[Openid-specs-ab] Response types clarification

Torsten Lodderstedt torsten at lodderstedt.net
Mon Feb 20 18:30:28 UTC 2012


Hi all,

I'm trying to catch up with the Implementors Draft and need some advice 
from the group.

Is it correct that "code" is the only response type, which is delivered 
to the client via URI query parameter? For all other response types, the 
response parameters are encoded within the URI fragment.

Furthermore, is the client always issued an access token _and_ an 
id_token for scope "openid" and response type "code"?

thanks in advance,
Torsten.


More information about the Openid-specs-ab mailing list