Terminology Index
Glossary
2953 terms
N6
O26
OIDC Client Security
OIDC client security protects authorization-code initiation, redirect handling, PKCE, state or nonce binding, issuer selection, token validation, key rollover, client authentication, and token storage.
It uses exact redirect URIs, avoids implicit token delivery and open redirects, validates every required claim, distinguishes public and confidential clients, and relies on maintained protocol libraries.
Introduced in: Customer Identity and Access Management
Examples
- Use authorization code with PKCE in a mobile app
- Validate ID-token issuer, audience, signature, expiry, and nonce
No related terms linked yet.
