Duo JWT Token
Steven Premeau
steven.premeau at maine.edu
Tue Feb 24 20:45:54 UTC 2026
Mark -
You can work with the JWT Token inside of
shibboleth.authn.DuoOIDC.ContextToPrincipalMappingStrategy (which would be
configured in authn/duo-oidc-authn-config.xml).
You can see some details and an example under "Context to Principal
Mapping Strategy" within the "Advanced Topics" on
https://shibboleth.atlassian.net/wiki/spaces/IDPPLUGINS/pages/1374027959/DuoOIDCAuthnConfiguration#Advanced-Topics
Steve.
On Tue, Feb 24, 2026 at 3:18 PM Mark Boyce via users <users at shibboleth.net>
wrote:
> Hello All,
>
>
>
> We have an ask to capture the payload from Duo’s JWT Token post
> authentication and include some elements as attributes passed in the SAML
> Assertion. My understanding is that the token is discarded after the
> authentication flow is completed. Has anyone had any success with capturing
> this?
>
>
>
> Thanks,
>
> m.
>
>
>
> *Mark L. Boyce*
>
> Senior Identity Management Analyst
>
> University of California, Office of the President
>
> Office: 510.987.9681
>
> Cell: 209.851.0196
>
>
> --
> For Consortium Member technical support, see
> https://shibboleth.atlassian.net/wiki/x/ZYEpPw
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20260224/6f6198bf/attachment.htm>
More information about the users
mailing list