OIDC attribute/claim inclusion in id_token
Randy R. Rouch
rrrouch at cpp.edu
Tue Jan 13 21:37:29 UTC 2026
Dear Shibboleth Users,
We are trying to set up JAMF to use our Shibboleth as an OIDC provider, but we've run into an issue. They require that certain attributes like mail and sn be a part of the ID Token to log in instead of making a UserInfo Endpoint request. From what I've discovered so far, most seem to recommend using the idp.oidc.alwaysIncludedAttributes property in oidc.properties to force the needed attributes into the ID Token, but that feels like using a sledgehammer instead of a scalpel as it will force the attributes into ALL ID Tokens, even if it's not JAMF.
Is this the standard functionality, or is there a per vendor attribute I haven't discovered yet? Has anyone run into a similar issue, especially if they've also dealt with JAMF and OIDC?
Thanks,
Randy
----------------------------------------
Randy R. Rouch
Linux Systems Administrator
Cloud & Support Services
CalPolyPomona
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20260113/e7b75a9d/attachment.htm>
More information about the users
mailing list