IdToken

IdToken
IdToken

The ID Token object as per the OpenID Connect specification. See:https://openid.net/specs/openid-connect-core-1_0.html#IDToken

JSON Example
{
    "signature": "string",
    "name": "string",
    "locale": "en_US",
    "customClaims": {
        "customClaims": {}
    },
    "nonce": "string",
    "email": "string",
    "expired": false,
    "jwsHeader": {
        "typ": "string",
        "alg": "string",
        "kid": "string",
        "jku": "string",
        "jwk": "string",
        "x5u": "string",
        "x5t": "string",
        "x5c": "string"
    },
    "iat": 1539988834,
    "group_ids": [
        "string"
    ],
    "azp": "MyOAuth2Client@e9d80cec-4e12-4970-828d-ae4557e33174",
    "auth_time": 1539988834,
    "aud": [
        "MyOAuth2Client@e9d80cec-4e12-4970-828d-ae4557e33174"
    ],
    "group_names": [
        "string"
    ],
    "acr": "string",
    "at_hash": "string",
    "c_hash": "string",
    "email_verified": false,
    "updated_at": 1539988834,
    "subject": "exampleuser@TENANT",
    "phone_number": "string",
    "exp": 1539988834,
    "sub": "exampleuser@TENANT",
    "iss": "\"https://acme.vmwareidentity.com/acs\"",
    "given_name": "string",
    "oid": "string",
    "user_name": "string",
    "roles": [
        {
            "name": "admin",
            "resources": [
                "string"
            ],
            "_links": {
                "self": {
                    "href": "https://example.com/path-to-self"
                }
            },
            "display_name": "Administrator",
            "membership_type": [
                "DIRECT",
                "GROUP"
            ],
            "group_ids": [
                "groupId1",
                "groupId2"
            ],
            "sub_roles": [
                {
                    "type": "nsx",
                    "names": [
                        {
                            "name": "moderator",
                            "display_name": "Moderator"
                        }
                    ],
                    "_links": {
                        "self": {
                            "href": "https://example.com/path-to-self"
                        }
                    }
                }
            ],
            "expires_at": 1700000000000
        }
    ],
    "family_name": "string"
}
string
signature
Optional

signature

string
name
Optional

The end-user's full name in displayable form

string
locale
Optional

The locale of the end-user

object
customClaims
Optional

customClaims

string
nonce
Optional

String value used to associate a Client session with an ID Token. The value is passed through unmodified from the Authentication Request to the ID Token.

string
email
Optional

The end-user's preferred e-mail address

boolean
expired
Optional

expired

jwsHeader
Optional

jwsHeader

integer As int64 As int64
iat
Optional

The time at which the JWT was issued. Its value is a JSON number representing the number of seconds from 1970-01-01T0:0:0Z as measured in UTC until the date/time.

array of string
group_ids
Optional

The IDs of all groups the user belongs to

string
azp
Optional

Authorized party - the party to which the ID Token was issued. Contains the OAuth 2.0 Client ID of this party.

integer As int64 As int64
auth_time
Optional

The time when the end-user authentication occurred. Its value is a JSON number representing the number of seconds from 1970-01-01T0:0:0Z as measured in UTC until the date/time.

array of string
aud
Optional

The audience(s) that this ID Token is intended. The audience value is the OAuth 2.0 client_id of the Relying Party.

array of string
group_names
Optional

The names of all groups the user belongs to

string
acr
Optional

The authentication context used to authenticate the user

string
at_hash
Optional

The access token hash value. Base64url encoded value.

string
c_hash
Optional

The hash of the access code. Base 64 URL encoded value. Returned when the ID Token is issued from the Authorization Endpoint with a "code" or "code id_token", or "code id_token token" as the response type.

boolean
email_verified
Optional

The verified e-mail address of the end-user

integer As int64 As int64
updated_at
Optional

The time the end-user's information was last updated. Its value is a JSON number representing the number of seconds from 1970-01-01T0:0:0Z as measured in UTC until the date/time.

string
subject
Required  

This is the same as the subject identifier. It is maintained to provide backward compatibility with SAAS.

string
phone_number
Optional

The end-user's preferred telephone number

integer As int64 As int64
exp
Optional

The expiration time on or after which the ID Token MUST NOT be accepted for processing. Its value is a JSON number representing the number of seconds from 1970-01-01T0:0:0Z as measured in UTC until the date/time.

string
sub
Required  

The subject identifier of the subject for whom the ID Token is issued.

string
iss
Optional

The identifier for the authority that issued the token

string
given_name
Optional

The given name(s) or first name(s) of the end-user

string
oid
Optional

Get the oid of the user

string
user_name
Optional

Get the name of the user

roles
Optional

List of roles assigned to the subject

string
family_name
Optional

The surname(s) or last name(s) of the end-user