openid connect - Why is the IdentityTokenLifetime default to 300 sec? -


maybe should ask intended use of identity token is. thought used identify user , can passed other services (e.g. backend services) , services use id_token validate valid user? don't see current available endpoint validate id_token. if not, should passed 1 service service validate user?

the end point takes id_token parameter end session endpoint passed id_token_hint. in case, why identitytokenlifetime default 300 sec only? don't expect user end session in 300 sec.

the identity token one-time token.

it contains identity of user , authentication metadata. once token validated, (in theory) deleted. pick out claims interested in.

the situation want keep identity token around special features during sign-out.

the identity token never passed around. that's access token for.


Comments

Popular posts from this blog

Is there a better way to structure post methods in Class Based Views -

reflection - How to access the object-members of an object declaration in kotlin -

php - Doctrine Query Builder Error on Join: [Syntax Error] line 0, col 87: Error: Expected Literal, got 'JOIN' -