<div dir="ltr">It's more than just that.  To the extent you're doing an OIDC authentication and obtaining and using an access tokenyou may very well want scopes for reasons other than just restricting claims.  And you're probably going to want to go ahead and request the added scopes during the OIDC authentication and authorization process, rather than doing a token exchange and doing it then.<div><br></div><div>Greg</div></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Mon, Jun 8, 2020 at 3:28 PM Liam Hoekenga <<a href="mailto:liamr@umich.edu">liamr@umich.edu</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div dir="ltr"><div dir="ltr">On Mon, Jun 8, 2020 at 4:28 PM Wessel, Keith <<a href="mailto:kwessel@illinois.edu" target="_blank">kwessel@illinois.edu</a>> wrote:<br></div><div class="gmail_quote"><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">





<div lang="EN-US">
<div>
<p class="MsoNormal">Well, yes, it’s technically possible. I thought I had read at one point in the OIDC spec that inventing additional scopes was a violation of the profile, but I’m not seeing that now. So… carry on.</p></div></div></blockquote><div><br></div><div>I'd obviously like to stick with predefined / standard scopes, but there's stuff out there (e.g. <a href="https://connect2id.com/products/server/docs/config/claims-mapping" target="_blank">https://connect2id.com/products/server/docs/config/claims-mapping</a>)</div><div><br></div><div>thanks for the confirmation about naming claims!</div><div><br></div><div>Liam </div></div></div>
-- <br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div>