Validation Decisions
As per above section, SP might have invoked the validation API and below are some guidelines on how to make decision on token validation response.
Based on the response from earlier section, “Verify Access Token” and “Obtain User information API”, SP should check below in chronological order:
"client_id":"sdg_digivault",
"client_claims":
{
"distinguished_name":"CN=SDG DigitalVault",
"sub":"sdg_digitalvault",
"name":"SDG Digital Vault App",
"domain":"urn:safelayer:eidas:domain:oauth:client",
"acr":"urn:safelayer:tws:policies:authentication:level:low",
"amr":"["urn:oasis:names:tc:SAML:1:0:am:password"]
}{
"sub": "800F475AC0E7A9ED01B2D5D2C25A59B3",
…
…………
…………
"acr":
"urn:safelayer:tws:policies:authentication:level:high",
"mobile": "9715555555555",
"amr": [ "urn:safelayer:tws:policies:authentication:adaptive:methods:mobileid", "urn:uae:authentication:method:verified"]
}Last updated
Was this helpful?