0Pricing
OAuth2 & OpenID Connect Deep Dive · レッスン

UserInfoエンドポイント

OpenID ConnectのUserInfoエンドポイントを使い、クライアントがアクセストークンで認証済みユーザーに関する追加の検証済みクレームを取得する方法を学びます。

「UserInfoエンドポイント」はCoddyKit上の無料OAuth2 & OpenID Connect Deep Diveレッスンです。 これはレッスン4/4です。 下記で完全なレッスンを無料で読むことができます。その後、ブラウザ内の組み込みコードエディタと24時間対応のAIチューターでハンズオン演習できます。 これはOAuth2 & OpenID Connect Deep Dive学習パスの一部であり、ウェブとCoddyKitアプリ全体で進捗が同期されます。 OAuth2 & OpenID Connect Deep Diveコースには全4レッスンが含まれています。

このレッスンの一部はまだ翻訳されておらず、英語で表示されています。

Beyond the ID Token

The ID token proves who the user is, but to keep it small it may carry only a few claims. The UserInfo endpoint is an OAuth2-protected resource that returns additional claims about the currently authenticated user.

It Is a Protected Resource

UserInfo is not part of the token endpoint — it is a normal protected API. You call it with the access token obtained during the OIDC flow, presented as a Bearer token.

Discovering the Endpoint

Its URL is published in the provider's discovery document under userinfo_endpoint.

GET /.well-known/openid-configuration

{
  "userinfo_endpoint": "https://op.example.com/userinfo"
}

Making the Request

Send a GET (or POST) with the access token in the Authorization header.

GET /userinfo HTTP/1.1
Host: op.example.com
Authorization: Bearer eyJhbGciOiJSUzI1NiIs...

The Response

The response is a JSON object of claims. It must include the sub claim, which must equal the sub in the ID token to prevent token substitution.

{
  "sub": "248289761001",
  "name": "Jane Doe",
  "email": "jane@example.com",
  "email_verified": true,
  "picture": "https://example.com/jane.jpg"
}

Scopes Control Claims

Which claims are returned depends on the scopes granted during authorization:

  • profile — name, picture, locale, etc.
  • email — email, email_verified.
  • address — postal address.
  • phone — phone_number, phone_number_verified.

Verifying the sub

Always confirm the sub from UserInfo matches the sub in the validated ID token. Otherwise an attacker could swap an access token issued for a different user.

if (userInfo.sub !== idTokenClaims.sub) {
  throw new Error('sub mismatch - possible token substitution');
}

Signed and Encrypted Responses

By default UserInfo returns plain JSON. Providers can also return a signed JWT (set via userinfo_signed_response_alg) so the client can verify integrity, and even an encrypted JWT for confidentiality.

ID Token vs UserInfo

When to use which?

  • Put stable, identity-critical claims in the ID token (sub, auth_time).
  • Fetch large or changeable profile data from UserInfo as needed.

This keeps the ID token compact while still giving rich profile access.

Caching Considerations

UserInfo data can change (a user updates their name). Avoid caching it indefinitely; refresh it on login or when you need current values, balancing freshness against extra network calls.

Error Handling

If the access token is expired or invalid, UserInfo returns a 401 with a WWW-Authenticate: Bearer error="invalid_token" header. Handle this by refreshing the token or re-authenticating.

Quick Check

Check your understanding of the UserInfo endpoint.

Recap

The UserInfo endpoint returns additional user claims using the access token.

  • It is a protected resource, discovered via userinfo_endpoint.
  • Returned claims depend on granted scopes.
  • Always verify its sub matches the ID token's sub.
  • Responses can be plain JSON or signed/encrypted JWTs.

よくある質問

「UserInfoエンドポイント」レッスンは無料ですか?

はい。「UserInfoエンドポイント」の完全なテキストはこのウェブで無料で読めます。インタラクティブに演習し(組み込みコードエディタと24時間対応のAIチューター)、OAuth2 & OpenID Connect Deep Diveコースの残りをアンロックするには、CoddyKit PROにアップグレードしてください。 OAuth2 & OpenID Connect Deep Diveコースには全4レッスンが含まれています。

「UserInfoエンドポイント」で何を学びますか?

OpenID ConnectのUserInfoエンドポイントを使い、クライアントがアクセストークンで認証済みユーザーに関する追加の検証済みクレームを取得する方法を学びます。 ブラウザで直接実行するハンズオンコードでOAuth2 & OpenID Connect Deep Diveを演習し、24時間対応のAIチューターがレッスンを進める中での質問に答えます。

OAuth2 & OpenID Connect Deep Diveを始めるのに経験は必要ですか?

事前経験は必要ありません。CoddyKitのOAuth2 & OpenID Connect Deep Diveは初級者から上級者向けに構成されているため、ここから始めるか最初から始めて、自分のペースで進むことができます。 これはレッスン4/4です。

「UserInfoエンドポイント」レッスンにはどのくらい時間がかかりますか?

ほとんどのCoddyKitレッスンは約5~10分かかります。各レッスンはコンパクトでインタラクティブなので、着実に進歩し、ウェブとアプリ全体で正確に前回の場所から再開できます。

このOAuth2 & OpenID Connect Deep Diveレッスンでコードを書いて実行できますか?

はい。すべてのOAuth2 & OpenID Connect Deep Diveレッスンに組み込みコードエディタが含まれているため、ブラウザでリアルコードを書いて実行し、即座のAIフィードバックを取得できます。ローカル設定は不要です。

このコースのすべてのレッスン

  1. OIDC:OAuth2のアイデンティティ層
  2. ID TokenとClaims
  3. OIDCフローの概要
  4. UserInfoエンドポイント
← OAuth2 & OpenID Connect Deep Diveに戻る