ID 토큰 및 클레임
사용자에 대한 ID 클레임을 담은 JSON 웹 토큰(JWT)인 ID 토큰의 구조와 내용을 살펴보세요.
ID 토큰 및 클레임은(는) CoddyKit의 무료 OAuth2 & OpenID Connect Deep Dive 강의입니다. 이것은 4개 중 2번째 강의입니다. 아래에서 전체 강의를 무료로 읽을 수 있으며, 내장 코드 에디터와 24/7 AI 튜터와 함께 브라우저에서 직접 실습할 수 있습니다. 이 강의는 OAuth2 & OpenID Connect Deep Dive 학습 경로의 일부이며, 진행 상황이 웹과 CoddyKit 앱에 동기화됩니다. OAuth2 & OpenID Connect Deep Dive 강의에는 총 4개의 강의가 포함되어 있습니다.
이 강의의 일부는 아직 번역되지 않았으며 영어로 표시됩니다.
The Identity Token Revealed
The ID Token is a core component of OpenID Connect (OIDC). Think of it as a digital ID card for the user.
Its main purpose is to provide your application with verified identity information about the end-user who just logged in. It tells you who the user is.
Crucially, an ID Token is different from an Access Token. While an Access Token is for authorization (what you can do), an ID Token is for authentication (who you are).
ID Token's Secret: It's a JWT!
Every ID Token is a JSON Web Token (JWT). JWTs are a compact, URL-safe means of representing claims to be transferred between two parties.
Being a JWT means ID Tokens have a specific, standardized structure that allows for secure and verifiable information exchange.
This standardized format makes it easy for different systems to understand and process identity information.
Breaking Down a JWT
A JWT consists of three parts, separated by dots (.):
- Header: Describes the token's type and the signing algorithm.
- Payload: Contains the actual "claims" (identity information).
- Signature: Used to verify the token hasn't been tampered with.
Both the Header and Payload are Base64Url-encoded JSON objects. The Signature is created using the encoded Header, Payload, and a secret key.
The Payload: Where Claims Live
The most important part of the ID Token for identity is its Payload. This is a JSON object containing various statements about the user and the authentication event.
These statements are called claims. Each claim is a key-value pair, like "name": "Jane Doe". They tell your application specific details about the user.
Claims are standardized by OIDC, but can also include custom information depending on the OpenID Provider (OP).
Required Claims: Issuer, Subject, Audience
Certain claims are essential for an ID Token to be valid and useful:
iss(Issuer): Identifies the entity that issued the token. This is typically the URL of the OpenID Provider.sub(Subject): A unique identifier for the end-user. It's usually a string that's unique to the user within the issuer's system.aud(Audience): Identifies the recipient(s) the JWT is intended for. This must be your application'sclient_id.
Time-Based Identity: Expiry & Issued At
ID Tokens also include important time-related claims:
exp(Expiration Time): The time after which the ID Token MUST NOT be accepted. It's a Unix timestamp.iat(Issued At Time): The time at which the ID Token was issued. Also a Unix timestamp.auth_time(Authentication Time): The time when the end-user last authenticated. Useful for session management policies.
Always check exp to ensure the token is still valid!
Nonce: A One-Time Security Check
The nonce claim is a unique, one-time value generated by your client application and sent to the Authorization Server.
When the ID Token is returned, it will include the same nonce. Your application then verifies that the nonce in the token matches the one it sent.
This helps mitigate replay attacks, ensuring that the ID Token wasn't captured and reused by a malicious party.
Enriching User Profiles
Beyond the core claims, ID Tokens often carry additional user information, known as "User Profile Claims". These are usually requested via scopes.
Common examples include:
name: The user's full name.given_name: The user's first name.family_name: The user's last name.email: The user's email address.picture: A URL to the user's profile picture.
These claims provide a rich set of data for your application.
Decoding an ID Token's Claims
When you receive and decode an ID Token, its payload might look something like this (simplified JSON):
{
"iss": "https://accounts.coddykit.com",
"sub": "user_id_xyz_789",
"aud": "my_mobile_app_123",
"exp": 1678886400,
"iat": 1678882800,
"auth_time": 1678882700,
"nonce": "a1b2c3d4e5",
"name": "Coddy User",
"email": "coddy.user@example.com"
}Each key-value pair is a specific claim providing identity details.
Quick Check on Claims
You've learned about the different claims within an ID Token.
Which of the following claims is primarily used to identify the recipient (your client application) for whom the ID Token is intended?
ID Token & Claims Recap
Great job! You've successfully explored the core of OpenID Connect: the ID Token and its claims.
- ID Tokens are JWTs carrying identity data.
- They contain a Header, Payload (claims), and Signature.
- Key claims like
iss,sub,aud,exp,iat, andnonceare crucial. - User Profile Claims like
nameandemailenrich the identity.
Next, we'll dive into the different OIDC flows that use these tokens!
AI 튜터와 함께 OAuth2 & OpenID Connect Deep Dive을(를) 배우세요 — 무료
브라우저에서 실제 코드를 작성하고 실행하며, 24/7 AI 튜터로부터 즉각적인 도움을 받고, 웹이나 앱에서 중단한 부분부터 계속 학습하세요.
- 코스
- 12
- 레슨
- 48
자주 묻는 질문
“ID 토큰 및 클레임” 강의는 무료인가요?
네 — “ID 토큰 및 클레임” 전체 내용을 이 웹사이트에서 무료로 읽을 수 있습니다. 인터랙티브하게 실습하려면(내장 코드 에디터와 24/7 AI 튜터), CoddyKit PRO로 업그레이드하면 OAuth2 & OpenID Connect Deep Dive 강의 전체를 잠금 해제할 수 있습니다. OAuth2 & OpenID Connect Deep Dive 강의에는 총 4개의 강의가 포함되어 있습니다.
“ID 토큰 및 클레임”에서 뭘 배우나요?
사용자에 대한 ID 클레임을 담은 JSON 웹 토큰(JWT)인 ID 토큰의 구조와 내용을 살펴보세요. 브라우저에서 직접 실행하는 실습 코드로 OAuth2 & OpenID Connect Deep Dive을(를) 배우며, 24/7 AI 튜터가 강의를 진행하면서 질문에 답변해줍니다.
OAuth2 & OpenID Connect Deep Dive을(를) 시작하는 데 경험이 필요한가요?
사전 경험은 필요하지 않습니다. CoddyKit의 OAuth2 & OpenID Connect Deep Dive은(는) 초급자부터 고급 학습자까지를 위해 구성되어 있으므로, 여기서 시작하거나 처음부터 시작할 수 있으며 자신의 속도대로 진행할 수 있습니다. 이것은 4개 중 2번째 강의입니다.
“ID 토큰 및 클레임” 강의는 얼마나 걸리나요?
대부분의 CoddyKit 강의는 약 5~10분이 소요됩니다. 각 강의는 간결하고 인터랙티브하여 꾸준한 진행이 가능하며, 웹과 앱에서 중단한 부분부터 바로 시작할 수 있습니다.
이 OAuth2 & OpenID Connect Deep Dive 강의에서 코드를 작성하고 실행할 수 있나요?
네. 모든 OAuth2 & OpenID Connect Deep Dive 강의에는 내장 코드 에디터가 포함되어 있으므로, 브라우저에서 바로 실제 코드를 작성하고 실행한 후 즉시 AI 피드백을 받을 수 있습니다 — 로컬 설정이 필요 없습니다.
이 강의의 모든 강의
- OIDC: OAuth2의 ID 계층
- ID 토큰 및 클레임
- OIDC 흐름 개요
- UserInfo 엔드포인트