[Openid-specs-ab] A question about Userinfo endpoint

Nat Sakimura sakimura at gmail.com
Wed Feb 20 15:27:19 UTC 2013

Hi. A question.

In Messages, it is stated that: 2.3.  UserInfo Endpoint

The UserInfo Endpoint is a Protected Resource that returns Claims about the
authenticated End-User. Claims are represented by a JSON object that
contains a collection of name and value pairs for the Claims.
Does Userinfo Endpoint only provide data for authenticated End-user? Or is
it a generic protected resource that returns whatever have been authorized
at the authorization server? In another word, is the value of sub in the ID
Token and the Userinfo response for the access token whose hash is in the
ID Token the same?
Nat Sakimura (=nat)
Chairman, OpenID Foundation
