OAuth2 & OpenID Connect Deep Dive · 课时

ID 令牌与声明

分析 ID Token 的结构和内容。ID Token 是一种携带用户身份声明的 JSON Web Token(JWT)。

第 2 / 4 课11 个步骤

ID 令牌与声明 是 CoddyKit 上的免费 OAuth2 & OpenID Connect Deep Dive 课时。 这是第 2 节课,共 4 节。 你可以在下方免费阅读本课时的完整内容 — 然后在浏览器中使用内置代码编辑器和全天候 AI 导师进行实践。 这是 OAuth2 & OpenID Connect Deep Dive 学习路径的一部分,你的进度在网页和 CoddyKit 应用中同步。 OAuth2 & OpenID Connect Deep Dive 课程共包含 4 节课。

本课时的部分内容尚未翻译,以英文显示。

The Identity Token Revealed

The ID Token is a core component of OpenID Connect (OIDC). Think of it as a digital ID card for the user.

Its main purpose is to provide your application with verified identity information about the end-user who just logged in. It tells you who the user is.

Crucially, an ID Token is different from an Access Token. While an Access Token is for authorization (what you can do), an ID Token is for authentication (who you are).

ID Token's Secret: It's a JWT!

Every ID Token is a JSON Web Token (JWT). JWTs are a compact, URL-safe means of representing claims to be transferred between two parties.

Being a JWT means ID Tokens have a specific, standardized structure that allows for secure and verifiable information exchange.

This standardized format makes it easy for different systems to understand and process identity information.

Breaking Down a JWT

A JWT consists of three parts, separated by dots (.):

  • Header: Describes the token's type and the signing algorithm.
  • Payload: Contains the actual "claims" (identity information).
  • Signature: Used to verify the token hasn't been tampered with.

Both the Header and Payload are Base64Url-encoded JSON objects. The Signature is created using the encoded Header, Payload, and a secret key.

The Payload: Where Claims Live

The most important part of the ID Token for identity is its Payload. This is a JSON object containing various statements about the user and the authentication event.

These statements are called claims. Each claim is a key-value pair, like "name": "Jane Doe". They tell your application specific details about the user.

Claims are standardized by OIDC, but can also include custom information depending on the OpenID Provider (OP).

Required Claims: Issuer, Subject, Audience

Certain claims are essential for an ID Token to be valid and useful:

  • iss (Issuer): Identifies the entity that issued the token. This is typically the URL of the OpenID Provider.
  • sub (Subject): A unique identifier for the end-user. It's usually a string that's unique to the user within the issuer's system.
  • aud (Audience): Identifies the recipient(s) the JWT is intended for. This must be your application's client_id.

Time-Based Identity: Expiry & Issued At

ID Tokens also include important time-related claims:

  • exp (Expiration Time): The time after which the ID Token MUST NOT be accepted. It's a Unix timestamp.
  • iat (Issued At Time): The time at which the ID Token was issued. Also a Unix timestamp.
  • auth_time (Authentication Time): The time when the end-user last authenticated. Useful for session management policies.

Always check exp to ensure the token is still valid!

Nonce: A One-Time Security Check

The nonce claim is a unique, one-time value generated by your client application and sent to the Authorization Server.

When the ID Token is returned, it will include the same nonce. Your application then verifies that the nonce in the token matches the one it sent.

This helps mitigate replay attacks, ensuring that the ID Token wasn't captured and reused by a malicious party.

Enriching User Profiles

Beyond the core claims, ID Tokens often carry additional user information, known as "User Profile Claims". These are usually requested via scopes.

Common examples include:

  • name: The user's full name.
  • given_name: The user's first name.
  • family_name: The user's last name.
  • email: The user's email address.
  • picture: A URL to the user's profile picture.

These claims provide a rich set of data for your application.

Decoding an ID Token's Claims

When you receive and decode an ID Token, its payload might look something like this (simplified JSON):

{
  "iss": "https://accounts.coddykit.com",
  "sub": "user_id_xyz_789",
  "aud": "my_mobile_app_123",
  "exp": 1678886400,
  "iat": 1678882800,
  "auth_time": 1678882700,
  "nonce": "a1b2c3d4e5",
  "name": "Coddy User",
  "email": "coddy.user@example.com"
}

Each key-value pair is a specific claim providing identity details.

Quick Check on Claims

You've learned about the different claims within an ID Token.

Which of the following claims is primarily used to identify the recipient (your client application) for whom the ID Token is intended?

ID Token & Claims Recap

Great job! You've successfully explored the core of OpenID Connect: the ID Token and its claims.

  • ID Tokens are JWTs carrying identity data.
  • They contain a Header, Payload (claims), and Signature.
  • Key claims like iss, sub, aud, exp, iat, and nonce are crucial.
  • User Profile Claims like name and email enrich the identity.

Next, we'll dive into the different OIDC flows that use these tokens!

免费开始

用 AI 导师学习 OAuth2 & OpenID Connect Deep Dive — 免费

在浏览器中编写并运行真实代码,获得全天候 AI 导师的即时帮助,并在网页或应用中继续学习。

课程
12
课程
48

常见问题解答

「ID 令牌与声明」课时是免费的吗?

是的 — 「ID 令牌与声明」的完整文本可在网页上免费阅读。要进行交互式练习(内置代码编辑器和全天候 AI 导师)并解锁 OAuth2 & OpenID Connect Deep Dive 课程的其余内容,请升级到 CoddyKit PRO。 OAuth2 & OpenID Connect Deep Dive 课程共包含 4 节课。

「ID 令牌与声明」这节课中我会学到什么?

分析 ID Token 的结构和内容。ID Token 是一种携带用户身份声明的 JSON Web Token(JWT)。 你通过在浏览器中直接运行的动手代码来练习 OAuth2 & OpenID Connect Deep Dive,全天候 AI 导师会在你学习这节课的过程中回答你的问题。

学习 OAuth2 & OpenID Connect Deep Dive 需要有经验吗?

无需任何先前经验。CoddyKit 上的 OAuth2 & OpenID Connect Deep Dive 课程适合初学者到高级学习者,你可以从这里开始或从头开始,按照自己的节奏学习。 这是第 2 节课,共 4 节。

「ID 令牌与声明」课时需要多长时间?

大多数 CoddyKit 课程大约需要 5–10 分钟。每节课都很精短且互动,所以你能稳步进步,并在网页和应用中从离开的地方继续。

我能在这节 OAuth2 & OpenID Connect Deep Dive 课中编写并运行代码吗?

能。每节 OAuth2 & OpenID Connect Deep Dive 课都包含内置代码编辑器,你可以在浏览器中直接编写并运行真实代码,并获得即时 AI 反馈 — 无需本地设置。

此课程中的所有课时

  1. OIDC:OAuth2 上的身份层
  2. ID 令牌与声明
  3. OIDC 流程概览
  4. UserInfo 端点
← 返回 OAuth2 & OpenID Connect Deep Dive