[Openid-specs-mobile-profile] Issue #91: CIBA: Authentication request and context parameters (openid/mobile)

Petteri Stenius issues-reply at bitbucket.org
Wed Sep 26 12:49:59 UTC 2018

New issue 91: CIBA: Authentication request and context parameters

Petteri Stenius:

This topic was briefly discussed in yesterday's call (September 25)

It was recognized there is need to let client send context and metadata parameters to OP as part of authentication request.

Examples of possible context and metadata parameters that may be useful 

* IP address of user agent, for example when authentication is initiated by a user using a web browser
* Type of device initiating authentication (vending machine, ATM etc)
* GPS location coordinates of device initiating authentication
* others

At a minimum there should be a registry of names for context and metadata parameters. Should it also be possible for an OP to define parameters that are mandatory?

More information about the Openid-specs-mobile-profile mailing list