[Openid-specs-ab] response_type and nonce

Roland Hedberg roland.hedberg at adm.umu.se
Mon Sep 3 13:00:46 UTC 2012


I'm almost certain I've asked this before but I've change mail client so
I might have lost some mails.

OpenID Connect supports the additional response_type "id_token".
Just "id_token" !!

If "id_token" is the response_type what type of flow is it ?

Or to be more specific; about nonce it's said:

"Use of the nonce is REQUIRED when using the implicit flow and OPTIONAL
when using the code flow."

So, if the response_type == "id_token" is nonce REQUIRED or OPTIONAL.

-- Roland

More information about the Openid-specs-ab mailing list