Episode 099: 03‐27‐2025 New JWT Tokens for RP Acct Mgt - GluuFederation/identerati-office-hours GitHub Wiki
Title: OpenID Provider Commands: New JWT Tokens for RP Acct Mgt
-
Host: Mike Schwartz, Founder/CEO Gluu
-
Dick Hardt, Founder/CEO Hellō
-
Guest: Karl McGuinness, Identerati at large
Description
"OpenID Provider Commands" is a new proposed protocol via Dick Hardt and Karl McGuinness which introduces a mechanism for delivering backchannel "command tokens" (a JWT) that allows an OpenID Provider (OP) to send the following messages to an OpenID Relying Party (RP):
- 🔑 Activate an account
- 🔄 Maintain an account
- ⏸️ Suspend an account
- 🔓 Reactivate an account
- 📦 Archive an account
- ♻️ Restore an account
- ❌ Delete an account
- 🚫 Unauthorize an account
In this episode we'll hear from the authors why they think this new protocol is needed, and why their solution is the right design for the Internet.
Homework
- Here is a link to a very early draft
Takeaways
TBD