
23 Oct
2015
23 Oct
'15
8:18 a.m.
In the examples in 3.5.4 and 3.6.2 ”http://openid.net/specs/openid-connect-core-1_0.html#HybridIDToken” is given as an example of claim_token_format/format. I can’t see that Hybrid Flow ID Token provides the AS with any extra information compared to a ’normal’ ID Token that the AS can have any use of. Since the AS will most probably not have access to the code or the access_token value. Or am I missing something ? So, why choose it as an example. — Roland 'Look, that's why there's rules, understand? So that you think before you break ’em.’ - Terry Pratchett