OIDC ID Token validation
Question Variations
- "Which claims must a relying party validate in an ID Token?"
- "What is the OIDC nonce for?"
- "Why must discovery metadata come from a trusted issuer?"
Why This Is Asked
OIDC is often integrated through a library, but a relying party still needs the correct trust boundaries. This question assesses whether a candidate knows that signature verification alone is insufficient and can articulate issuer, audience, nonce, timing, and authorization-code binding checks.
Key Concepts
- Issuer and discovery: Trust is anchored to a configured issuer and its metadata.
- Audience and authorized party: The token must be intended for the relying party.
- Nonce: Binds the authentication response to the browser request.
- Code flow binding:
c_hashand related checks can bind an ID Token to the authorization response where required.
Question Variations
- “Which claims must a relying party validate in an ID Token?”
- “What is the OIDC nonce for?”
- “Why must discovery metadata come from a trusted issuer?”