[Openid-specs-ab] user_jwk claim name

Mike Jones Michael.Jones at microsoft.com
Wed Jan 23 05:13:09 UTC 2013


What should the "user_jwk" claim be called?  I suspect we named it "user_jwk" to be parallel with "user_id", but we've since changed the name "user_id" to "sub".  This claim contains the self-issued OP's public key that is used to check the signature of the ID token.

The name "op_jwk", for one thing, seems better than "user_jwk".  I say that because (I don't think) it's a key that's specific to the user.  It's a key that's specific to the OP.

I'm asking this now, because while we're continuing to tweak some names to be more intuitive before we issue the implementer's drafts, we should stop making breaking changes if at all after the implementer's drafts are out.

Any other preferences/ideas?

                                                            Thanks,
                                                            -- Mike

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.openid.net/pipermail/openid-specs-ab/attachments/20130123/3f6572ec/attachment.html>


More information about the Openid-specs-ab mailing list