OAuth2 & OpenID Connect Deep Dive · Aula

Usando nonce para impedir repetição

Aprenda como o parâmetro nonce do OpenID Connect vincula um token de ID a uma solicitação de autenticação específica e protege contra ataques de repetição de tokens.

Aula 4 de 413 etapas

Usando nonce para impedir repetição é uma aula grátis de OAuth2 & OpenID Connect Deep Dive no CoddyKit. Esta é a aula 4 de 4. Você pode ler a aula completa abaixo gratuitamente — depois pratica ao vivo no navegador com um editor de código integrado e um tutor de IA 24/7. Faz parte do caminho de aprendizado de OAuth2 & OpenID Connect Deep Dive, e seu progresso é sincronizado entre a web e o app CoddyKit. O curso de OAuth2 & OpenID Connect Deep Dive inclui 4 aulas no total.

Partes desta aula ainda não foram traduzidas e aparecem em inglês.

What Is the nonce?

The nonce is a random value the client generates and includes in the authentication request. The OpenID Provider echoes it back inside the issued ID token. Matching them proves the token belongs to this request.

The Replay Threat

Without a nonce, an attacker who captures a valid ID token (for example, in the Implicit or Hybrid flow where tokens travel via the browser) could replay it into another session. The nonce ties the token to one specific request, defeating replay.

nonce vs state

They are different tools:

  • state — protects the OAuth2 authorization request/response against CSRF.
  • nonce — protects the ID token against replay, validated inside the token itself.

Use both together in OIDC flows.

Generating a nonce

Create a high-entropy random value and store it bound to the user's session before redirecting.

import secrets
nonce = secrets.token_urlsafe(32)
session['oidc_nonce'] = nonce
print(nonce)

Including It in the Request

Add the nonce to the authorization request alongside the usual parameters.

GET /authorize?
  response_type=code
  &client_id=app123
  &scope=openid profile
  &redirect_uri=https://app.example.com/cb
  &state=xyz
  &nonce=Tk9SQ0VfdmFsdWU

It Comes Back in the ID Token

The ID token's payload includes the exact nonce you sent.

{
  "iss": "https://op.example.com",
  "sub": "248289",
  "aud": "app123",
  "nonce": "Tk9SQ0VfdmFsdWU",
  "exp": 1735689600
}

Validating the nonce

After validating the ID token's signature and claims, compare its nonce with the value stored in the session.

if id_token['nonce'] != session.pop('oidc_nonce', None):
    raise Exception('nonce mismatch - reject token')

When nonce Is Required

The nonce is mandatory in the Implicit and Hybrid flows because ID tokens are returned through the browser front channel. In the Authorization Code flow it is recommended and strongly encouraged.

One-Time Use

Treat each nonce as single-use. Remove it from the session as soon as it is validated so the same value can never authorize a second token, closing replay windows.

Common Mistakes

Pitfalls to avoid:

  • Using a predictable or reused nonce.
  • Forgetting to compare it after validating the signature.
  • Storing it client-side without integrity protection.
  • Skipping it in front-channel flows.

Putting It Together

The full lifecycle: generate nonce, store in session, send in auth request, receive it in the ID token, verify signature and claims, then compare and discard the nonce. Only then trust the authentication.

Quick Check

Test your knowledge of the nonce.

Recap

The nonce protects ID tokens from replay.

  • Generate a random nonce, store it in session, send it in the auth request.
  • The OP echoes it inside the ID token.
  • Validate by comparing token nonce to session nonce, then discard it.
  • Required in Implicit/Hybrid flows; recommended everywhere.
Grátis para começar

Aprenda OAuth2 & OpenID Connect Deep Dive com um tutor de IA — grátis

Escreva e execute código real no seu navegador, obtenha ajuda instantânea de um tutor de IA 24/7 e continue de onde parou na web ou no app.

Cursos
12
Aulas
48

Perguntas Frequentes

A aula “Usando nonce para impedir repetição” é grátis?

Sim — o texto completo de “Usando nonce para impedir repetição” é grátis para ler aqui na web. Para praticá-la interativamente (um editor de código integrado e um tutor de IA 24/7) e desbloquear o restante do curso de OAuth2 & OpenID Connect Deep Dive, atualize para CoddyKit PRO. O curso de OAuth2 & OpenID Connect Deep Dive inclui 4 aulas no total.

O que vou aprender em “Usando nonce para impedir repetição”?

Aprenda como o parâmetro nonce do OpenID Connect vincula um token de ID a uma solicitação de autenticação específica e protege contra ataques de repetição de tokens. Você pratica OAuth2 & OpenID Connect Deep Dive com código prático que executa diretamente no navegador, e um tutor de IA 24/7 responde suas dúvidas enquanto trabalha na aula.

Preciso ter experiência prévia para começar OAuth2 & OpenID Connect Deep Dive?

Nenhuma experiência prévia é necessária. OAuth2 & OpenID Connect Deep Dive no CoddyKit é estruturado para alunos iniciantes até avançados, então você pode começar aqui ou desde o início e aprender no seu ritmo. Esta é a aula 4 de 4.

Quanto tempo leva a aula “Usando nonce para impedir repetição”?

A maioria das aulas CoddyKit leva cerca de 5–10 minutos. Cada uma é compacta e interativa, então você faz progresso constante e retoma exatamente de onde parou entre web e app.

Posso escrever e executar código nesta aula de OAuth2 & OpenID Connect Deep Dive?

Sim. Cada aula de OAuth2 & OpenID Connect Deep Dive inclui um editor de código integrado, então você escreve e executa código real direto no navegador e recebe feedback de IA instantaneamente — nenhuma configuração local necessária.

Todas as aulas deste curso

  1. Fluxo do Código de Autorização com OIDC
  2. Fluxo Implícito com OIDC
  3. Fluxo Híbrido com OIDC
  4. Usando nonce para impedir repetição
← Voltar para OAuth2 & OpenID Connect Deep Dive