OAuth2 & OpenID Connect Deep Dive · レッスン

ID TokenとClaims

ユーザーのアイデンティティに関するクレームを保持するJSON Web Token(JWT)であるID Tokenの構造と内容を確認します。

レッスン 2/411 ステップ

「ID TokenとClaims」はCoddyKit上の無料OAuth2 & OpenID Connect Deep Diveレッスンです。 これはレッスン2/4です。 下記で完全なレッスンを無料で読むことができます。その後、ブラウザ内の組み込みコードエディタと24時間対応のAIチューターでハンズオン演習できます。 これはOAuth2 & OpenID Connect Deep Dive学習パスの一部であり、ウェブとCoddyKitアプリ全体で進捗が同期されます。 OAuth2 & OpenID Connect Deep Diveコースには全4レッスンが含まれています。

このレッスンの一部はまだ翻訳されておらず、英語で表示されています。

The Identity Token Revealed

The ID Token is a core component of OpenID Connect (OIDC). Think of it as a digital ID card for the user.

Its main purpose is to provide your application with verified identity information about the end-user who just logged in. It tells you who the user is.

Crucially, an ID Token is different from an Access Token. While an Access Token is for authorization (what you can do), an ID Token is for authentication (who you are).

ID Token's Secret: It's a JWT!

Every ID Token is a JSON Web Token (JWT). JWTs are a compact, URL-safe means of representing claims to be transferred between two parties.

Being a JWT means ID Tokens have a specific, standardized structure that allows for secure and verifiable information exchange.

This standardized format makes it easy for different systems to understand and process identity information.

Breaking Down a JWT

A JWT consists of three parts, separated by dots (.):

  • Header: Describes the token's type and the signing algorithm.
  • Payload: Contains the actual "claims" (identity information).
  • Signature: Used to verify the token hasn't been tampered with.

Both the Header and Payload are Base64Url-encoded JSON objects. The Signature is created using the encoded Header, Payload, and a secret key.

The Payload: Where Claims Live

The most important part of the ID Token for identity is its Payload. This is a JSON object containing various statements about the user and the authentication event.

These statements are called claims. Each claim is a key-value pair, like "name": "Jane Doe". They tell your application specific details about the user.

Claims are standardized by OIDC, but can also include custom information depending on the OpenID Provider (OP).

Required Claims: Issuer, Subject, Audience

Certain claims are essential for an ID Token to be valid and useful:

  • iss (Issuer): Identifies the entity that issued the token. This is typically the URL of the OpenID Provider.
  • sub (Subject): A unique identifier for the end-user. It's usually a string that's unique to the user within the issuer's system.
  • aud (Audience): Identifies the recipient(s) the JWT is intended for. This must be your application's client_id.

Time-Based Identity: Expiry & Issued At

ID Tokens also include important time-related claims:

  • exp (Expiration Time): The time after which the ID Token MUST NOT be accepted. It's a Unix timestamp.
  • iat (Issued At Time): The time at which the ID Token was issued. Also a Unix timestamp.
  • auth_time (Authentication Time): The time when the end-user last authenticated. Useful for session management policies.

Always check exp to ensure the token is still valid!

Nonce: A One-Time Security Check

The nonce claim is a unique, one-time value generated by your client application and sent to the Authorization Server.

When the ID Token is returned, it will include the same nonce. Your application then verifies that the nonce in the token matches the one it sent.

This helps mitigate replay attacks, ensuring that the ID Token wasn't captured and reused by a malicious party.

Enriching User Profiles

Beyond the core claims, ID Tokens often carry additional user information, known as "User Profile Claims". These are usually requested via scopes.

Common examples include:

  • name: The user's full name.
  • given_name: The user's first name.
  • family_name: The user's last name.
  • email: The user's email address.
  • picture: A URL to the user's profile picture.

These claims provide a rich set of data for your application.

Decoding an ID Token's Claims

When you receive and decode an ID Token, its payload might look something like this (simplified JSON):

{
  "iss": "https://accounts.coddykit.com",
  "sub": "user_id_xyz_789",
  "aud": "my_mobile_app_123",
  "exp": 1678886400,
  "iat": 1678882800,
  "auth_time": 1678882700,
  "nonce": "a1b2c3d4e5",
  "name": "Coddy User",
  "email": "coddy.user@example.com"
}

Each key-value pair is a specific claim providing identity details.

Quick Check on Claims

You've learned about the different claims within an ID Token.

Which of the following claims is primarily used to identify the recipient (your client application) for whom the ID Token is intended?

ID Token & Claims Recap

Great job! You've successfully explored the core of OpenID Connect: the ID Token and its claims.

  • ID Tokens are JWTs carrying identity data.
  • They contain a Header, Payload (claims), and Signature.
  • Key claims like iss, sub, aud, exp, iat, and nonce are crucial.
  • User Profile Claims like name and email enrich the identity.

Next, we'll dive into the different OIDC flows that use these tokens!

無料で開始

AI チューターと学ぶ OAuth2 & OpenID Connect Deep Dive — 無料

ブラウザでリアルコードを書いて実行し、24/7 の AI チューターから瞬時にサポートを受け、ウェブまたはアプリで続きから学習できます。

コース
12
レッスン
48

よくある質問

「ID TokenとClaims」レッスンは無料ですか?

はい。「ID TokenとClaims」の完全なテキストはこのウェブで無料で読めます。インタラクティブに演習し(組み込みコードエディタと24時間対応のAIチューター)、OAuth2 & OpenID Connect Deep Diveコースの残りをアンロックするには、CoddyKit PROにアップグレードしてください。 OAuth2 & OpenID Connect Deep Diveコースには全4レッスンが含まれています。

「ID TokenとClaims」で何を学びますか?

ユーザーのアイデンティティに関するクレームを保持するJSON Web Token(JWT)であるID Tokenの構造と内容を確認します。 ブラウザで直接実行するハンズオンコードでOAuth2 & OpenID Connect Deep Diveを演習し、24時間対応のAIチューターがレッスンを進める中での質問に答えます。

OAuth2 & OpenID Connect Deep Diveを始めるのに経験は必要ですか?

事前経験は必要ありません。CoddyKitのOAuth2 & OpenID Connect Deep Diveは初級者から上級者向けに構成されているため、ここから始めるか最初から始めて、自分のペースで進むことができます。 これはレッスン2/4です。

「ID TokenとClaims」レッスンにはどのくらい時間がかかりますか?

ほとんどのCoddyKitレッスンは約5~10分かかります。各レッスンはコンパクトでインタラクティブなので、着実に進歩し、ウェブとアプリ全体で正確に前回の場所から再開できます。

このOAuth2 & OpenID Connect Deep Diveレッスンでコードを書いて実行できますか?

はい。すべてのOAuth2 & OpenID Connect Deep Diveレッスンに組み込みコードエディタが含まれているため、ブラウザでリアルコードを書いて実行し、即座のAIフィードバックを取得できます。ローカル設定は不要です。

このコースのすべてのレッスン

  1. OIDC:OAuth2のアイデンティティ層
  2. ID TokenとClaims
  3. OIDCフローの概要
  4. UserInfoエンドポイント
← OAuth2 & OpenID Connect Deep Diveに戻る