Manage OIDC Claims and Scopes
Use the OIDC Settings page to define the claims and scopes that can be used for adding OIDC relying party. The changes that you make to claims are applied to all the OIDC connections that use these claims.
When you configure an OIDC-based protected resource, you control which claims are sent to the application. Each claim includes customizable display text that appears in user consent forms, helping users understand what information is being shared from the identity provider (IdP) to the application.
A global scope and claim mapping configuration allows you to:
Map identity source attributes to OIDC claims
Optionally group claims into scopes by entering the name of an existing or new scope in the Scopes field
Reuse configured claims and scopes across multiple OIDC applications
This centralized configuration helps you maintain consistent, transparent, and secure data sharing between RSA ID Plus and connected applications.
Procedure
In the Cloud Administration Console, click Access > OIDC Settings.
On the Claims tab, provide the details as described in the following table.
Field Description Claim Name Name of the claim. Source
Select the source for the claim value:
Identity Source sends a user attribute from the identity source. By default, All is selected in Identity Source(s). Select a specific identity source only if the attribute should apply to that identity source. Use the User Attribute field to select a common user schema attribute or an identity source-specific attribute. For information about common schema attributes, see the Common User Schema Attributes section in Identity Sources for Cloud Access Service.
Constant sends a static string, for example, the name of the application.
System sends the user's authentication method information.
Property Select a property when the source is Identity Source or System, or enter a value when the source is Constant. Type Select the claim type. The Default option is selected automatically. Scopes Enter the name of an existing scope or a new scope. If you add a new scope, it appears on the Scopes tab.
Consent Description Provide a user-friendly description of the claim that is displayed when requesting the user's consent. Click the plus icon to save the claim and add another claim.
On the Scopes tab, enter the new scope. To save the scope and add another scope, click the plus icon.
Note: The Scopes tab displays the scopes added from both Claims and Scopes table. Click the expand icon to view the associated claim details.
Click Save Settings.
(Optional) To publish this configuration and immediately activate it, click Publish Changes.
Related Articles
Coming in January 2023: Cloud Authentication Service as Authorization Server for Generic OIDC Relying Party 30Number of Views PingFederate - Relying Party Configuration Using OIDC - RSA Ready Implementation Guide 22Number of Views JAMF Connect - Relying Party Configuration using OIDC- RSA Ready Implementation Guide 5Number of Views 1Password - Relying Party Configuration Using OIDC - RSA Ready Implementation Guide 22Number of Views Cato Networks - Relying Party Configuration Using OIDC - RSA Ready Implementation Guide 3Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device Reporting on RSA Authentication Manager 8.x users with On-Demand Token, a fixed passcode or a hardware/software token assi… How to Download OTP Token Seed Files from myRSA Anomalix idGenius - SAML Relying Party Configuration - RSA Ready Implementation Guide RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide