It's a JSON object that describes the token itself, like what type of token it is and the algorithm used to sign it.
alg: The cryptographic algorithm used for signing (e.g., RS256, HS256).typ: The type of token, which is usually"JWT".
Header in Action
When you decode the base64url-encoded header, you'll see a JSON object like this. This tells you how the token was secured.
{
"alg": "RS256",
"typ": "JWT",
"kid": "someKeyId"
}The kid (Key ID) helps find the correct public key for verification.
Decoding Header Example
The header is base64url encoded. Here's how you might decode a JWT header string in Java. This helps reveal its content.
import java.util.Base64;
import java.nio.charset.StandardCharsets;
public class JwtDecoder {
public static void main(String[] args) {
String encodedHeader = "eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6InNvbWVLZXlJZCJ9";
byte[] decodedBytes = Base64.getUrlDecoder().decode(encodedHeader);
String decodedString = new String(decodedBytes, StandardCharsets.UTF_8);
System.out.println("Decoded Header:");
System.out.println(decodedString);
}
}The Payload: Claims About You
The second part is the Payload. This is where the actual "claims" about the user and the authentication event are stored. Claims are statements about an entity (typically the user).
Standard claims you'll often see include:
iss: Issuer (who issued the token).sub: Subject (unique identifier for the user).aud: Audience (who the token is for).exp: Expiration Time (when the token expires).iat: Issued At Time (when the token was issued).
Payload in Action
Similar to the header, the payload is also a base64url-encoded JSON object. It contains the identity information you need.
{
"iss": "https://example.com/auth",
"sub": "user123",
"aud": "myAppClientId",
"exp": 1678886400,
"iat": 1678882800,
"name": "Alice Wonderland"
}exp and iat are Unix timestamps.
The Signature: Ensuring Trust
The third and final part is the Signature. This is critical for security! It's used to verify that the token hasn't been tampered with and that it comes from a legitimate issuer.
The signature is created by taking the encoded header, the encoded payload, and a secret key or private key, and running them through the cryptographic algorithm specified in the header.
Verifying the Signature
When your application receives an ID Token, it uses the public key (provided by the Issuer) to verify the signature. It re-computes the signature using the header, payload, and the public key.
If the re-computed signature matches the token's signature, you can trust that:
- The token hasn't been altered.
- It was issued by the expected Authorization Server.
Quick Check on JWT
You've learned that ID Tokens are structured as JWTs, with three distinct parts. Each part plays a vital role in conveying and securing user identity information.
Recap: ID Token Anatomy
Great job! You now understand the fundamental structure of an ID Token.
- Header: Describes the token and signing algorithm.
- Payload: Contains identity claims about the user.
- Signature: Ensures the token's integrity and authenticity.
Each part is base64url encoded and separated by dots, forming a secure and verifiable digital identity for the user.
AI チューターと学ぶ OAuth2 & OpenID Connect Deep Dive — 無料
ブラウザでリアルコードを書いて実行し、24/7 の AI チューターから瞬時にサポートを受け、ウェブまたはアプリで続きから学習できます。
- コース
- 12
- レッスン
- 48
よくある質問
「ID Tokenの構造と署名」レッスンは無料ですか?
はい。「ID Tokenの構造と署名」の完全なテキストはこのウェブで無料で読めます。インタラクティブに演習し(組み込みコードエディタと24時間対応のAIチューター)、OAuth2 & OpenID Connect Deep Diveコースの残りをアンロックするには、CoddyKit PROにアップグレードしてください。 OAuth2 & OpenID Connect Deep Diveコースには全4レッスンが含まれています。
「ID Tokenの構造と署名」で何を学びますか?
ID Token(JWT)のヘッダー、ペイロード、署名を分解し、署名方法と含まれる情報を理解します。 ブラウザで直接実行するハンズオンコードでOAuth2 & OpenID Connect Deep Diveを演習し、24時間対応のAIチューターがレッスンを進める中での質問に答えます。
OAuth2 & OpenID Connect Deep Diveを始めるのに経験は必要ですか?
事前経験は必要ありません。CoddyKitのOAuth2 & OpenID Connect Deep Diveは初級者から上級者向けに構成されているため、ここから始めるか最初から始めて、自分のペースで進むことができます。 これはレッスン1/4です。
「ID Tokenの構造と署名」レッスンにはどのくらい時間がかかりますか?
ほとんどのCoddyKitレッスンは約5~10分かかります。各レッスンはコンパクトでインタラクティブなので、着実に進歩し、ウェブとアプリ全体で正確に前回の場所から再開できます。
このOAuth2 & OpenID Connect Deep Diveレッスンでコードを書いて実行できますか?
はい。すべてのOAuth2 & OpenID Connect Deep Diveレッスンに組み込みコードエディタが含まれているため、ブラウザでリアルコードを書いて実行し、即座のAIフィードバックを取得できます。ローカル設定は不要です。
このコースのすべてのレッスン
- ID Tokenの構造と署名
- JWSとJWK Set
- トークンの失効とイントロスペクション
- 標準IDトークンクレームの検証