Terminology Index

Glossary

2953 terms

Open concept maps
N
6
O
26

OIDC Client Security

OIDC client security protects authorization-code initiation, redirect handling, PKCE, state or nonce binding, issuer selection, token validation, key rollover, client authentication, and token storage.

It uses exact redirect URIs, avoids implicit token delivery and open redirects, validates every required claim, distinguishes public and confidential clients, and relies on maintained protocol libraries.

Introduced in: Customer Identity and Access Management

Examples

  • Use authorization code with PKCE in a mobile app
  • Validate ID-token issuer, audience, signature, expiry, and nonce

No related terms linked yet.